Rootnode - information about Thursday accident

Discuss and help improve OpenMW's infrastructure: Website, Forums, issue tracker and everything having to do with keeping the lights on with OpenMW.
Post Reply
User avatar
lgromanowski
Site Admin
Posts: 1193
Joined: 05 Aug 2011, 22:21
Location: Wroclaw, Poland
Contact:

Rootnode - information about Thursday accident

Post by lgromanowski »

Hi,
beginning of this year (and end of previous year) was very unlucky for Rootnode - raid failure, power failure and now some hacking attacks. Unfortunately one of users probably use some 0-day exploit and gain access (from inside) to Rootnode system database where user names, address etc. information was stored, and this data leaked. Based on what leaked and how it looks like some of RN old angry/dissatisfied (I can't find proper word) users is doing the dirty on RN admins.

The investigation is in progress, RN admins (and me too) assumed worst case scenario - not only database information was leaked, but script-kiddie had also root access to system.

Since Monday (6 Feb) all shell users (including me) will be moved to separate LXC containers therefore, there could be some downtime, but I will monitor the situation and notify about it.

I was thinking about migration openmw website infrastructure to the different hosting, but I decided to stay (Since March 2009 I haven't any big problems with RN services, and It is easier for me to administrate webpage from shell and have all things in one place). But If you think we really should move from RN, then please write.
Post Reply