• Home
  • Et Cetera

Infosecurity.US

100,000 UK Web Sites Obliterated, Virtualized Zero Day Vulnerability Blamed…

By Marc Handelman on June 10th, 2009

Colorful Zebras

News, overnight, of the apparent destruction, and subsequent data loss, of an estimated one hundred thousand websites hosted in the United Kingdom at VASERV.

Evidence point to a virtulization exploit – at least from the perspective of the ISP (The truth probably resides somewhere between appalling poor security assessment/management/policies and vulnerabilities in their hosted, virtualized platforms,); notwithstanding, we do sympathize with the administrators tasked with bringing these system back online, not to mention the unfortunate data owners. Backups, we don’t need no stinkin’ backups! Woops…

More information (comprised of the original post at The Register, as well as a status page from VASERV, tell the sorry tale) and links appears after the jump.

via El Reg’s Dan Goodin: “Webhost hack wipes out data for 100,000 sites“

“Vaserv suspects zero-day virtualization vuln”

“A large internet service provider said data for as many as 100,000 websites was destroyed by attackers who targeted a zero-day vulnerability in a widely-used virtualization application…” “Technicians at UK-based Vaserv.com were still scrambling to recover data on Monday evening UK time, more than 24 hours after unknown hackers were able to gain root access to the company’s system, Rus Foster, the company’s director told The Register. He said the attackers were able to penetrate his servers by exploiting a critical vulnerability in HyperVM, a virtualization application made by a company called LXLabs…”

—

Old status on index 1 | index 2

FSCKVPS Summary

The following fsck servers have total data loss and we will be inspecting them further later
8 9 13 15 17 21 22 23 25 26 27 30 34 36 41 43 44 45 46 48 50 51 52 54

All other servers should be online.

VAServ Status

US

VZ US West Coast – some of the nodes have been restored while others are being checked and once done full list will be issued
VZ TX – We are still working on either investigating these or having them in the queue for investigation

UK

The following nodes have been restored:
vz1-vz9uk / vz40uk / vz49uk
Beyond that the following servers are still being worked on
vz26uk / vz36uk / vz37uk / vz42uk / vz61uk / vz62uk / vz63uk / vz65uk / vz67uk / vz72uk / vz73uk / vz74uk / vz75uk

If your server is not on the list of our status page that either means:

  • it is being checked currently
  • it is pending for a proper investigation and is in the queue

In case you need support please raise a ticket with http://support.vaserv.com/ but kindly consider high volume of tickets and kindly open tickets for top priority inquiries for the moment. Your patience is well appreciated.

News:
22:19 vz47uk restored
22:21 vz46uk data loss
22:42 Please allow upto 2 hours for a ticket response as currently we have 200+ active tickets
23:02 vz67uk data loss
23:20 vz50uk data restored
23:23 vz51uk data loss
23:43 We currently have people onsite restoring UK servers and installing new servers for the people who have elected to have clean installs. We still have staff working through open support tickets. We will be continuting server restores in approx 90 minutes
00:03 FsckVPS server26 and server27 are still being worked on, but data *appears* to be intact
00:18 FsckVPS server33 is being worked on
00:45 FsckVPS server33 has approximately 50% of data lost. 7 VPSes on this box remain intact.
01:11 Fsckvps server48 has suffered from a complete data loss
01:15 Fsckvps ns1.fsckvps.com and ns2.fsckvps.com are currently being worked on and will be restored if possible.
03:46 Fsckvps at this time server54 and server52 are still under reconstruction/investigation and no further information is available regarding them
04:14 vz20uk no data
04:16 vz31uk fixed
04:26 vz74uk no data
04:31 vz75uk no data
04;44 vz43uk restored
04:56 vz60uk no data
05:08 FsckVPS server26, server27, server52, server54 all 100% data lost.
05:09 FsckVPS server33 being worked on, DNS being worked on.
05:21 FsckVPS dns servers will be alive in an eta of 15 minutes. (basic dns service).
05:32 FSCKVPS DNS is now resyncing
05:33 A general status report now follows FSCKVPS – Its about as good as its going to get so we are now starting to tackle individual issues
VAServ West Coast – Restored as its going to get
Texas – We are waiting for TMS to finish reloading. We have 7 or so servers still down there VAServ Atlanta – We still have vzspecial* to go over but other servers in the DC are up
VAServ UK – We have about 10 servers left to do
To place this into context in the last 36 hours we have recommissioned approx 180 servers and restored approx 2000 VPS using a standard config. If you are seeing disk space/memory issues please let us know via ticket. We will be going round sorting out correct quotas when things are quieter but for now people will be given allocations that would generally be above their default just so they can work.i
05:48: New/replacement builds. We have approx 300 customers wanting new VPS. We are going to start building these on the UK servers BSQ have lent us
07:42 vz26uk restored
07:55 vz14tx restored
07:56 vz2tx data loss
08:08 vz4tx restored
08:16 vz6x restored
08:19 vz8tx data loss
13:00 vzspecial1,2,4,5,7 restored 3,6,8 has suffered a data loss
13:01 vz37uk restored
13:20 vz63uk.vaserv.com restored
13:30 vz72 restored
We are going to finish up the final few UK nodes then go over all the other nodes top to bottom to clean out any problems that have arisen. Please excuse the spelling as currently most of us have been pulling double/triple shifts.
13:33 vz65uk restored
15:40 vz10uk has been reloaded and complete data loss has been determined
17:32 Dear Customer,

