Read the latest issue of WHIR Magazine or subscribe to receive it FREE!

Web Host Hack Deletes 100k Sites

By Justin Lee, June 08, 2009

(WEB HOST INDUSTRY REVIEW) -- As many as 100,000 websites were deleted Sunday evening after hackers exploited a vulnerability found in UK web hosting provider Vaserv's (www.vaserv.com) system, according to an exclusive report by The Register.

A visit to the web host's site shows a lengthy index log of updates from the technicians as they work to recover the lost data.

On Sunday evening, unknown hackers managed to breach the web host's system by exploiting a vulnerability in a virtualization application.

The company says it was attacked by zero-day exploit in version 2.0.7992 of the LXLabs-developd HyperVM.

Vaserv director Rus Foster says he has already heard from others that they too have been hit with the same exploit.

According to The Register report, no one at the Bangalore-based LXLabs was able to be reached for comment on the exploit.

The report also points out that it is still unclear if other web hosts that are using the HyperVM application have been hit with a similar attack.

Foster says that all the information contained on about half of the company's hosted websites was instantly wiped sometime on Sunday evening following the attack.

The attackers managed to gain control of the web host's system where it was able to perform Unix commands, including "rm -rf," which prompts a recursive delete of all files.

About half of the affected customers lost all their data since they opted for Vaserv's unmanaged service, which fails to include data backup.

Foster says he is not entirely sure if the affected customers will ever be able to retrieve their lost data.

So far, not much is is known about the attackers. Foster says the perpetrators likely used a SQL injection attack to breach Vaserv's central management system, and subsequently deleted key binaries and data for about half of all the user data hosted by the web host.

  • (1) Comments

Comment anonymously or log into your WHIR account

Logging in allows enhanced commenting features (such as external linking) in news, features, blogs and more.

User:

Pass:

(reset password)

Don't have an account yet? Register now!


 

Comment by Anonymous on Tuesday, June 09, 2009

My friend's business website has been destroyed because of LXLabs crash. The lesson here is simple. Website backups are very important, we had learned a hard way. Its hard to rely on the web hosts these days months ago our web host has gone out of business. Our site along with the contents vanished of the Internet. We had to recreate the whole thing all over again and waste 5 weeks and almost 3k on rebuilding from scrach. You should always be using an automated backup software or service. We use www.websitebackup.ca for mirroring our website on weekly basis. Good luck to all the folks who lost their sites because of LXLabs . - Carson.

Read Back Issues of WHIR Magazine

October 2009 - Web Hosting's All Star Team
This has been, for us, one of the most interesting, exciting and challenging build-ups to an issue of the magazine yet, Web Hosting's All Star Team. The balloting process was our first experiment with a kind of user participation we're planning to do a lot more with in the months to come. We had thousands of ballots submitted, with hundreds of write-in suggestions and a demonstration of user engagement that has us feeling super positive about the project.
About This Issue | Read Digital Edition

July 2009 - What am I Worth?
One of the interesting luxuries of working on a project like the printed WHIR magazine is that it allows us to play with things like our point of view from one issue to the next. In recent months we've been giving added attention to the kind of practical and applicable advice aimed at smaller hosts and resellers. This issue carries on with that point of view, asking, in our cover story, "what am I worth?" It's a complicated question without a clear-cut answer.
About This Issue | Read Digital Edition

May 2009 - The Blueprint for a Small Web Host
I was a little surprised by how difficult it became to see this idea through. We set out to assemble a blueprint for a small hosting business, but butted up pretty quickly against the general impossibility of covering all the territory that was out there to be covered. The basic constraints of a printed magazine, and the less-than-infinite amount of time we had available forced us to face the fact that we could never produce an exhaustive guide to starting a hosting company.
About This Issue | Read Digital Edition

Read more WHIR Magazine back issues