Showing posts with label HyperVM. Show all posts
Showing posts with label HyperVM. Show all posts

Wednesday, June 10, 2009

The story on Slashdot

The story publicated on Slashdot:
"The discovery of 24 security vulnerabilities may have contributed to the death of the chief of LxLabs. A flaw in the company's HyperVM software allowed data on 100,000 sites, all hosted by VAserv, to be destroyed. The HyperVM solution is popular with cheap web hosting services and the attacks are easy to reproduce, which could lead to further incidents."

More on Slashdot
Read more

Lxlabs/HyperVM owner, K T Ligesh hanged himself!?

A tragical news has been publicated on several news portal on the internet:
Lxlabs/HyperVM owner K T Ligesh hanged himself.
You can read the news here , here and here .
And also several forum topics has been started about his suicide on Webhostingtalk and Lxlabs forum

The HyperVM control panel is used at FSCKVPS and at the whole Vaserv empire (and at lots of other VPS providers) for managing of the virtual private servers.
And possible, the hacker(s) exploited the HperVM's security hole for this attack.

I don't know whether the news about his suicide is true or not, but how long will this hacker story continue?

Sad and tragical
Read more

Tuesday, June 9, 2009

The Attack

A large internet service provider said data for as many as 100,000 websites was destroyed by attackers who targeted a zero-day vulnerability in a widely-used virtualization application.

Technicians at UK-based Vaserv.com were still scrambling to recover data on Monday evening UK time, more than 24 hours after unknown hackers were able to gain root access to the company's system, Rus Foster, the company's director told The Register. He said the attackers were able to penetrate his servers by exploiting a critical vulnerability in HyperVM, a virtualization application made by a company called LXLabs.

"We were hit by a zero-day exploit" in version 2.0.7992 of the application, he said. "I've heard from other people they've been hit by the same thing."

Foster said he's been unable to reach anyone at LXLabs to discuss the suspected vulnerability.

More on The Register
Read more
 
404 © 2009