Fasthosts Security Breach
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Plusnet Community
- :
- Forum
- :
- Help with my Plusnet services
- :
- Everything else
- :
- Fasthosts Security Breach
Fasthosts Security Breach
18-10-2007 7:51 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
I've just had an e-mail from Fasthosts telling me that one of its servers has been successfully hacked into.
I can't find any reference to this on the Fasthosts website, but the e-mail looks genuine.
Re: Fasthosts Security Breach
18-10-2007 8:00 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Link
Re: Fasthosts Security Breach
18-10-2007 8:07 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
My company has a reseller account with them and we have a lot of passwords to change AAAARRRRGGGG!!!!!!
Re: Fasthosts Security Breach
18-10-2007 8:08 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Re: Fasthosts Security Breach
18-10-2007 8:13 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Dear <name>
We are writing to inform you that we have recently discovered evidence of a network intrusion involving a Fasthosts server. We have reason to believe that the intruder has gained access to our internal systems, and that this may have in turn given them access to your username and some service passwords.
We have since closed the vulnerability through which access was gained, and have taken steps to ensure that this cannot happen again.
We therefore recommend, as a precaution, that you now change the following passwords on your account, both for your personal use, and for your customers:
- Your main account control panel login password
- All email (Standard, Advanced and Exchange mailbox) passwords for you and your customers' mailboxes
- All FTP passwords
- All MySQL and MS SQL database passwords
These can all be changed within your control panel. Further details on how to change your passwords can also be found in the support section of our website.
We strongly recommend that you choose secure passwords so that they cannot easily be guessed. These passwords should include the following:
- It should be a minimum of 8 characters long
- It should contain an upper case and a lower case letter
- It should also contain at least one number (numeric)
We recognise that this may cause some inconvenience and concern, and for that we sincerely apologise. Please be assured that your account security is extremely important to us, and we have taken every step possible to secure your information against any future intrusion attempts.
If you have any questions relating to this, please contact our Customer Support team on 0870 888 3600 or customersupport@fasthosts.co.uk who will be happy to help you.
Yours sincerely,
The Fasthosts Internet team
Re: Fasthosts Security Breach
18-10-2007 8:34 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Re: Fasthosts Security Breach
18-10-2007 8:56 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Re: Fasthosts Security Breach
18-10-2007 9:06 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Re: Fasthosts Security Breach
18-10-2007 9:19 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Re: Fasthosts Security Breach
19-10-2007 1:31 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
"In The Beginning Was The Word, And The Word Was Aardvark."
Re: Fasthosts Security Breach
19-10-2007 9:01 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Phil
Superusers are not staff, but they do have a direct line of communication into the business in order to raise issues, concerns and feedback from the community.
Re: Fasthosts Security Breach
19-10-2007 9:07 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Quote from: axisofevil Does PlusNet store any unencrypted passwords?
My guess would be no, however I would guess they're stored in a reversible encryption scheme.
I would assume that Plusnet have a central RADIUS server that stores all the authentication information. When each service that requires authentication makes a request for the password, it should be encrypted on-the-wire in whatever format the service requires.
When dealing with large-scale deployments of distributed authentication it is actually fairly common practice to store the passwords in this manner. When you're dealing with authentication requirements that span over several operating systems, through several services and even across realms (BT authentication for the ADSL connection for example) then actually storing the passwords in an irreversibly encrypted form would make inter-communication incredibly difficult.
Lets take the Portal as an example - when you log into the portal, my guess would be that the portal servers request the credentials in one particular encryption format. The RADIUS server would then provide the password to the portal servers in that format for comparison. Anyone sniffing the traffic would only be able to see the encrypted hash of the password. Perhaps the CCGI servers (running a different OS than the portal servers) don't support that particular encryption type, so they would make a request under their own encryption type, et al.
Storing the passwords in a reversible way means that the RADIUS server has the option of decrypting and re-encoding them in whatever encryption mechanism the end-service requires.
I'm sure the RADIUS boxes are physically secure, and I would assume that they are hidden deep within Plusnet's internal network. No doubt there will be a flurry of auditing to double check their electronic security following this story though

B.
Re: Fasthosts Security Breach
22-10-2007 11:49 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator

Re: Fasthosts Security Breach
22-10-2007 9:02 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Hasn't UKReg always been owned by Fasthosts? It has been for the last 3 years, at least.
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Plusnet Community
- :
- Forum
- :
- Help with my Plusnet services
- :
- Everything else
- :
- Fasthosts Security Breach