Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

They were almost certainly impacted by the recent sudo bug, considering how they offered cPanel hosting: https://archive.is/PCZ99 I've been trying to make contact with virtual hosting providers over the last few weeks to bring the weakness to their attention, but I've been ignored. cPanel hasn't even issued an update. It's heartbreaking watching websites get destroyed by the bad guys.


You have my attention, what is this recent sudo bug?


https://news.ycombinator.com/item?id=25919235

As a tip for the future, in case you're interested: you can use hn.algolia.com, search "sudo", time window something like "past month", and you'd have found it.


duckduckgo has a !bang for hacker news `sudo !hn` redirects to hn.algolia.com with the thread at the top of the list


Oh cool, didn't know that!


It is much more efficient and future-proof to have someone put the exact link as a reply, that way people coming to the thread afterwards can simply click on.


I gave the full link, and additionally gave a tip for those who were interested.

hn.algolia.com is a great resource and I'm certain not everybody here knows about it.


I appreciate when you give me the fish, and also show me how to fish (or even remind me where the fish are).


Thanks for teaching these men to fish. I thought I was going to need to do all the explaining.


Not every man needs to fish, we live in a society with specialization. Some people can do the fishing and some can do other things.


Would be nice if everyone knew how to wipe their own ass though.


How do you know they are men?


They don't. They're referring to a famous proverb.


Discussed here: https://news.ycombinator.com/item?id=25919235

Though they would have had to also get into the admin server running (probably) WHMCS.

The sudo bug would let a hacker take over a server where the customer code ran, but not the main admin server. They would have needed some other weakness to get that. Perhaps aided by owning one of the customer servers.


I think it's this one, which came to light last month:

https://www.linux-magazine.com/Online/News/Decade-Old-Sudo-F...

Edited to add: Here's another article about it (you should be able to find quite a few more, too):

https://www.theregister.com/2021/01/26/qualys_sudo_bug/



The sudo package is provided by CentOS and should update fine with yum update. CentOS patched that in late January.

    * Wed Jan 20 2021 Radovan Sroka <rsroka@redhat.com>
    - 1.8.23-10.1
    - RHEL 7.9.Z ERRATUM
    - CVE-2021-3156
    Resolves: rhbz#1917729


Maybe they didn't update? It's "no support" after all...


It's possible they don't have updates running on a cron. It's also possible they got hit in the day or so between the announcement and the automatic installation.

It's even possible that while this seems to be a very likely attack vector that the attacker used something else. One place to look if they had a billing system hit and all their hosting systems is if maybe the billing system got breached first. There are automated provisioning and C&C things built into, say, WHMCS or WHM Autopilot that would be an ideal vector to all the hosting servers if someone breached the billing and provisioning system first.

I don't know how many different individual hosting systems we're talking about. Having a user account to use the sudo vuln on each and every one of them and then also breaching the billing server seems unlikely. It seems more likely the centralized tool was taken over (perhaps using one or a few hosting systems as a springboard) and used to spread to all the hosting systems automatically.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: