Crucial Paradigm

Call us now 1300 884 839

Member Login
Australia USA

Location: Australia

Soar with High Availability Web Hosting from $11.95/month Elastic Self-Healing Windows VPS from $54.95/month State Of The Art Infrastructure Powered By Hewlett Packard and Cisco R1 Soft CDP Backup Solution

Go Back   Crucial Paradigm Official Forums > Crucial Paradigm Announcements > Public Announcements

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 17-09-2010, 08:08 PM
Aaron's Avatar
Hosting Slave
 
Join Date: Dec 2008
Location: Sydney
Posts: 625
Send a message via MSN to Aaron
Default Incident Report: AU 17/Sep/2010 5PM AEST (+10GMT) - s392.au.crucialx.net

You are being contacted as you have a reseller account on the server s392.au.crucialx.net.

EVENT START DATE: 17/Sep/2010
EVENT START TIME: 5PM AEST
EVENT END DATE: n/a
EVENT END TIME: n/a

EVENT IMPACT: Customers with reseller accounts on s392.au.crucialx.net.

EVENT DETAILS: A security incident has been detected on this server, and some customers sites have been effected. As a result we will be restoring all accounts from our daily backups.

While a forensic investigation is underway, our highest priority is restore all customer accounts from backups. A backup will first be taken of all sites in their current state before we start the restoration. During the restoration your site will be offline for a period of 2-8 hours. During this time we ask you to refrain from submitting tickets until you receive notification that all accounts have been restored.

You will receive a notification just before we start the restoration which we expect to take place in 2-4 hours from now.

NOTE: Crucial Paradigm takes security very seriously and has a large number of measures we use to ensure our customers data stays secure. We will be completing a thorough investigation into why this security incident occurred, and to help prevent such an issue from occurring in future.

UPDATE (18/Sep/2010 1:07PM):
The backup of s392 has been completed, and we will be taking it offline shortly to do an OS re-install, and restore accounts from our backups.

This process will result in your site being offline for between 3-9 hours while we complete the re-installation of the server, and then restoration of all the accounts from backups.
__________________
Aaron Weller
Powered by dare
Crucial Paradigm Staff
Reply With Quote
  #2 (permalink)  
Old 18-09-2010, 01:19 AM
Aaron's Avatar
Hosting Slave
 
Join Date: Dec 2008
Location: Sydney
Posts: 625
Send a message via MSN to Aaron
Default

The backup is taking a little longer than expected, we will complete the restoration from backups once the backups are complete. We expect another few hours before this occurs.
__________________
Aaron Weller
Powered by dare
Crucial Paradigm Staff
Reply With Quote
  #3 (permalink)  
Old 18-09-2010, 03:09 AM
Crucial Tech
 
Join Date: Jan 2010
Posts: 16
Default Quick update

The backup is still running. The backups is being generated in the alphbetical order of usernames. It has now been completed till "g". We will keep you updated here.
Reply With Quote
  #4 (permalink)  
Old 18-09-2010, 06:09 AM
Junior Member
 
Join Date: Sep 2010
Posts: 9
Default

We have reached accounts starting with 'U', expecting this to be finished in few hours.

Gopeekrishnan
Crucial Paradigm
Reply With Quote
  #5 (permalink)  
Old 18-09-2010, 10:05 AM
Member
 
Join Date: Mar 2010
Posts: 64
Default

any updates on this yet?
Reply With Quote
  #6 (permalink)  
Old 18-09-2010, 10:46 AM
Member
 
Join Date: Mar 2010
Posts: 64
Default

my account starts with "c" and it is still showing the muslim hacked stuff....
Reply With Quote
  #7 (permalink)  
Old 18-09-2010, 11:03 AM
Member
 
Join Date: Mar 2010
Posts: 64
Default

if anyone is interested, it seems to be CMS/DB type sites that have been affected on my account. appears to be an index.html file that has been injected, once I delete/rename that file the index.php is active again and all good (as far as I can tell)

edit - has also been sites with index.html files. just restored from my own backup or replaced with a maintenance message. at least there is no sign of being hacked now.

Last edited by cybercomp; 18-09-2010 at 11:25 AM.
Reply With Quote
  #8 (permalink)  
Old 18-09-2010, 11:09 AM
Junior Member
 
Join Date: Sep 2010
Posts: 9
Default

We are taking the backup of accounts starting by 'V'
Mainly the index files of accounts are the affected ones. Any how as a matter of security we will be doing an OS reload after wiping the whole content.

Regards
Gopeekrishnan
Crucial Paradigm
Reply With Quote
  #9 (permalink)  
Old 18-09-2010, 12:39 PM
Member
 
Join Date: Mar 2010
Posts: 64
Default

and to top is off the USA server account I use s369.c4.crucialx.net is down.. what a day!
Reply With Quote
  #10 (permalink)  
Old 18-09-2010, 01:10 PM
Aaron's Avatar
Hosting Slave
 
Join Date: Dec 2008
Location: Sydney
Posts: 625
Send a message via MSN to Aaron
Default

Quote:
Originally Posted by cybercomp View Post
and to top is off the USA server account I use s369.c4.crucialx.net is down.. what a day!
Yes, unfortunately it is. The server went down after we applied a temporary fix to ensure the same thing that happened to s392 does not happen to s369. This worked without any issues on all our servers except for s369. s369 crashed and instead of rebooting and bringing the server online we have had to go through several fscks (unrelated to the original incident).

The specific security issue we experienced was due to a 0day exploit (meaning no fix had been released yet). We managed to find a temporary fix to protect our servers until an official kernel update has been released. We will be providing a full report once the issue has been resolved.
__________________
Aaron Weller
Powered by dare
Crucial Paradigm Staff
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +11. The time now is 03:12 AM.

Powered by vBulletin® Version 3.8.6
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.5.2

Copyright 2003-2010 © Crucial Paradigm Pty Ltd, All Rights Reserved