We just received an email from MaxCDN, informing us that they have discovered an attempted breach of their systems and warning us to change our password immediately.
See the email translated into Greek
Over the weekend, our security team discovered an attempted breach of some of our systems. We immediately took the necessary measures to thwart the attackers and mitigate any security issues.
Initial investigation showed that the attackers were likely able to gain access to NetDNA (MaxCDN's parent) user information such as:
Email address and contact details
Some client configuration information
Strikethrough passwords and API keys
This means that, to further ensure the integrity and security of your services at NetDNA, you need to:
Change your password: We have reset all passwords. Reset your password if you have recently logged in. If you have not logged in, you will see a notification from the control panel that your password has expired and you will be asked to change it.
Change API Credentials: Change the API keys in your code. https://support.netdna.com/tutorials/create-an-api-idkey-pair/
The passwords were encrypted (and salted), but we recommend that you change or reset your passwords on all services where you used the same or similar ones. We recommend that you use a unique password for each service.
What happened?
One of the third-party vendors, who should make an announcement in the coming days, had a security breach. The provider's internal infrastructure stored the IPMI module access credentials on some of our remote servers (which we use for remote access). From there, the attacker was able to obtain their original access point. As a result of this vulnerability, a server containing customer information on our network fell into the hands of hackers. We are already working around the clock on this.
What are you doing about it?
We have locked down all entry points. We will continue to be vigilant.
We change passwords across the entire system and its users using bcrypt.
We have removed the API whitelisting.
All internal passwords have been changed.
Are my account details at risk?
No, the system that stores our customers' credit cards and billing information was not affected by the malicious access.
What was the hackers' goal?
We believe that the hackers wanted to inject malicious JavaScript code into high-traffic websites by changing the hostnames
Why wouldn't you contact you directly?
Why we had to act immediately to secure our systems.
View the entire email
[quote]
Dear Customer,
Over the Memorial Day weekend the NetDNA (parent company of MaxCDN) Operations team responded to a security breach on a small number of our systems. We immediately took action to block the attackers and mitigate any further security problems.
The initial investigation has shown that the parties responsible were likely able to gain access to NetDNA user information including:
Email address and contact information
Some customer configuration information
Hashed passwords and API Keys
This means, to further assure the integrity and security of your NetDNA service, we are requiring you to:
Change your Password: We have expired all passwords. Our control panel has already reset your password if you've logged in recently. If you have not logged in, you will be prompted at the control panel that your password has expired and you will be asked to reset it.
Update API Credentials: Change the API keys in your code. https://support.netdna.com/tutorials/create-an-api-idkey-pair/
Strengthen your API Whitelist: If you are using our API, please make sure that only IPs you recognize are whitelisted, as an extra precaution:
https://support.netdna.com/tutorials/how-to-whitelist-your-server-ip-to-use-the-api/
Although passwords were encrypted (hashed and salted), we recommend that you change or reset passwords on other services where you may use similar passwords. We recommend you use a unique password on each service.
What happened?
We use a combination of our own infrastructure and managed infrastructure provided by third party vendors. One of the third party vendors, who will be making an announcement in the coming days, had a security breach. The internal infrastructure of this provider stored certain access credentials to the IPMI module on some of our remote servers (used for remote access)? this is where the intruder gained their initial point of access. As a result of this vulnerability, a web server containing customer information on our network was able to be accessed. We have been working around the clock since discovering this.
What are we doing about it?
We have currently locked down all entry points. We will continue to remain vigilant.
We are forcing system wide password changes using bcrypt.
We have removed wildcard API whitelisting.
All internal passwords have been changed.
We will launch more security features for you in the coming weeks.
Is my payment information compromised?
No, the system that stores customer credit card and billing information was NOT affected or accessed.
What were the hackers targeting?
We believe the hackers wanted to insert malicious javascript into high traffic websites by changing their origin hostnames.
Why didn't we contact you immediately?
We took immediate action to secure our systems. We wanted to understand any threats through investigation and system wide lock-down. We are now notifying you with a clearer understanding of what has happened and what this means for you.
What else do I need to do to be aware of?
If you are hosting at a managed service provider, as many of our customers do, make sure that all credentials are as locked down as possible.
I don't remember my password, how can I change it?
For this process, we've disabled the “Forgot Password” feature on our control panel login page. Please contact support to verify your account – support@netdna.com.
Will you be releasing more information?
Yes, we will release as much information as possible as soon as possible. We will be as transparent as possible. We have an ongoing investigation into the incident. We are working with the appropriate Federal authorities who are investigating the attack. We are also working closely with our vendors to share information used in jointly securing our systems.
As similar events with other large internet services have shown, this type of activity has become increasingly prevalent. We take our responsibility to protect your data with the utmost seriousness. We are working to improve our defense against such attacks by performing policy changes, security audits and lockdowns, and system upgrades.
We are very sorry for the inconvenience that we have caused you. We will post a detailed post mortem and a list of security features that we have added to prevent things like this from happening in the future on our blog. You may also contact me directly or our support team at any time.
Sincerely,
Chris Ueland
President, NetDNA
[/quote]
