Email us! Subscribe to Liquidmatrix!

Hackers Load Malware Onto Mercury Music Award Site

Oops. It turns out that our web hosting company has been pwned.

Hackers have been able to load malware onto the official Mercury music awards site, as well as hundreds of other sites, after breaking into the systems of US-based hosting firm DreamHost.

DreamHost blamed a security flaw in its web control panel software for an attack that allowed hackers to compromise a “very small subset” of user accounts. Affected customers have been notified by email. DreamHost said only web content - not credit card or billing information - was compromised.

In a statement published Wednesday, DreamHost said: “The security flaw allowed the attackers to log into our customer web control panel with the access privileges of another user. From our web panel they were able to access individual user password information. The attackers also attempted to gain access to our central database and billing information but were ultimately thwarted in that attempt. No credit card information or customer personal information was obtained.”

DreamHost takes care of more than 500,000 domains, according to the firm. An email sent by DreamHost to its customers on 5 June, said approximately 3,500 separate FTP accounts were compromised by the hack. DreamHost has advised its customers to change their FTP account passwords immediately. The firm has promised to update concerned punters about the steps it is taking to prevent a repetition.

After talking with Dreamhost it appears that we here at Liquidmatrix are not among the affected. That being said, we changed our passwords just the same.
:)
Oh, and here is the statement from Dreamhost.

Article Link (thx Myrcurial)

Tags: , ,

Tag It:
  • Digg
  • del.icio.us
  • Slashdot
  • Technorati
  • SphereIt
  • StumbleUpon
  • Fark
  • YahooMyWeb
  • Furl
  • Spurl
  • Ma.gnolia
  • NewsVine
Related Articles:

  • Web Hosting Break-Ins, Security Update
  • HP Mercury Quality Center Buffer Overflow
  • Hackers Debut Mac OS X Adware
  • Malware Plagues US Playstation Site
  • IM Worm Installs Rogue Browser
  • Liquidmatrix Security Digest » Web Hosting Break-Ins, Security Update said,

    June 11, 2007 @ 8:06 pm

    [...] hosting provider, Dreamhost, had a run of bad luck last week when some of their FTP accounts were compromised. Thankfully, none of them were ours. [...]

    RSS feed for comments on this post · TrackBack URI

    Leave a Comment