We have worked tirelessly through the night and over the last 48 hours to recover as many VPS as possible. However, we have now reached the end of all of our servers, and as such, if your server is not currently up, or not partly up (i.e. it is up but not working due to a configuration issue) then it is unfortunate that you will have lost your data due to this third party attack.

We are offering all customers who have lost data a brand new VPS on our new platform. If you are in the position of requiring a new VPS due to your old one not coming back up, please submit a support ticket with the subject ‘New VPS Required’, and including the specification you ordered in the message. We will then start to provision these straight away. We will aim to have all new servers up within 6 hours at the latest, of course providing no new issues occur. If you have your own backups you can then restore these onto the new VPS.

We will also be providing two months free hosting as compensation to customers that have lost data and require a new VPS.

We apologise for any inconvenience caused, and your patience and understanding in these very difficult times.
Regards, VAServ Team.

21:03 vz54uk dead/100% loss
21:05 vz51uk dead/100% loss
21:08 All failed 100% vz16uk / vz22uk / vz28uk / vz32uk / vz38uk / vz41uk / vz57uk / vz59uk / vz66uk
21:11 A batch of new uk vps’s have been delivered to VASERV customers. This does not cover all request, more will be done.
21:29 FsckVPS: We still ask that customers only have one ticket open and only update that ticket. This will help track each clients individual needs. ETA for ticket response time is currently 2 hours.
22:10 Extra Staff called into both locations to help with tickets responses. We currently have about 600 tickets open between our brands. Were still attempting a 2 hour response time for tickets.

Reblog this post [with Zemanta]

Categories: Infosecurity
Tags: Access Providers, Domain Name System, HyperVM, Internet service provider, Virtual private server, Virtulization Security, Zero day attack

Related Headlines

    Related posts:

    1. OSF Moves To Manage Data Loss DB
    2. WordPress 2.7.1 Released
    3. Steganographic Discoveries Lead To New Data Hiding Vectors
    4. Microsoft, TMobile Have, Umm… Issues
    5. Federal Prosecutors File Charges Against Key Players in TJMAX, DSW and OfficeMax Dataloss Debacles

2 Responses to �,000 UK Web Sites Obliterated, Virtualized Zero Day Vulnerability Blamed…”

  1. Bart Hopper
    Jun 10th, 2009 at 09:06

    100K UK Websites obliterated. Virtualized 0-day blamed. http://infosecurity.us/?p=9130

  2. subdriven
    Jun 10th, 2009 at 17:16

    RT @d4ncingd4n: 100K UK Websites obliterated. Virtualized 0-day blamed. http://infosecurity.us/?p=9130

