Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Below is the post I left on the thread in the link. This exact situation happened to me too. Root cause was the person who installed my OS set the root password to "g0grid". Bulletproof.

----------------------

This exact same thing happened to me! I have a crappy little single box with them and I have been reasonably happy with their service (I was originally with servepath before they got bought by GoGrid). I requested a 64-bit upgrade, which they did promptly. I was contacted by customer service to tell me the upgrade was complete and to tell me how to log in, but I had already gone to bed. The customer service rep left a VM message saying "check your customer portal account for instructions on how to log in." The next morning before I leave for work, I'm just about to log in to my fresh box when I get a call from GoGrid saying my server has been compromised, offering to let me pay for a fresh install, or I can lock it down myself immediately. I'm no security expert, but I damn well wasn't going to pay for a reinstall on a box I never logged in to. I finally managed to get them to do the reinstall for free because they had to admit the password that the customer service rep had picked after the reinstall wasn't so hot: "g0grid". Nice job, guys.



I hope they don't provision their servers with the same default root password; it would be trivial to compromise.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: