Warning! The ColoCrossing database appears to have been compromised.

edited May 2025 in General

We warned ColoCrossing, but they decided to restore the email, we
came up with the choice to start leaking the database, and once we
get access to the new data from the email back - we'll send
everything out to the emails
Link to ColoCrossing database https://dropmefiles.com/REMOVED

Removed the download link and I'm not sure if I'm allowed to post it.

«1

Comments

  • edited May 2025

    Their Virtualizor got breached. ColoCrossing, HudsonValleyHost, ChicagoVPS are affected. ~11k customers data is there, all in plaintext. Passwords, email and data related to VM's. I would recommend reinstalling all your VM's with them and changing passwords. Or even better, don't use providers with Virtualizor.


    mod edit: snip

  • FritzFritz Behlnd you
  • imokimok OG Not Administrator

    And nothing will happen to them.

  • Did anyone received explanation email from cc? Laughable.

  • You mean as usual? This is not the first or last time.

    The Yeti has left the building.

  • edited May 2025

    Dear Customer,

    We’re reaching out to inform you of a recently resolved security matter involving the control panel software used to manage your ColoCloud virtual servers.

    The issue was identified on May 24th and stemmed from a vulnerability in a Single Sign-On (SSO) feature. While this did not impact the ColoCloud billing system (WHMCS) or expose any personal or payment information, the attacker was able to access limited system metadata, email addresses, and used our mail server API to send an unauthorized message to ColoCloud customers.

    All ColoCloud infrastructure is fully operational and secure. With support from the software vendor, we have taken all necessary steps to address the vulnerability and harden the environment.

    As a precaution, we recommend:

    • Rotating the root password for your virtual server container
    • If you reuse your Virtualizor password on other platforms, consider updating those as well

    These recommendations are made out of an abundance of caution. All stored container passwords remain securely encrypted. Additionally, while we have temporarily disabled access to the Virtualizor control panel, customers may still manage and interact with their virtual servers securely via WHMCS.

    We’ve responded quickly and thoroughly to ensure platform security and prevent this from recurring. If you need assistance resetting your passwords, our support team is ready to help.

    Please note: this communication applies only to the ColoCloud cloud/vps platform. It does not involve any part of the ColoCrossing dedicated server or colocation infrastructure, which operates on a separate system.

    Thank you for your continued trust.

    Sincerely,
    The ColoCloud Team

    This is the response. And they are lying about the scope.
    There is evidence of several VM's being compromised as a result of this, and the leaked data speaks for itself.

  • cybertechcybertech OGBenchmark King YABS 24/7/365

    dont know why anyone would use CC vps. far from best in price and performance.

    I bench YABS 24/7/365 unless it's a leap year.

  • NeoonNeoon OG
    edited May 2025

    Looks pretty ugly, they also posted the link on nodeseek....

  • "the attacker was able to access limited system metadata, email addresses" passwords are not limited system metadata. They are literally lying.

  • @LowEnd said:
    "the attacker was able to access limited system metadata, email addresses" passwords are not limited system metadata. They are literally lying.

    Plaintext container passwords 🫠

    I wonder why other panels only show a generated root password once…

  • @treesmokah said: I would recommend reinstalling all your VM's with them and changing passwords.

    Do people keep the password set by the panel during installation (and/or set the root password through the panel)? Is this ever a good idea?

    Or if you are using the VPS for something important - shouldn't you install the VPS from scratch anyway, so you know what's actually running on the VPS?

  • teamaccteamacc OG teamacc

    Sorry, but how does
    "leaking email addresses"
    qualify as

    ".. this did not ... expose any personal ... information"

    Hey teamacc. You're a dick. (c) Jon Biloh, 2020.

  • somiksomik OG Hostbusters

    @teamacc said:
    Sorry, but how does
    "leaking email addresses"
    qualify as

    ".. this did not ... expose any personal ... information"

    Maybe the email that got leaked was their company email address, not personal email. :lol:

    I speak fluent sarcasm and broken logic. | I would agree with you, but thæn we’d both be wrong.

