<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>深度VPS &#187; 被黑</title>
	<atom:link href="http://www.deepvps.com/tag/%E8%A2%AB%E9%BB%91/feed" rel="self" type="application/rss+xml" />
	<link>http://www.deepvps.com</link>
	<description>专注VPS技术，关注前端技术</description>
	<lastBuildDate>Sat, 04 Feb 2023 14:00:33 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>全球主机交流论坛 hostloc.com 再次被黑？</title>
		<link>http://www.deepvps.com/hostloc-forum-is-dns-hijacking.html</link>
		<comments>http://www.deepvps.com/hostloc-forum-is-dns-hijacking.html#comments</comments>
		<pubDate>Sun, 25 Sep 2011 13:06:10 +0000</pubDate>
		<dc:creator>deepvps</dc:creator>
				<category><![CDATA[网络杂谈]]></category>
		<category><![CDATA[DNS劫持]]></category>
		<category><![CDATA[hostloc]]></category>
		<category><![CDATA[全球主机交流论坛]]></category>
		<category><![CDATA[被黑]]></category>

		<guid isPermaLink="false">http://www.deepvps.com/?p=869</guid>
		<description><![CDATA[晚上闲来无事，想上hostloc.com转转，结果发现hostloc居然再次被黑了。后来在群里了解到，这次事件不是被黑，据说是DNS被劫持了。DNS被劫持事件比较有名的就是上次百度域名被伊朗黑客劫持。
DNS劫持：
DNS劫持又称域名劫持，是指在劫持的网络范围内拦截域名解析的请求，分析请求的域名，把审查范围以外的请求放行，否则返回假的IP地址或者什么都不做使请求失去响应，其效果就是对特定的网络不能反应或访问的是假网址。


]]></description>
			<content:encoded><![CDATA[<p>晚上闲来无事，想上hostloc.com转转，结果发现hostloc居然再次被黑了。后来在群里了解到，这次事件不是被黑，据说是DNS被劫持了。DNS被劫持事件比较有名的就是上次百度域名被伊朗黑客劫持。</p>
<p><strong>DNS劫持：</strong></p>
<blockquote><p>DNS劫持又称域名劫持，是指在劫持的网络范围内拦截域名解析的请求，分析请求的域名，把审查范围以外的请求放行，否则返回假的IP地址或者什么都不做使请求失去响应，其效果就是对特定的网络不能反应或访问的是假网址。</p></blockquote>
<p><span id="more-869"></span><br />
<a href="http://www.deepvps.com/wp-content/uploads/2011/09/hostloc-hacked.jpg"><img class="aligncenter size-full wp-image-870" title="hostloc-hacked" src="http://www.deepvps.com/wp-content/uploads/2011/09/hostloc-hacked.jpg" alt="" width="610" height="374" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.deepvps.com/hostloc-forum-is-dns-hijacking.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>悲剧：hostloc论坛被黑</title>
		<link>http://www.deepvps.com/hostloc-forum-is-hack.html</link>
		<comments>http://www.deepvps.com/hostloc-forum-is-hack.html#comments</comments>
		<pubDate>Tue, 07 Jun 2011 14:47:04 +0000</pubDate>
		<dc:creator>deepvps</dc:creator>
				<category><![CDATA[网络杂谈]]></category>
		<category><![CDATA[hostloc]]></category>
		<category><![CDATA[被黑]]></category>

		<guid isPermaLink="false">http://www.deepvps.com/?p=822</guid>
		<description><![CDATA[前天晚上hostloc论坛被黑，访问论坛的时候变成了 403错误。

起因是因为论坛挂KT的广告，然后有一位会员和管理吵架，说KT是骗子。 结果账号被管理员封了， 封了没多久，论坛就被黑了， 论坛首页就出现了：
感谢ccav 感谢方院长让我翻了好几层墙..感谢cpuer 封了我的帐号.感谢domin记住了我
感谢nbvps emsvps vpsyou diavps d9vps 印迹vps 阿川vps vpszz..ktp2008:谁让你挂骗子广告了其实我最感谢debian教会我的超级无敌大ddos..回头帮你update成dabian(大便)请不要ddos我..黑阔你伤不起..
最后谢谢你们给我次出名的机会 hacked by kpt2008 kt是骗子广告..请尽快撤下..
5分钟之后 系统自动rm -rf /*

