NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Security / Incidents

Incidents


VAServ Hack Results in Massive Data Loss

Zero-day vulnerability in virtualization software exploited to delete server data

By Lucian Constantin, Web News Editor

9th of June 2009, 10:13 GMT

Adjust text size:


Low-cost VPS provider hit by hackers via 0-day vulnerability
Enlarge picture
A 0-day vulnerability in HyperVM, a virtualization application produced by Lxlabs, led to a major hack on the servers of VAServ, a UK-based hosting provider. The attackers obtained root access and wiped large portions of the data.

VAServ is a low-cost virtual private server (VPS) provider serving thousands of customers. The company has servers located both in the UK and the US. On Sunday evening, unknown hackers exploited a vulnerability in the HyperVM software used by the company and obtained administrative permissions on its systems.

The perpetrators then proceeded to delete data from tens of UK and US servers. Company staff were alerted by the suspicious activity and intervened, but the damage was already done. They have since been working 24/7 to restore what they can, but it's likely that some of the data has been lost forever.

Rus Foster, the company's CEO, noted that about 50 percent of customers did not sign up for managed services, meaning they did not benefit from automatic backup. Those users might never be able to recover their data, unless they backed it up themselves.

This attack comes after last Thursday someone anonymously published exploit code for a staggering 24 high-risk unpatched vulnerabilities in the Kloxo software, also developed by Lxlabs. Kloxo Enterprise is a web-based central management platform with the ability to "manage 100s of thousands of domains on hundreds of servers," according to the vendor.

There is no confirmation yet, but it is likely that VAServ was also using this software for managing its HyperVM-based infrastructure and one of these publicly disclosed vulnerabilities represented the point of entry.

The unknown individual who disclosed these flaws claimed that the vendor was unresponsive to their reports. According to him, he originally notified Lxlabs on 21 May and received a confirmation from it. On 4 June, however, he wrote, "Nothing heard from vendor, and the private resource containing the vulnerability info still does not appear to have been accessed." This led him to conclude that the "vendor appears uninterested."

According to The Register, Foster also attempted to contact Bangalore-based Lxlabs about the vulnerability, but did not receive any response. "I've heard from other people they've been hit by the same thing," he notes.

Meanwhile, Lxlabs' founder and owner, K T Ligesh, was found dead in his house yesterday, in what appears to be a case of suicide by hanging. His best friend reported that the night before he drank heavily and was depressed over losing an important contract and the suicide of his mother and sister five years ago.

TAGS:

HyperVM | VAServ | Lxlabs | 0-day vulnerability | data loss
Read by 3,462 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Excellent (5.0/5) 2 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Online Merchant's Server Hacking Results in Data Breach

Two U.S. Army Servers Compromised by Turkish Hackers

Orange French Portal Hacked

Hacker Delivers Fatal Blow to Major Flight Sim Website

A 'Monstrous' Data Breach

New Mass Web Attack Makes 40,000 Victims

Gumblar Morphs, Becomes Martuz

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM