Feeds

Security breach at Opscode as attackers download databases

Attack blocked in five minutes flat

  • alert
  • submit to reddit

Choosing a cloud hosting partner with confidence

Updated Opscode, the commercial side of the open source Chef configuration management tool beloved by Google, Facebook, and IBM, has warned customers that a flaw in an unnamed third-party application has left its wiki and ticketing system pwned.

"The attacker gained escalated privileges and downloaded the user database for the wiki and ticketing system," the company said in a blog post on Thursday. "The user database that was accessed contained usernames, email addresses, full names, and hashed passwords."

"We believe these passwords are adequately secure (the software in question uses the PBKDF2 algorithm), but we will be forcing a password change on the ticketing and wiki systems. If you use this password on other systems, we suggest choosing a new password on those systems as well. We will also contact the affected users via email today."

The company was alerted to the attack by internal security monitoring, the attacker has been kicked out, and now a full investigation is underway using forensics the team has gathered. There's no word as to whether the police are involved.

Opscode says there's "currently no evidence" that hosted data has been copied or compromised, but it recommends users who use the same username and password for hosted accounts should also change passwords.

It's an embarrassing issue for a company that has become something of a cloud and datacenter darling of late, but it could happen to anyone these days and such openness is to be commended.

The company promises more details as they become available. ®

Update

Opscode has provided more details about the hacking attack, and says that all hosted Chef data is now confirmed to be secure and untouched.

"The attack happened around 1pm yesterday, and our security systems picked it up in under five minutes," Pauly Comtois, director of operations, told El Reg. "Once we were alerted that someone was running a script in the system, we pulled the plug on the box and took it offline immediately."

Overnight, two Opscode teams worked on the problem. The first set about rebuilding the wiki and ticketing system from the ground up so that normal services wouldn't be interrupted, while a second team took the original system and started gathering forensic evidence.

It appears the attacker used a vulnerability in the wiki software and ran a JavaScript program from the Uniform Resource Identifier. In the short time before being spotted, the attacker was able to download some database data, but nothing too serious.

While the attacker got some information, all passwords are secure from anything but a brute force attack requiring significant processing time, but Comtois said the company wants to let users know about the breach so that they could take precautions – just in case.

Beginner's guide to SSL certificates

More from The Register

next story
Russian hackers exploit 'Sandworm' bug 'to spy on NATO, EU PCs'
Fix imminent from Microsoft for Vista, Server 2008, other stuff
Microsoft pulls another dodgy patch
Redmond makes a hash of hashing add-on
FYI: OS X Yosemite's Spotlight tells Apple EVERYTHING you're looking for
It's on by default – didn't you read the small print?
'LulzSec leader Aush0k' found to be naughty boy not worthy of jail
15 months home detention leaves egg on feds' faces as they grab for more power
Forget passwords, let's use SELFIES, says Obama's cyber tsar
Michael Daniel wants to kill passwords dead
Kill off SSL 3.0 NOW: HTTPS savaged by vicious POODLE
Pull it out ASAP, it is SWISS CHEESE
Facebook slurps 'paste sites' for STOLEN passwords, sprinkles on hash and salt
Zuck's ad empire DOESN'T see details in plain text. Phew!
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Cloud and hybrid-cloud data protection for VMware
Learn how quick and easy it is to configure backups and perform restores for VMware environments.
Three 1TB solid state scorchers up for grabs
Big SSDs can be expensive but think big and think free because you could be the lucky winner of one of three 1TB Samsung SSD 840 EVO drives that we’re giving away worth over £300 apiece.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.