]]></description>
			<content:encoded><![CDATA[<p>前天晚上hostloc论坛被黑，访问论坛的时候变成了 403错误。</p>
<p><img title="hostloc论坛被黑" src="http://www.deepvps.com/wp-content/uploads/auto_save_image/2011/06/224705mvv.png" border="0" alt="hostloc论坛被黑" width="258" height="125" /></p>
<p>起因是因为论坛挂KT的广告，然后有一位会员和管理吵架，说KT是骗子。 结果账号被管理员封了， 封了没多久，论坛就被黑了， 论坛首页就出现了：<span id="more-822"></span></p>
<blockquote><p>感谢ccav 感谢方院长让我翻了好几层墙..感谢cpuer 封了我的帐号.感谢domin记住了我</p>
<p>感谢nbvps emsvps vpsyou diavps d9vps 印迹vps 阿川vps vpszz..ktp2008:谁让你挂骗子广告了其实我最感谢debian教会我的超级无敌大ddos..回头帮你update成dabian(大便)请不要ddos我..黑阔你伤不起..</p>
<p>最后谢谢你们给我次出名的机会 hacked by kpt2008 kt是骗子广告..请尽快撤下..</p>
<p>5分钟之后 系统自动rm -rf /*</p></blockquote>
<p><a href="http://www.xianzhong.net/wp-content/uploads/2011/06/YAT8EZZ0ATRMCU3GEFD1.jpg" target="_blank"><img title="hostloc论坛被黑" src="http://www.deepvps.com/wp-content/uploads/auto_save_image/2011/06/224706OWP.jpg" border="0" alt="hostloc论坛被黑" width="584" height="102" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.deepvps.com/hostloc-forum-is-hack.html/feed</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
		<item>
		<title>PHP代码源被黑</title>
		<link>http://www.deepvps.com/php-code-source-was-hack.html</link>
		<comments>http://www.deepvps.com/php-code-source-was-hack.html#comments</comments>
		<pubDate>Fri, 25 Mar 2011 13:13:02 +0000</pubDate>
		<dc:creator>deepvps</dc:creator>
				<category><![CDATA[网络杂谈]]></category>
		<category><![CDATA[php]]></category>
		<category><![CDATA[SVN]]></category>
		<category><![CDATA[wiki]]></category>
		<category><![CDATA[代码]]></category>
		<category><![CDATA[代码源]]></category>
		<category><![CDATA[漏洞]]></category>
		<category><![CDATA[被黑]]></category>

		<guid isPermaLink="false">http://www.deepvps.com/?p=748</guid>
		<description><![CDATA[源头在于wiki.php.net的漏洞导致wiki账号被盗，而wiki的账号和php代码源的SVN提交权限相关联。
有图有真相：

　　原文：
　　The wiki.php.net boxwas compromised and the attackers were able to collect wiki account credentials. No other machines in the php.net infrastructure appear to have been affected. Our biggest concern is, of course, the integrity of our source code. We did an extensive code audit and looked at every commit since 5.3.5 to make sure that [...]]]></description>
			<content:encoded><![CDATA[<p>源头在于wiki.php.net的漏洞导致wiki账号被盗，而wiki的账号和php代码源的SVN提交权限相关联。<br />
有图有真相：</p>
<p><img src="http://www.deepvps.com/wp-content/uploads/auto_save_image/2011/03/131403twz.jpg" alt="" height="298" /><span id="more-748"></span></p>
<p>　　原文：</p>
<p>　　The wiki.php.net boxwas compromised and the attackers were able to collect wiki account credentials. No other machines in the php.net infrastructure appear to have been affected. Our biggest concern is, of course, the integrity of our source code. We did an extensive code audit and looked at every commit since 5.3.5 to make sure that no stolen accounts were used to inject anything malicious. Nothing was found. The compromised machine has been wiped and we are forcing a password change for all svn accounts.<br />
　　We are still investigating the details of the attack which combined a vulnerability in the Wiki software with a Linux root exploit.</p>
<p>　　内容大致是：</p>
<p>　　由于wiki账号被盗，PHP的代码源极有可能被污染，当然，PHP团队已经做最大的努力以保证自PHP5.3.5版本的代码没有收到污染，并且强迫SVN修改现有的密码。</p>
<p>　　而事件目前的状态是，他们仍然没法锁定漏洞所在，因为他们仍在排查。</p>
<p>　　一个很明显的问题是，PHP5.3.6以及其后续版本的代码已经被污染，目前只能把未受污染的代码版本确保到PHP5.3.5，下载PHP代码的人，要小心了。</p>
<p>　　而windows.php.net和wiki.php.net也已经暂停访问。</p>
]]></content:encoded>
			<wfw:commentRss>http://www.deepvps.com/php-code-source-was-hack.html/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>安全警报：Virpus 19台母机被黑，数据全部丢失。</title>
		<link>http://www.deepvps.com/virpus-security-breach-nineteenth-servers-data-loss.html</link>
		<comments>http://www.deepvps.com/virpus-security-breach-nineteenth-servers-data-loss.html#comments</comments>
		<pubDate>Sat, 22 Jan 2011 15:25:51 +0000</pubDate>
		<dc:creator>deepvps</dc:creator>
				<category><![CDATA[网络杂谈]]></category>
		<category><![CDATA[virpus]]></category>
		<category><![CDATA[数据丢失]]></category>
		<category><![CDATA[母机]]></category>
		<category><![CDATA[被黑]]></category>