  • tentortentor Provider

    @cmeerw said: Do people keep the password set by the panel during installation (and/or set the root password through the panel)? Is this ever a good idea?

    Someone apparently does, and it is definitely not a good idea. Better approach (from a providers' perspective) is to enforce password reset on first successful login. The best approaches are use of SSH public keys, or, as you've mentioned:

    @cmeerw said: Or if you are using the VPS for something important - shouldn't you install the VPS from scratch anyway, so you know what's actually running on the VPS?

    However, there is a problem with this approach - virtual machine provision will take significantly longer or more effort than installation from a provider provided template.

    Check our KVM VPS plans in 🇵🇱 Warsaw, Poland and 🇸🇪 Stockholm, Sweden

  • @skhron said:

    @cmeerw said: Or if you are using the VPS for something important - shouldn't you install the VPS from scratch anyway, so you know what's actually running on the VPS?

    However, there is a problem with this approach - virtual machine provision will take significantly longer or more effort than installation from a provider provided template.

    Right, but using the provider provided template will hit you later (most likely at the most inconvenient time): when something breaks (probably because you are upgrading to a new version) and you have to figure out why, and then you have to ask "why on earth did they make that modification in their template?"

    I have yet to see a provider provided template without any issues.

  • tentortentor Provider

    @cmeerw said:

    @skhron said:

    @cmeerw said: Or if you are using the VPS for something important - shouldn't you install the VPS from scratch anyway, so you know what's actually running on the VPS?

    However, there is a problem with this approach - virtual machine provision will take significantly longer or more effort than installation from a provider provided template.

    Right, but using the provider provided template will hit you later (most likely at the most inconvenient time): when something breaks (probably because you are upgrading to a new version) and you have to figure out why, and then you have to ask "why on earth did they make that modification in their template?"

    I have yet to see a provider provided template without any issues.

    Depends, there should be no issues with templates that are official images with cloud-init.

    Check our KVM VPS plans in 🇵🇱 Warsaw, Poland and 🇸🇪 Stockholm, Sweden

  • zgatozgato Chief Idle Officer

    @teamacc said:
    Sorry, but how does
    "leaking email addresses"
    qualify as

    ".. this did not ... expose any personal ... information"

    Full names are also exposed, since those are migrated from WHMCS when they create your Virtualizor account for management. Unless you manually changed it.

  • somiksomik OG Hostbusters
    edited May 2025

    @zgato said:
    Full names are also exposed, since those are migrated from WHMCS when they create your Virtualizor account for management. Unless you manually changed it.

    Anyone know where to download such files? Asking on behalf of some very reputable hosts looking for new customers :lol:

    EDIT: ^ The above is a sarcasm and not to be taken seriously (cant believe i have to explain it)...

    I speak fluent sarcasm and broken logic. | I would agree with you, but thæn we’d both be wrong.

  • @tulipyun said:
    Removed the download link and I'm not sure if I'm allowed to post it.

    Good move. Feel free to discuss what happened but there will be no sharing or distribution of compromised databases/customer details on this platform.

    yabs daddy

  • cybertechcybertech OGBenchmark King YABS 24/7/365

    @VirMach are you secretly enjoying this

    I bench YABS 24/7/365 unless it's a leap year.

  • imokimok OG Not Administrator

    I'm sure he can neither confirm nor deny it.

  • Well it appears they have received the ColonCleansing they needed

    The Yeti has left the building.

  • @AuroraZero said:
    Well it appears they have received the ColonCleansing they needed

    Colonoscopy was done and some artifacts discovered. Now long path to healing... Both reputational damage + damage for deleted servers.

  • @legendary said:

    @AuroraZero said:
    Well it appears they have received the ColonCleansing they needed

    Colonoscopy was done and some artifacts discovered. Now long path to healing... Both reputational damage + damage for deleted servers.

    They are like slimes man they always recover for awful reason. Like the bad guys in DBZ.

    The Yeti has left the building.

