amuck-landowner

Recent content by Steven

  1. S

    Easy DCIM Released

    Not true. We tried to evaluate it and the development installation they (MG) provided had issues. We tried to get it resolved but communication dropped off. We would like to be involved, but the logistics of it is not working out.
  2. S

    SolusVM Security Update (1.16.11)

    Partially right. I'll elaborate.  You can audit code all day long, but there are some kinds of vulnerabilities that can be missed during a code audit. I don't believe in merely a code audit. We have a multi-faceted approach. The audit starts off with a check list where we go through an entire...
  3. S

    SolusVM update - 1.16 - Security and Features!

    Given that the frontend to virtualizor runs php as root I wouldn't say virtualizor is that great to begin with. Any commend injection exploit or sqli could grant root access to the node.
  4. S

    SolusVM update - 1.16 - Security and Features!

    It is very important that you update to this release :)
  5. S

    Vendor Manager Plugin for WHMCS - Beta Testers Wanted

    Sounds like a great way to get your entire infrastructure pwnt. Hopefully you guys have done relevant code review to ensure its not full of goatse sized security holes.
  6. S

    Fiberhub running on generator power

    I refuse to take cabs there when I fly in. I rent a car, and rental return is literally around the block from the airport.
  7. S

    Fiberhub running on generator power

    I have to say in the past 6 months his communication has really stepped up. I haven't really had a single issue. We had a minor outage on B power due to an electrical contractor turning off the POST ups power. It affected one of my racks because the rack level ats is lazy and I run on B primary...
  8. S

    URPad Claiming new WHMCS Vuln

    We haven't heard or seen anything. They probably got hacked and don't know how and are making assumptions.
  9. S

    Seems like UrPad was hit by the IPMI Vuln.

    Same parent company - Root Level Tech
  10. S

    SEMOWeb hacked and nodes wiped

    And this is why you should at least be a tad bit intelligent and lock this shit down to the point it is not accessible on the internet publicly.
  11. S

    Kloxo installations compromised

    Yes its related to an old hack. http://forum.lxcenter.org/index.php?t=msg&th=19215&goto=102646&#msg_102646 in specific. Its being done via the webcommand.php which also calls those functions.
  12. S

    Kloxo installations compromised

    It appears to be an sql Injection:   They are getting access the admin  user:   They are injecting files using display.php   NOTE: default.php is being injected into 'every' account.
  13. S

    Kloxo installations compromised

    Null 178.248.23.0/24 on your network everyone.
  14. S

    Kloxo installations compromised

    Important to note that the default.php file is owned by root.
Top
amuck-landowner