全球主机交流论坛

 找回密码
 注册

QQ登录

只需一步,快速开始

CeraNetworks网络延迟测速工具IP归属甄别会员请立即修改密码
查看: 1656|回复: 5

OneProvider发生用户数据泄露

[复制链接]
发表于 2019-2-23 08:20:58 | 显示全部楼层 |阅读模式
本帖最后由 刘贾宜 于 2019-2-23 08:23 编辑
View this email in your browser

Dear customer,

We have discovered on February 18th an unauthorized access to a frontend entity of our infrastructure. Following investigation, it was determined that a limited amount of customer data was briefly consulted. While the unauthorized access was rapidly contained, the affected customers were immediately informed of the details in a separate message.


On February 21th, we have found that the incident was unfortunately more important than we originally believed. It is highly likely that a deprecated database backup, dating from December 2016, was partially retrieved.


The retrieved portions of the database contained: Customer Information, including hashed login passwords (to OnePanel).


The database does not contain payment information.


Because we take this situation very seriously, we have taken every appropriate measure to further secure our infrastructure and increase our security.


While your services are unlikely to have been compromised, we would like to remind you to make a habit of always changing the root passwords of your newly delivered servers.


As an additional measure of security, we have implemented an automatic password update feature that will prompt you to update your password every 6 months. You will see this feature upon your next login. We have also reset accesses for all inactive accounts. We also remind you that you can monitor the activity of your account at any time in the 'Account' section in both the "Activity Log" menu and the "Sessions" tab in the Account page.


We deeply apologize for what we realize is a grave situation, and for any inconvenience caused. Your account managers and our support team remain available for any questions you may have, or to assist you in examining as well as securing your infrastructure. We are taking the necessary steps with the concerned authorities.


Regards,

OneProvider.com


鸡翻如下

请用你的浏览器看这封电子邮件
 
亲爱的顾客,

我们在2月18日发现未经授权访问我们基础设施的前端实体。经过调查,确定简要咨询了有限数量的客户数据。虽然未经授权的访问被迅速控制,但受影响的客户会立即通过单独的消息通知详细信息。


2月21日,我们发现事件不幸比我们原先认为的更重要。从2016年12月开始,部分检索已弃用的数据库备份很可能已被部分检索。


检索到的数据库部分包含:客户信息,包括散列登录密码(到OnePanel)。


该数据库不包含付款信息。


因为我们非常重视这种情况,所以我们采取了一切适当的措施来进一步保护我们的基础设施并提高安全性。


虽然您的服务不太可能受到损害,但我们想提醒您养成始终更改新交付服务器的root密码的习惯。


作为额外的安全措施,我们实施了自动密码更新功能,该功能将提示您每6个月更新一次密码。您将在下次登录时看到此功能。我们还重置了所有非活动帐户的访问权限。我们还提醒您,您可以随时在“帐户”部分的“活动日志”菜单和“帐户”页面的“会话”标签中监控帐户的活动。


对于我们认识到的严重情况,以及造成的任何不便,我们深表歉意。您的客户经理和我们的支持团队随时可以解答您的任何问题,或协助您检查和保护您的基础架构。我们正在与有关当局采取必要步骤。


问候,

OneProvider.com

发表于 2019-2-23 08:22:22 | 显示全部楼层
还行,挺及时发公告了
发表于 2019-2-23 09:00:39 来自手机 | 显示全部楼层
也收到邮件了
发表于 2019-2-23 09:43:12 | 显示全部楼层
有点扯,人家不要支付信息要破小鸡的登陆信息???人家要的就是支付信息好吧
发表于 2019-2-23 11:27:14 | 显示全部楼层
我一个被要求验证的号收到,主号没有收到
发表于 2019-2-23 12:11:39 | 显示全部楼层
收到了,还好我是用1p,各站独立密码
您需要登录后才可以回帖 登录 | 注册

本版积分规则

Archiver|手机版|小黑屋|全球主机交流论坛

GMT+8, 2024-4-25 21:25 , Processed in 0.066487 second(s), 8 queries , Gzip On, MemCache On.

Powered by Discuz! X3.4

© 2001-2023 Discuz! Team.

快速回复 返回顶部 返回列表