News: 1637613436

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

SSL keys, sFTP passwords and more exposed after someone broke into GoDaddy Managed WordPress using 'compromised password'

(2021/11/22)


GoDaddy has admitted to America's financial watchdog that one or more miscreants broke into its systems and potentially accessed a huge amount of customer data, from email addresses to SSL private keys.

In [1]a filing on Monday to the SEC, the internet giant said that on November 17 it discovered an "unauthorized third-party" had been roaming around part of its Managed WordPress service, which essentially stores and hosts people's websites.

GoDaddy’s chief information security officer Demetrius Comes said his company "immediately began an investigation with the help of an IT forensics firm and contacted law enforcement."

[2]

Those infosec sleuths, we're told, found evidence that an intruder had been inside part of GoDaddy's website provisioning system, described by Comes as a "legacy code base," since September 6, gaining access using a "compromised password."

[3]

[4]

The miscreant was able to view up to 1.2 million customer email addresses and customer ID numbers, and the administrative passwords generated for WordPress instances when they were provisioned. Any such passwords unchanged since the break-in have been reset.

According to GoDaddy, the sFTP and database usernames and passwords of active user accounts were accessible, too, and these have been reset as well.

[5]

"For a subset of active customers, the SSL private key was exposed," Comes added. "We are in the process of issuing and installing new certificates for those customers." GoDaddy has not responded to a request for further details and exact numbers of users affected.

"We will learn from this incident and are already taking steps to strengthen our provisioning system with additional layers of protection," the exec added.

[6]GoDaddy hack: Miscreant goes AWOL with 28,000 users' SSH login creds after vandalizing server-side file

[7]Web biz DomainFactory confirms: We were hacked in January 2018

[8]Anonymous: We've leaked disk images stolen from far-right-friendly web host Epik

[9]tsoHost pleads for 'patience and understanding' as sites borked, support sinkholed

GoDaddy's not exactly earning A+ grades so far. Last year [10]it admitted to losing the SSH usernames and passwords for around 28,000 users.

Comes didn't say if any data had actually been exfiltrated from GoDaddy's servers, though did warn that the pairing of "email addresses and customer numbers" puts customers at risk of phishing. Now would be a good time for GoDaddy users to be on alert for suspicious emails asking them to log in to, say, confirm their details: if in doubt, go straight to the GoDaddy website. ®

Get our [11]Tech Resources



[1] https://www.sec.gov/Archives/edgar/data/1609711/000160971121000122/gddyblogpostnov222021.htm

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YZwhKGYmlrLbWIUhvf1-WgAAAIc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YZwhKGYmlrLbWIUhvf1-WgAAAIc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YZwhKGYmlrLbWIUhvf1-WgAAAIc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YZwhKGYmlrLbWIUhvf1-WgAAAIc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2020/05/05/godaddy_ssh_login_details_compromised/

[7] https://www.theregister.com/2018/07/09/domainfactory_in_germany_confirms_brdata_breach/

[8] https://www.theregister.com/2021/09/30/anonymous_second_epik_dump/

[9] https://www.theregister.com/2021/07/14/tsohost_outage/

[10] https://www.theregister.com/2020/05/05/godaddy_ssh_login_details_compromised/

[11] https://whitepapers.theregister.com/



Why are they even holding "passwords"?

heyrick

In this day and age, shouldn't these things go though a gibberishificator, so your password is known to you and only you, and the server sees a long complicated looking number instead?

For miscreants to potentially see passwords implies passwords in clear text, what the fuck?

Re: Why are they even holding "passwords"?

Skiron

...and what the hell are they all doing being stored in wordpress?

Re: Why are they even holding "passwords"?

Androgynous Cupboard

It’s the SSL private keys I’m wondering about.

J. Cook

Glad I dumped Godaddy long ago for hosting my own web site. between the unexplained outages (ie, the site was down, but by the time I got a ticket opened it was back up, with no explanation for the outage) and the funky home-brewed backend for managing it (or putting files up and down on it), I finally said 'screw it' and moved to Dreamhost and have been more or less happy since.

at least for web hosting. Email, that's another kettle of fish.

And we heard him exclaim
As he started to roam:
"I'm a hologram, kids,
please don't try this at home!'"
-- Bob Violence