		<guid isPermaLink="false">http://www.deepvps.com/?p=704</guid>
		<description><![CDATA[Virpus 从2006年就开始销售VPS，算一家“老“ VPS主机商了。deepvps也曾多次介绍过他们家。今天收到他们的邮件公告，他们的19台母机被黑，只有一台数据部分丢失，剩下的18台数据完全丢失。真是惨不忍睹啊。如果还有用他们家VPS的同学，抓紧自己备份数据啦。
先全文转载如下：
Dear Customers,
We regret to inform you that Virpus has had a security breach in our network, which has caused ~19 servers to have complete or partial data loss. There is only one server that has had partial data loss.
The list of nodes is as follows:
masi
hale
anderson
george
murphy
gemini
glacier
titan
willett (partial &#8211; VM&#8217;s are still running)
capricorn
clix
valarius
barksdale
robles
goss
olsen
wright
lang
royal
We know how [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://virpus.com/" target="_blank">Virpus</a> 从2006年就开始销售VPS，算一家“老“ VPS主机商了。deepvps也曾多次介绍过他们家。今天收到他们的邮件公告，他们的19台母机被黑，只有一台数据部分丢失，剩下的18台数据完全丢失。真是惨不忍睹啊。如果还有用他们家VPS的同学，抓紧自己备份数据啦。</p>
<p>先全文转载如下：</p>
<blockquote><p>Dear Customers,</p>
<p>We regret to inform you that Virpus has had a security breach in our network, which has caused ~19 servers to have complete or partial data loss. There is only one server that has had partial data loss.</p>
<p><span id="more-704"></span>The list of nodes is as follows:</p>
<p>masi<br />
hale<br />
anderson<br />
george<br />
murphy<br />
gemini<br />
glacier<br />
titan<br />
willett (partial &#8211; VM&#8217;s are still running)<br />
capricorn<br />
clix<br />
valarius<br />
barksdale<br />
robles<br />
goss<br />
olsen<br />
wright<br />
lang<br />
royal</p>
<p>We know how the culprit(s) gained access and have recorded their IP&#8217;s although there are high chances that the IP&#8217;s could be spoofed. The point of attack has been cured. Virpus will be undergoing a complete security revamp in every aspect and will bring in a third party security expert to assist.</p>
<p>Virpus will offer any customers who are on these nodes who wish to resume services a 2 month credit on their services with us due to this. If you wish to get services again, please open a ticket with Sales.</p>
<p>I have helped build this company from the ground up, and it is especially painful for me to see such an event. I would like to apologize to our customers for this, and hope that we can move forward. This hurts both our customers and us as a company, and we will try to pursue all possible legal ways to find who did this.<br />
__________________<br />
Kenneth Odem<br />
CEO/Co-Founder<br />
Virpus Networks, Inc.<br />
1-877-484-7787 ext 83</p></blockquote>
<p>文中提到的补偿方案也不是很给力。补偿如下：</p>
<p>1，如果想继续使用他们家VPS的，需要客户在后台发ticket联系sales给补偿2个月时间。</p>
<p>2，如果不想用他们家VPS的，给提供部分退款。deepvps 个人觉的此次事件对Virpus打击甚大。<span style="color: #ff0000;">有还在用他们家VPS的同学抓紧时间自己备份，数据安全不能指望主机商，只能靠自己，切记切记。 </span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.deepvps.com/virpus-security-breach-nineteenth-servers-data-loss.html/feed</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
	</channel>
</rss>
