<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	
	xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>The Inquisitr &#187; Vaserv</title>
	<atom:link href="http://www.inquisitr.com/tag/vaserv/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.inquisitr.com</link>
	<description>The Better Mix</description>
	<lastBuildDate>Tue, 14 Feb 2012 15:54:43 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>UPDATE: New information on the Vaserv hack that wiped 100K sites</title>
		<link>http://www.inquisitr.com/25617/update-new-information-on-the-vaserv-hack-that-wiped-100k-sites/</link>
		<comments>http://www.inquisitr.com/25617/update-new-information-on-the-vaserv-hack-that-wiped-100k-sites/#comments</comments>
		<pubDate>Tue, 09 Jun 2009 21:13:02 +0000</pubDate>
		<dc:creator>Steven Hodson</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Vaserv]]></category>

		<guid isPermaLink="false">http://www.inquisitr.com/25617/update-new-information-on-the-vaserv-hack-that-wiped-100k-sites/</guid>
		<description><![CDATA[<br />Earlier I wrote about how the UK based Vaserv.com was hacked and had over 100,000 sites deleted from their servers. At that time I, and other tech news sites, were under the impression that it had something to do with virtualization software from LxLabs, whose boss was found hanged on Monday morning. It turns out, [...]<p><a href="http://www.inquisitr.com/25617/update-new-information-on-the-vaserv-hack-that-wiped-100k-sites/">UPDATE: New information on the Vaserv hack that wiped 100K sites</a> is a post from: <a href="http://www.inquisitr.com">The Inquisitr</a></p>
<br /><br /><br />]]></description>
			<content:encoded><![CDATA[<p> <center><img title="hackedjq6" border="0" alt="hackedjq6" src="http://www.inquisitr.com/wp-content/hackedjq6.jpg" width="321" height="122" /></center>  </p>
<p>Earlier <a href="http://www.inquisitr.com/25590/after-100k-sites-wiped-clean-lxlabs-boss-found-hanged/">I wrote about how the UK based Vaserv.com was hacked</a> and had over 100,000 sites deleted from their servers. At that time I, and other tech news sites, were under the impression that it had something to do with virtualization software from LxLabs, whose boss was found hanged on Monday morning. It turns out, if the information provided in the comments of that original post is correct, that it may have been a more directed attack that had nothing to do with the LxLabs software.</p>
<p>This is the comment as it showed up under the original post</p>
<p><img style="border-right-width: 0px; display: block; float: none; border-top-width: 0px; border-bottom-width: 0px; margin-left: auto; border-left-width: 0px; margin-right: auto" title="pastebin" border="0" alt="pastebin" src="http://www.inquisitr.com/wp-content/pastebin.png" width="495" height="116" /> </p>
<p>So being the curious type of person I am I checked out the link and this is part of what I found</p>
<blockquote><ol>
<li>
<p>Z3r0 day in hypervm?? plz u give us too much credit. If you really really wanna know how you got wtfpwned bitch it was ur own stupidity and excessive passwd reuse. Rus&#8217;s passwds are          </p>
<p>Code:           </p>
<p>e2x2%sin0ei unf1shf4rt 3^%3df 1/2=%mod5 f0ster           </p>
<p>f0ster being the latest one, quite secure eh bitches? We were in ur networks sniffing ur passwds for the past two months quite funny this openvz crap is we could just get into any VPS we like at any time thanks to ur mad passwds. But we got bored so we decided to initiate operation rmfication and hypervm was a great t00l to do that since it spared us the time of sshing into all ur 200 boxen just to issue rm -rf. Coded a little .pl to do just that, take a look at this eleet output it&#8217;s mad dawg           </p>
<p>Code:           </p>
<p>[root@vz-vaserv .ssh]# perl h.pl -user admin -pass ****off -host cp.vaserv.com -cmd &#8216;rm -rf /* 2&gt; /dev/null &gt; /dev/null &amp;&#8217; [+] Attempting to login using admin / ****off [+] Logged in, showtime!</p>
</li>
</ol>
</blockquote>
<p>Further down the outputted file there is some additional smack talk for the Vaserv guys</p>
<blockquote><p>Did the same fo ****vps.com after resetting the passwd to hyper ve emz, it was ever so much fun you should try it sometime Rus it&#8217;s GREAT!      </p>
<p>BTW to all the customers we deleted ur loving provider is overselling their crappy 8gb nodez to hell and back, thought you&#8217;d like to know, you can also thank ur loving buddy Rus for losing ur data hihi. BTW Rus we still have ur billing system wtfpwned and baqdoored we got shitload of CCz from ur retarded customers thanks a lot buddy. Telling you this cuz we got bored of this ****, it&#8217;s just too easy and monotonous so patch ur crap, if your too dumb to secure a simple web server my rate is $100/hour or one night with ur sister hauhaiahiaha. </p>
<p>Also wheres ur team Rus? the only ****ers i saw in ur billing sys are Kody, Vlada and u you guys work like ****ing hindus i bet but ur cheap like jews lolz hire some pros like me to help you out manage all those retards VPSs lolololl </p>
<p>Code: 1 1 rghf c32f3310baffcb431875a67196e99ebd Rus F zswlxxoomx@nowmymail.com 0 , Edit Delete 3 1 vlada c32f3310baffcb431875a67196e99ebd Vlada Neskovic zswlxxoomx@nowmymail.com 0 , Edit Delete 4 1 Kody fde67637d867c52d739931528dd92ef0 Kody Riker zswlxxoomx@nowmymail.com Georgia &#8211; server22 space 1slot 1gb 0 , </p>
<p>See we care about ur privacy and edited ur emailz unlike you who do not care about the privacy of ur retarded customers lol</p>
</blockquote>
<p>If the folks who actually did this read this and want to pass along any additional info about what happened with the Vaserv servers you can contact me at <a title="WinExtra" href="http://www.winextra.com/">winextra</a> <a href="http://twitter.com/">@</a>  gmail.com – confidentiality assured.</p>
<p><a href="http://www.inquisitr.com/25617/update-new-information-on-the-vaserv-hack-that-wiped-100k-sites/">UPDATE: New information on the Vaserv hack that wiped 100K sites</a> is a post from: <a href="http://www.inquisitr.com">The Inquisitr</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.inquisitr.com/25617/update-new-information-on-the-vaserv-hack-that-wiped-100k-sites/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
	
		<media:thumbnail url="http://www.inquisitr.com/wp-content/hackedjq6.jpg" />
		<media:content url="http://www.inquisitr.com/wp-content/hackedjq6.jpg" medium="image">
			<media:title type="html">hackedjq6</media:title>
		</media:content>
		<media:content url="http://www.inquisitr.com/wp-content/pastebin.png" medium="image">
			<media:title type="html">pastebin</media:title>
		</media:content>
	</item>
	</channel>
</rss>