  • sh97sh97 Top MJJ

    @VirMach any any refugee offers? Just got 3 of VMs nuked.
    Reguards

  • edited May 2025

    @cmeerw said: Or if you are using the VPS for something important - shouldn't you install the VPS from scratch anyway, so you know what's actually running on the VPS?

    Looks like you won't have to reinstall it anymore, the attackers nuked all the vm's lol
    They still have access to Virtualizor, prior to that some Chinese users started getting infected with crypto miners on their VPS.

    What a disaster

  • colocrossing is also not loading anymore

  • @sh97 said:
    @VirMach any any refugee offers? Just got 3 of VMs nuked.
    Reguards

    We can probably honor whatever amount of service you had left with them and renewal at the same price, but I don't know much about the type of offers they've been posting. Let's just say it'd be to help out any LES members, as I don't want to open the floodgates to a bunch of tickets at the moment (it'll be difficult to go through all of them, verify, and manually create.)

    @cybertech said:
    @VirMach are you secretly enjoying this

    I'm waiting for the @raindog308 "ColoCrossing Teeters at the Edge" LEB post.

  • @VirMach said: I'm waiting for the @raindog308 "ColoCrossing Teeters at the Edge" LEB post.

    Yeah, he won't bite the hand that feeds him. CC ultimately feeds him contrary to other statements. I foresee an LEB post of "all is really fine, they are on top of it, you should thank CC for their effort and not worry, etc".

  • sh97sh97 Top MJJ

    @VirMach said:

    @sh97 said:
    @VirMach any any refugee offers? Just got 3 of VMs nuked.
    Reguards

    We can probably honor whatever amount of service you had left with them and renewal at the same price, but I don't know much about the type of offers they've been posting. Let's just say it'd be to help out any LES members, as I don't want to open the floodgates to a bunch of tickets at the moment (it'll be difficult to go through all of them, verify, and manually create.)

    Wow nice. Their main plan was a $10 one - 1c/1g/20gb SSD and 20tb bw. I think most people are on that.

    @cybertech said:
    @VirMach are you secretly enjoying this

    I'm waiting for the @raindog308 "ColoCrossing Teeters at the Edge" LEB post.

    Already out
    https://lowendbox.com/blog/colocloud-breach-virtualizer-bugs-lead-to-wild-lowendtalk-thread/

  • @sh97 said:

    @VirMach said:

    @sh97 said:
    @VirMach any any refugee offers? Just got 3 of VMs nuked.
    Reguards

    We can probably honor whatever amount of service you had left with them and renewal at the same price, but I don't know much about the type of offers they've been posting. Let's just say it'd be to help out any LES members, as I don't want to open the floodgates to a bunch of tickets at the moment (it'll be difficult to go through all of them, verify, and manually create.)

    Wow nice. Their main plan was a $10 one - 1c/1g/20gb SSD and 20tb bw. I think most people are on that.

    @cybertech said:
    @VirMach are you secretly enjoying this

    I'm waiting for the @raindog308 "ColoCrossing Teeters at the Edge" LEB post.

    Already out
    https://lowendbox.com/blog/colocloud-breach-virtualizer-bugs-lead-to-wild-lowendtalk-thread/

    Always someone else's fault never theirs. Take some god damned responsibility and own up to you screwed up, and then fix it like an adult.

    The Yeti has left the building.

  • MikeAMikeA ProviderOG

    Feel bad for them, despite the lies when they seemingly didn't understand what was going on fully, what a shitty and stressful situation to be in.

  • edited May 2025

    Is it me or is 'ColoCloud' being used as a scape goat to try minimizing referencing ColoCrossing and try make it look like some random Bangladeshi company is affected by this?

    cum laude bongineering

  • imokimok OG Not Administrator

    Was that post made by Colocrossing? It looks like a PR cleanup

  • _MS__MS_ OG
    edited May 2025

    @beanman109 said:

    Is it me or is 'ColoCloud' being used as a scape goat to try minimizing referencing ColoCrossing and try make it look like some random Bangladeshi company is affected by this?

    That's exactly what's happening.

    They'll also replace the real CC word in the current thread title with the new imaginary one.

    Have you tried turning it off and on again?

  • -.- What scum

    The Yeti has left the building.

  • Blame ColoCrossing for sending an email saying that only one part of "ColoCloud" infra was breached and that ColoCrossing dedis/colocation were not affected. Well, also blame LEB for ignoring all the evidence that CC is lying about breach affect, I guess, but LEB aren't the ones that invented the "ColoCloud" term here.

  • It'd be nice to know if this breach was due to leaked credentials/human error or if there is an actual Virtualizor bug like CC is claiming.

  • @Wolv said:
    It'd be nice to know if this breach was due to leaked credentials/human error or if there is an actual Virtualizor bug like CC is claiming.

    We don't know yet. Right now @raindog308 simply assumed it is a bug in Virtualizor because of ColoCrossing, but nothing was made public in this regard. Normally at this stage the bug should have been made public and patched so that something like this does not happen to other providers too. However, there is no proof of such bug.

  • So this didn't affect anything on purpledaddy, right? As far as I can recall, that's the only CC plan I still have (for anything in production, anyway), and it seems to be working fine.

  • @SocksAreComfortable said:
    So this didn't affect anything on purpledaddy, right? As far as I can recall, that's the only CC plan I still have (for anything in production, anyway), and it seems to be working fine.

    https://lowendtalk.com/discussion/comment/4430823#Comment_4430823

  • msattmsatt ProviderOG

    @sh97 said: Wow nice. Their main plan was a $10 one - 1c/1g/20gb SSD and 20tb bw. I think most people are on that.

    Don't know if @VirMach still accepts orders through https://vps.blackfriday but the deals in there are certainly comparable / better than the CC and may reduce all the ticketing !!!

    Get your FREE VPS if you develop Open Source software

  • vyasvyas OG
    edited May 2025

    @msatt said:
    Don't know if @VirMach still accepts orders through https://vps.blackfriday but the deals in there are certainly comparable / better than the CC and may reduce all the ticketing !!!

    You mean you want to buy a new VPS plan too,but are.... resisting? Give in to the temptation, give in...it's just a VPS.. till it is not.

  • cybertechcybertech OGBenchmark King YABS 24/7/365

    91% OFF*
    $9.54 PER YEAR
    1024MB DDR4 RAM
    2 vCORE
    20GB SSD (NVMe)
    BANDWIDTH 9216GB
    2 IPv4

    fastest fingers first

    I bench YABS 24/7/365 unless it's a leap year.

  • @cybertech said:

    fattest fingers first

    Fixed that for you...

  • Sharing this comment by @servarica_hani on the OGF.

    For other Providers and other sellers here

    Review all orders done since 25th
    We found out a couple of the account got accessed by same person who made orders from those users accounts

    So users started going through the leaked DB and they are trying the passwords on all known VPS hosts hoping users used the same password and they got lucky on some accounts

    Providers, FYI/FYA.

    "The imitator dooms himself to hopeless mediocrity." — Ralph Waldo Emerson

  • serverpointserverpoint Provider
    edited May 2025

    Wait... Virtualizor saves passwords in plain text??? Our software wipes out the password from our DB once it is given to the client.

    Remember HyperVM? And its creator committing suicide when all HyperVM based hosts got compromised and destroyed because of a bug in his software?

  • imokimok OG Not Administrator

    Times have changed. This stuff gets forgotten easily.

    Nothing bad will happen (to anybody that's not a customer)

  • @SocksAreComfortable said: So this didn't affect anything on purpledaddy

    P-diddy is safe. He owns dedicated servers, which does not use virtualizor.

  • zgatozgato Chief Idle Officer
    edited May 2025

    @serverpoint said:
    Wait... Virtualizor saves passwords in plain text??? Our software wipes out the password from our DB once it is given to the client.

    The passwords itself are saved salted, however, the email sent to the client with all the details (including VNC which no one changes the password for that) is not, and ColoCrossing never deleted that info from their db.

Sign In or Register to comment.