Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. i set up a new vps at some weird provider and they sent me an e-mail with my vps credentials

i set up a new vps at some weird provider and they sent me an e-mail with my vps credentials

Scheduled Pinned Locked Moved Uncategorized
16 Posts 15 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

    i set up a new vps at some weird provider and they sent me an e-mail with my vps credentials

    the root password said N/A, so you'd think that there's no root password by default. BUT NO! THE ROOT PASSWORD IS LITERALLY "N/A"!! AND SSHD IS EXPOSED ON PUBLIC IPV4?? THE FUCK ??

    Link Preview Image
    9 This user is from outside of this forum
    9 This user is from outside of this forum
    9pfs@tilde.zone
    wrote last edited by
    #2

    @rebane2001 that's concerning, wonder what their compromised host rates look like

    1 Reply Last reply
    0
    • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

      i set up a new vps at some weird provider and they sent me an e-mail with my vps credentials

      the root password said N/A, so you'd think that there's no root password by default. BUT NO! THE ROOT PASSWORD IS LITERALLY "N/A"!! AND SSHD IS EXPOSED ON PUBLIC IPV4?? THE FUCK ??

      Link Preview Image
      wolkensteine@mastodon.wolkenheim.euW This user is from outside of this forum
      wolkensteine@mastodon.wolkenheim.euW This user is from outside of this forum
      wolkensteine@mastodon.wolkenheim.eu
      wrote last edited by
      #3

      @rebane2001
      Sketchy - very sketch

      1 Reply Last reply
      0
      • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

        i set up a new vps at some weird provider and they sent me an e-mail with my vps credentials

        the root password said N/A, so you'd think that there's no root password by default. BUT NO! THE ROOT PASSWORD IS LITERALLY "N/A"!! AND SSHD IS EXPOSED ON PUBLIC IPV4?? THE FUCK ??

        Link Preview Image
        harrysintonen@infosec.exchangeH This user is from outside of this forum
        harrysintonen@infosec.exchangeH This user is from outside of this forum
        harrysintonen@infosec.exchange
        wrote last edited by
        #4

        @rebane2001 This reminds me of a certain provider who used to have a pre-created user on the default Linux image with a password the same as the username. The user was in sudoers. This user account wasn't documented anywhere.

        So even if you changed the root password, all systems set up with that image remained trivially exploitable over ssh.

        1 Reply Last reply
        0
        • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

          i set up a new vps at some weird provider and they sent me an e-mail with my vps credentials

          the root password said N/A, so you'd think that there's no root password by default. BUT NO! THE ROOT PASSWORD IS LITERALLY "N/A"!! AND SSHD IS EXPOSED ON PUBLIC IPV4?? THE FUCK ??

          Link Preview Image
          nyanbinary@infosec.exchangeN This user is from outside of this forum
          nyanbinary@infosec.exchangeN This user is from outside of this forum
          nyanbinary@infosec.exchange
          wrote last edited by
          #5

          @rebane2001 which provider? Asking for a ... friend

          1 Reply Last reply
          0
          • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

            i set up a new vps at some weird provider and they sent me an e-mail with my vps credentials

            the root password said N/A, so you'd think that there's no root password by default. BUT NO! THE ROOT PASSWORD IS LITERALLY "N/A"!! AND SSHD IS EXPOSED ON PUBLIC IPV4?? THE FUCK ??

            Link Preview Image
            varx@defcon.socialV This user is from outside of this forum
            varx@defcon.socialV This user is from outside of this forum
            varx@defcon.social
            wrote last edited by
            #6

            @rebane2001 Oh that's a new one to add to my list of hilarious misconfiguration defaults like "null", " undefined" and "none".

            1 Reply Last reply
            0
            • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

              i set up a new vps at some weird provider and they sent me an e-mail with my vps credentials

              the root password said N/A, so you'd think that there's no root password by default. BUT NO! THE ROOT PASSWORD IS LITERALLY "N/A"!! AND SSHD IS EXPOSED ON PUBLIC IPV4?? THE FUCK ??

              Link Preview Image
              can@haz.pinkC This user is from outside of this forum
              can@haz.pinkC This user is from outside of this forum
              can@haz.pink
              wrote last edited by
              #7

              @rebane2001 I bet there was a provisioning error and the password was generated wrongly to be “N/A” and the script just went with it

              1 Reply Last reply
              0
              • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                i set up a new vps at some weird provider and they sent me an e-mail with my vps credentials

                the root password said N/A, so you'd think that there's no root password by default. BUT NO! THE ROOT PASSWORD IS LITERALLY "N/A"!! AND SSHD IS EXPOSED ON PUBLIC IPV4?? THE FUCK ??

                Link Preview Image
                voxel@infosec.spaceV This user is from outside of this forum
                voxel@infosec.spaceV This user is from outside of this forum
                voxel@infosec.space
                wrote last edited by
                #8

                @rebane2001 I would switch the provider and request data deletion under article 17 GDPR 🫡

                1 Reply Last reply
                0
                • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                  i set up a new vps at some weird provider and they sent me an e-mail with my vps credentials

                  the root password said N/A, so you'd think that there's no root password by default. BUT NO! THE ROOT PASSWORD IS LITERALLY "N/A"!! AND SSHD IS EXPOSED ON PUBLIC IPV4?? THE FUCK ??

                  Link Preview Image
                  benjaminnelan@mastodon.socialB This user is from outside of this forum
                  benjaminnelan@mastodon.socialB This user is from outside of this forum
                  benjaminnelan@mastodon.social
                  wrote last edited by
                  #9

                  @rebane2001 thanks for contributing a server to the botnet, friend

                  1 Reply Last reply
                  0
                  • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                    i set up a new vps at some weird provider and they sent me an e-mail with my vps credentials

                    the root password said N/A, so you'd think that there's no root password by default. BUT NO! THE ROOT PASSWORD IS LITERALLY "N/A"!! AND SSHD IS EXPOSED ON PUBLIC IPV4?? THE FUCK ??

                    Link Preview Image
                    fritzadalis@infosec.exchangeF This user is from outside of this forum
                    fritzadalis@infosec.exchangeF This user is from outside of this forum
                    fritzadalis@infosec.exchange
                    wrote last edited by
                    #10

                    @rebane2001
                    I wonder if N/A is in any of the common password lists.

                    draeath@infosec.exchangeD 1 Reply Last reply
                    0
                    • fritzadalis@infosec.exchangeF fritzadalis@infosec.exchange

                      @rebane2001
                      I wonder if N/A is in any of the common password lists.

                      draeath@infosec.exchangeD This user is from outside of this forum
                      draeath@infosec.exchangeD This user is from outside of this forum
                      draeath@infosec.exchange
                      wrote last edited by
                      #11

                      @FritzAdalis @rebane2001 it's in several of Openwall's: https://www.openwall.com/wordlists/

                      • English/3-large/acronym.lst
                      • English/4-extra/acronym.lst
                      • mangled.lst
                      • all.lst
                      1 Reply Last reply
                      0
                      • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                        i set up a new vps at some weird provider and they sent me an e-mail with my vps credentials

                        the root password said N/A, so you'd think that there's no root password by default. BUT NO! THE ROOT PASSWORD IS LITERALLY "N/A"!! AND SSHD IS EXPOSED ON PUBLIC IPV4?? THE FUCK ??

                        Link Preview Image
                        ham_sando@mastodon.socialH This user is from outside of this forum
                        ham_sando@mastodon.socialH This user is from outside of this forum
                        ham_sando@mastodon.social
                        wrote last edited by
                        #12

                        @rebane2001 bruh

                        1 Reply Last reply
                        0
                        • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                          i set up a new vps at some weird provider and they sent me an e-mail with my vps credentials

                          the root password said N/A, so you'd think that there's no root password by default. BUT NO! THE ROOT PASSWORD IS LITERALLY "N/A"!! AND SSHD IS EXPOSED ON PUBLIC IPV4?? THE FUCK ??

                          Link Preview Image
                          grumpydad@infosec.exchangeG This user is from outside of this forum
                          grumpydad@infosec.exchangeG This user is from outside of this forum
                          grumpydad@infosec.exchange
                          wrote last edited by
                          #13

                          @rebane2001 Weird provider seems to be an understatement

                          1 Reply Last reply
                          0
                          • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                            i set up a new vps at some weird provider and they sent me an e-mail with my vps credentials

                            the root password said N/A, so you'd think that there's no root password by default. BUT NO! THE ROOT PASSWORD IS LITERALLY "N/A"!! AND SSHD IS EXPOSED ON PUBLIC IPV4?? THE FUCK ??

                            Link Preview Image
                            kiuhbit@hachyderm.ioK This user is from outside of this forum
                            kiuhbit@hachyderm.ioK This user is from outside of this forum
                            kiuhbit@hachyderm.io
                            wrote last edited by
                            #14

                            @rebane2001 *maybe* it's a randomly generated 3 character password and you got (un)lucky? ...probably not

                            1 Reply Last reply
                            0
                            • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                              i set up a new vps at some weird provider and they sent me an e-mail with my vps credentials

                              the root password said N/A, so you'd think that there's no root password by default. BUT NO! THE ROOT PASSWORD IS LITERALLY "N/A"!! AND SSHD IS EXPOSED ON PUBLIC IPV4?? THE FUCK ??

                              Link Preview Image
                              martenkoetsier@mastodon.socialM This user is from outside of this forum
                              martenkoetsier@mastodon.socialM This user is from outside of this forum
                              martenkoetsier@mastodon.social
                              wrote last edited by
                              #15

                              @rebane2001 my password is secret!

                              1 Reply Last reply
                              0
                              • rebane2001@infosec.exchangeR This user is from outside of this forum
                                rebane2001@infosec.exchangeR This user is from outside of this forum
                                rebane2001@infosec.exchange
                                wrote last edited by
                                #16

                                @stuartl yes

                                1 Reply Last reply
                                1
                                0
                                Reply
                                • Reply as topic
                                Log in to reply
                                • Oldest to Newest
                                • Newest to Oldest
                                • Most Votes


                                • Login

                                • Login or register to search.
                                • First post
                                  Last post
                                0
                                • Categories
                                • Recent
                                • Tags
                                • Popular
                                • World
                                • Users
                                • Groups