Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. i set up a new vps at some weird provider and they sent me an e-mail with my vps credentials

i set up a new vps at some weird provider and they sent me an e-mail with my vps credentials

Scheduled Pinned Locked Moved Uncategorized
16 Posts 15 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

    i set up a new vps at some weird provider and they sent me an e-mail with my vps credentials

    the root password said N/A, so you'd think that there's no root password by default. BUT NO! THE ROOT PASSWORD IS LITERALLY "N/A"!! AND SSHD IS EXPOSED ON PUBLIC IPV4?? THE FUCK ??

    harrysintonen@infosec.exchangeH This user is from outside of this forum
    harrysintonen@infosec.exchangeH This user is from outside of this forum
    harrysintonen@infosec.exchange
    wrote last edited by
    #4

    @rebane2001 This reminds me of a certain provider who used to have a pre-created user on the default Linux image with a password the same as the username. The user was in sudoers. This user account wasn't documented anywhere.

    So even if you changed the root password, all systems set up with that image remained trivially exploitable over ssh.

    1 Reply Last reply
    0
    • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

      i set up a new vps at some weird provider and they sent me an e-mail with my vps credentials

      the root password said N/A, so you'd think that there's no root password by default. BUT NO! THE ROOT PASSWORD IS LITERALLY "N/A"!! AND SSHD IS EXPOSED ON PUBLIC IPV4?? THE FUCK ??

      nyanbinary@infosec.exchangeN This user is from outside of this forum
      nyanbinary@infosec.exchangeN This user is from outside of this forum
      nyanbinary@infosec.exchange
      wrote last edited by
      #5

      @rebane2001 which provider? Asking for a ... friend

      1 Reply Last reply
      0
      • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

        i set up a new vps at some weird provider and they sent me an e-mail with my vps credentials

        the root password said N/A, so you'd think that there's no root password by default. BUT NO! THE ROOT PASSWORD IS LITERALLY "N/A"!! AND SSHD IS EXPOSED ON PUBLIC IPV4?? THE FUCK ??

        varx@defcon.socialV This user is from outside of this forum
        varx@defcon.socialV This user is from outside of this forum
        varx@defcon.social
        wrote last edited by
        #6

        @rebane2001 Oh that's a new one to add to my list of hilarious misconfiguration defaults like "null", " undefined" and "none".

        1 Reply Last reply
        0
        • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

          i set up a new vps at some weird provider and they sent me an e-mail with my vps credentials

          the root password said N/A, so you'd think that there's no root password by default. BUT NO! THE ROOT PASSWORD IS LITERALLY "N/A"!! AND SSHD IS EXPOSED ON PUBLIC IPV4?? THE FUCK ??

          can@haz.pinkC This user is from outside of this forum
          can@haz.pinkC This user is from outside of this forum
          can@haz.pink
          wrote last edited by
          #7

          @rebane2001 I bet there was a provisioning error and the password was generated wrongly to be “N/A” and the script just went with it

          1 Reply Last reply
          0
          • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

            i set up a new vps at some weird provider and they sent me an e-mail with my vps credentials

            the root password said N/A, so you'd think that there's no root password by default. BUT NO! THE ROOT PASSWORD IS LITERALLY "N/A"!! AND SSHD IS EXPOSED ON PUBLIC IPV4?? THE FUCK ??

            voxel@infosec.spaceV This user is from outside of this forum
            voxel@infosec.spaceV This user is from outside of this forum
            voxel@infosec.space
            wrote last edited by
            #8

            @rebane2001 I would switch the provider and request data deletion under article 17 GDPR 🫡

            1 Reply Last reply
            0
            • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

              i set up a new vps at some weird provider and they sent me an e-mail with my vps credentials

              the root password said N/A, so you'd think that there's no root password by default. BUT NO! THE ROOT PASSWORD IS LITERALLY "N/A"!! AND SSHD IS EXPOSED ON PUBLIC IPV4?? THE FUCK ??

              benjaminnelan@mastodon.socialB This user is from outside of this forum
              benjaminnelan@mastodon.socialB This user is from outside of this forum
              benjaminnelan@mastodon.social
              wrote last edited by
              #9

              @rebane2001 thanks for contributing a server to the botnet, friend

              1 Reply Last reply
              0
              • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                i set up a new vps at some weird provider and they sent me an e-mail with my vps credentials

                the root password said N/A, so you'd think that there's no root password by default. BUT NO! THE ROOT PASSWORD IS LITERALLY "N/A"!! AND SSHD IS EXPOSED ON PUBLIC IPV4?? THE FUCK ??

                fritzadalis@infosec.exchangeF This user is from outside of this forum
                fritzadalis@infosec.exchangeF This user is from outside of this forum
                fritzadalis@infosec.exchange
                wrote last edited by
                #10

                @rebane2001
                I wonder if N/A is in any of the common password lists.

                draeath@infosec.exchangeD 1 Reply Last reply
                0
                • fritzadalis@infosec.exchangeF fritzadalis@infosec.exchange

                  @rebane2001
                  I wonder if N/A is in any of the common password lists.

                  draeath@infosec.exchangeD This user is from outside of this forum
                  draeath@infosec.exchangeD This user is from outside of this forum
                  draeath@infosec.exchange
                  wrote last edited by
                  #11

                  @FritzAdalis @rebane2001 it's in several of Openwall's: https://www.openwall.com/wordlists/

                  • English/3-large/acronym.lst
                  • English/4-extra/acronym.lst
                  • mangled.lst
                  • all.lst
                  1 Reply Last reply
                  0
                  • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                    i set up a new vps at some weird provider and they sent me an e-mail with my vps credentials

                    the root password said N/A, so you'd think that there's no root password by default. BUT NO! THE ROOT PASSWORD IS LITERALLY "N/A"!! AND SSHD IS EXPOSED ON PUBLIC IPV4?? THE FUCK ??

                    ham_sando@mastodon.socialH This user is from outside of this forum
                    ham_sando@mastodon.socialH This user is from outside of this forum
                    ham_sando@mastodon.social
                    wrote last edited by
                    #12

                    @rebane2001 bruh

                    1 Reply Last reply
                    0
                    • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                      i set up a new vps at some weird provider and they sent me an e-mail with my vps credentials

                      the root password said N/A, so you'd think that there's no root password by default. BUT NO! THE ROOT PASSWORD IS LITERALLY "N/A"!! AND SSHD IS EXPOSED ON PUBLIC IPV4?? THE FUCK ??

                      grumpydad@infosec.exchangeG This user is from outside of this forum
                      grumpydad@infosec.exchangeG This user is from outside of this forum
                      grumpydad@infosec.exchange
                      wrote last edited by
                      #13

                      @rebane2001 Weird provider seems to be an understatement

                      1 Reply Last reply
                      0
                      • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                        i set up a new vps at some weird provider and they sent me an e-mail with my vps credentials

                        the root password said N/A, so you'd think that there's no root password by default. BUT NO! THE ROOT PASSWORD IS LITERALLY "N/A"!! AND SSHD IS EXPOSED ON PUBLIC IPV4?? THE FUCK ??

                        kiuhbit@hachyderm.ioK This user is from outside of this forum
                        kiuhbit@hachyderm.ioK This user is from outside of this forum
                        kiuhbit@hachyderm.io
                        wrote last edited by
                        #14

                        @rebane2001 *maybe* it's a randomly generated 3 character password and you got (un)lucky? ...probably not

                        1 Reply Last reply
                        0
                        • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                          i set up a new vps at some weird provider and they sent me an e-mail with my vps credentials

                          the root password said N/A, so you'd think that there's no root password by default. BUT NO! THE ROOT PASSWORD IS LITERALLY "N/A"!! AND SSHD IS EXPOSED ON PUBLIC IPV4?? THE FUCK ??

                          martenkoetsier@mastodon.socialM This user is from outside of this forum
                          martenkoetsier@mastodon.socialM This user is from outside of this forum
                          martenkoetsier@mastodon.social
                          wrote last edited by
                          #15

                          @rebane2001 my password is secret!

                          1 Reply Last reply
                          0
                          • rebane2001@infosec.exchangeR This user is from outside of this forum
                            rebane2001@infosec.exchangeR This user is from outside of this forum
                            rebane2001@infosec.exchange
                            wrote last edited by
                            #16

                            @stuartl yes

                            1 Reply Last reply
                            1
                            0
                            Reply
                            • Reply as topic
                            Log in to reply
                            • Oldest to Newest
                            • Newest to Oldest
                            • Most Votes


                            • Login

                            • Login or register to search.
                            • First post
                              Last post
                            0
                            • Categories
                            • Recent
                            • Tags
                            • Popular
                            • World
                            • Users
                            • Groups