« Dilbert: Scott’s Birthday Microsoft Updates MAC Office To 12.1.9 »
  • Latest
  • Random
  • Bookmarks
  • Archives
  • Steve Benson: Persian Lights…
  • New, Pernicious BotNet Emerges
  • VMWare Announces ESX Console Security Update
  • Nick Anderson: Egg
  • Doppelgänger Infinitus
  • Robert Ariall: Iran For Cover
  • Data Leakage Wednesdays: Old Printer Vector
  • XKCD: Exoplanets
  • Apple Releases Magic Footpad, Raises Ante On Bipedal Computer Controls
  • Science Tuesday: Asteroidal Discoveries Mapped, 01980 – 02010
  • Microsoft Announces Upcoming Patch Tuesday Update Fest
  • US Targets Chinese State-Sponsored Hacker Responsible For Google Break-In
  • Adobe Security Updates For Compromised Acrobat and Reader Released
  • Metasploit Framework 3.4.0 Released
  • VMWare Releases Security Notification
  • BlackHat: Kaminsky’s Grandmother Bakes Session Cookies
  • Space Agency Network Security Challenges Revealed
  • XKCD: Geeks and Nerds
  • Chip Bok: Apology Channel
  • XKCD: Poisson Distribution
  • Apple
  • BSD
  • Closson
  • Darknet
  • Debian
  • Finnigan
  • ha.ckers
  • Hoff
  • Insecure
  • Krebs
  • Layer8
  • MSRC
  • Network Security Blog
  • NSA SEL
  • openSUSE
  • RedHat
  • SANS
  • Schneier
  • Security Eunoia
  • Securosis
  • Shimel
  • September 2010
  • August 2010
  • July 2010
  • June 2010
  • May 2010
  • April 2010
  • March 2010
  • February 2010
  • January 2010
  • December 2009
Subscribe

Featured Blog - Blogs.com SANS Security Reading Room KnotOriginal: fine art to hang on your body and walls Member - Security Bloggers Network

Dilbert

KnotOriginal

Featured Video

QOTD

RSS Security Bloggers Network

  • Two Wheel EV Recumbant: Zerotracer 2010/09/02 Davi Ottenheimer
  • Ben Franklin’s Endpoint Security Advice 2010/09/02 Jeff Hughes
  • Configuring Conditional SSH Connections 2010/09/02 Xavier
  • Truecrypt and USB drives 2010/09/02 always peace
  • LogChat Podcast 1: Anton Chuvakin and Andrew Hay Talk Logs 2010/09/02 Andrew Hay
  • Safe Web Surfing Rule # 1: READ the URL 2010/09/02 Tom Kelchner
  • Heartland Set To Pay Discover $5M For 2008 Data Breach 2010/09/02 spinman
  • User’s Opinions on Malware Infections 2010/09/02 spinman
  • Acunetix Web Vulnerability Scanner 7 Released 2010/09/02 spinman
  • LogChat Podcast 1: Anton Chuvakin and Andrew Hay Talk Logs 2010/09/02 Anton Chuvakin

RSS Cryptography

  • Monitor: Schrodinger's cat and mouse 2010/09/02
  • How to configure a Junos security device 2010/09/02
  • Net Effect: Hay-what? 2010/09/02
  • The Art of Proof 2010/09/02
  • Quantum crypto cracked, researchers say 2010/09/01

RSS SANS ISC

  • Microsoft EMETv2 released, (Thu, Sep 2nd) 2010/09/02
  • SDF, please!, (Thu, Sep 2nd) 2010/09/02
  • Month of Undisclosed 0-day Bugs, (Wed, Sep 1st) 2010/09/01
  • Microsoft issues updates to sysinternals ProcDump and Process Monitor: http://blogs.technet.com/b/sysinternals/archive/2010/08/30/updates-procdump-process-monitor-and-a-new-mark-s-blog-post.aspx, (Wed, Sep 1st) 2010/09/01
  • VMWARE releases 2 security advisories for ESX Service Console: http://lists.vmware.com/pipermail/security-announce/2010/000103.html and http://lists.vmware.com/pipermail/security-announce/2010/000104.html, (Wed, Sep 1st) 2010/09/01

RSS Oracle

  • Going to Oracle OpenWorld 2010? 2010/09/02
  • Automatic Time Zone support in Application Express 4.0 2010/09/02
  • EBS, Collaborate, Security, BPEL, OWB, Blog of Note, Hyperion, EPM, Burnout, WiFi 2010/09/02
  • Details of Tuxedo sessions at OOW 2010/09/02
  • JavaOne Preview on TechCast Live! (Tues., Sept. 7, 10am PT) 2010/09/02
  • links for 2010-09-02 2010/09/02
  • Join us for a Bersin & Associates Webcast - "Evolution of ERPs: Driving Business Value through Integrated Talent Management" 2010/09/02

RSS MySQL

  • Join MySQL at OSCON 2010/07/02
  • TechCast Live: Jono Bacon and Luke Kowalski on MySQL Community 2010/05/21
  • What's New in the MySQL Enterprise Spring 2010 Release? - Interview with Mark Matthews and Andy Bang 2010/05/17
  • Introduction to MySQL 5.5 2010/04/13
  • Why Should I Check Out a MySQL-Based Column Database ? 2010/02/12
  • A deep look at MySQL 5.5 partitioning enhancements 2009/12/24
  • Sun "Tech Days" Conference World Tour Kicks Off in Brazil 2009/12/07

RSS Linux

  • A Guide to Today's Top 10 Linux Distributions - NetworkWorld.com 2010/09/02
  • Embedded Linux Conference videos available - LWN.net 2010/09/02
  • Net Applications' iOS vs Linux Report Confuses Me - Muktware (blog) 2010/09/02
  • Cloudlinux Named Editor's Choice By Web Host Magazine & Buyer's Guide - PR Urgent 2010/09/02
  • Samsung's 3D TV remote let's you take the screen with you - Geek.com 2010/09/02

RSS MAC OSX

  • Samsung Reveals Half-Pint iPad, The Galaxy Tab 2010/09/02 Eli Milchman
  • Daily Deals: New nano, touch and Apple TV 2010/09/02 Ed Sutherland
  • iPhone 4 Coffee Table Gets You Better Reception Than iPod Table? 2010/09/02 Nicole Martinelli
  • Walkman Outsells iPods in Japan, Can Wristwatch Nano Change That? 2010/09/02 Nicole Martinelli
  • Amazon: Buy – Don’t Rent – 99-Cent Fox, ABC TV Episodes 2010/09/02 Ed Sutherland
  • Analyst: New Apple TV Rival for Cable’s Video-on-Demand 2010/09/02 Ed Sutherland
  • iTunes Ping And Facebook: What’s Going On? 2010/09/02 Giles Turnbull

RSS Microsoft

  • Update on Security Advisory 2269637 2010/08/31 MSRCTEAM
  • Microsoft Security Advisory 2269637 Released 2010/08/22 MSRCTEAM
  • August 2010 Webcast and QA 2010/08/12 MSRCTEAM
  • Update on the publicly disclosed Win32k.sys EoP Vulnerability 2010/08/10 MSRCTEAM
  • August 2010 Security Bulletin Release 2010/08/10 MSRCTEAM
  • August 2010 Bulletin Release Advance Notification 2010/08/05 MSRCTEAM
  • August 2010 Out-of-Band Security Release Webcast Q&A 2010/08/03 MSRCTEAM

RSS Network

  • How to get started with a blade system 2010/09/02
  • Opsview Community Edition review 2010/09/02
  • Cacti review 2010/09/02
  • Brocade adds 100G Ethernet to switch and router line 2010/09/02
  • Is Cisco making a play for Skype? 2010/08/31
  • Skype launches Skype Connect enterprise voice calling 2010/08/31
  • Sonos ZonePlayer S5 review 2010/08/25

Daily Posts

September 2010
S M T W T F S
« Aug    
 1234
567891011
12131415161718
19202122232425
2627282930  
Creative Commons License
The Infosecurity.US Blog is licensed under a Creative Commons Attribution-Share Alike 3.0 United States License.

Find the best blogs at Blogs.com.

Creative Commons Attribution-Share Alike 3.0 U.S. License ©2010 Infosecurity.US

Subscribe