Jump to content
Matt

Top server host OVH warns of 'multi-stage' hacking attack

Recommended Posts

Posted

'Higher level of paranoia' suggests EU and US users should change passwords

French-based server host OVH has warned that its systems have been penetrated in a multi-stage attack that leaves US and European customers at risk.

In an advisory on its forum board, the company warned that an attacker had gained control of a system administrator's account, and used that to gain access to a VPN account of one of the firm's backoffice staff. This was used to get the personal data of customers in Europe and from a hosting firm in Canada.

"Overall, in the coming months the back office will be under PCI-DSS which will allow us to ensure that the incident related to a specific hack on specific individuals will have no impact on our databases," the company said.

"In short, we were not paranoid enough so now we're switching to a higher level of paranoia. The aim is to guarantee and protect your data in the case of industrial espionage that would target people working at OVH."

European customers' surname, first name, nic, address, city, country, telephone, fax, and encrypted password are all open to the attackers, and customers of the firm's Canadian hosting company have ben advised to change SSH keys to ensure a secure connection.

The company is staying mum about what exact data has been scraped, but has filed a complaint about the issue to local judicial authorities.

This isn't the first time OVH has suffered an attack. Back in May the company warned that its backoffice functions had been breached by hackers unknown and passwords were stolen.

Sursa TheRegister.co.uk

Posted

Am primit mail ieri de la ei:

Bonjour,

Récemment, nous avons relevé un incident de securité sur notre réseau interne

au siège social d'Ovh.

Nous avons immédiatement sécurisé et enquêté sur l'incident. Nous avons

relevé que la base de données des clients Europe aurait pu être illégalement

copiée. Cette base comporte les données suivantes :

le nom, le prénom, le nic, l'adresse, la ville, le pays, le téléphone, le

fax et le mot de passe chiffré. Les informations sur les cartes bancaires ne

sont pas concernées puisqu'elles ne sont pas stockées par OVH.

Même si le chiffrement du mot de passe de votre identifiant est très fort,

nous vous conseillons de changer le mot de passe dans les plus brefs délais.

Le-a "rupt" unu` baza de date :))

Posted
true , au schimbat toate parolele la toate servarele

La mine nu au schimbat la nici unul si am cateva in rbx. Singura problema e ca nu ajung emailurile cu detalii pentru serverele noi, trebuie sa le resetezi in rescue mode.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...