Linode Hackers Compromise Passwords, Credit Card Details

Hosting firm Linode has been hit by a hacker group, which accessed the company’s database which held credit card data and passwords.

Linode, which hosts virtual private servers for its customers, believes a group named Hack The Planet (HTP) exploited a vulnerability in Adobe’s ColdFusion application server. It assured users their data was protected with adequate encryption.

Linode hacked

“Credit card numbers in our database are stored in encrypted format, using public and private key encryption,” Linode noted in a blog post.

“The private key is itself encrypted with passphrase encryption and the complex passphrase is not stored electronically.

“Along with the encrypted credit card, the last four digits are stored in clear text to assist in lookups and for display on things like your Account tab and payment receipt emails. We have no evidence decrypted credit card numbers were obtained.”

HTP has claimed it has access to those keys, however, as it was stored on the same server it compromised, as noted in this online transcript showing a conversation between Linode customers and HTP hacker Ryan_.

Even though passwords for the Linode Manager product were salted and hashed, the company reset them anyway.

However, certain passwords for Lish, the Linode Shell, which allows users to access server consoles even when networking is disabled, were stored in plain text on the database. That has been corrected and passwords reset.

“Our entire team has been affected by this, leaving all of us, like you, feeling violated,” Linode added.

If affected Linode customers have reused their Linode passwords on any other services, they should change the passwords on these services too, as HTP could work its way round other services trying the passwords it has acquired.

This is the second time in just over a year a Linode breach has gone public. Last March, servers it hosted were hit and the hackers made off with bitcoins worth hundreds of thousands 0f dollars.

What do you know about Internet security? Find out with our quiz!

Thomas Brewster

Tom Brewster is TechWeek Europe's Security Correspondent. He has also been named BT Information Security Journalist of the Year in 2012 and 2013.

Recent Posts

Craig Wright Sentenced For Contempt Of Court

Suspended prison sentence for Craig Wright for “flagrant breach” of court order, after his false…

2 days ago

El Salvador To Sell Or Discontinue Bitcoin Wallet, After IMF Deal

Cash-strapped south American country agrees to sell or discontinue its national Bitcoin wallet after signing…

2 days ago

UK’s ICO Labels Google ‘Irresponsible’ For Tracking Change

Google's change will allow advertisers to track customers' digital “fingerprints”, but UK data protection watchdog…

2 days ago

EU Publishes iOS Interoperability Plans

European Commission publishes preliminary instructions to Apple on how to open up iOS to rivals,…

3 days ago

Momeni Convicted In Bob Lee Murder

San Francisco jury finds Nima Momeni guilty of second-degree murder of Cash App founder Bob…

3 days ago