Ugh. We need to remember that social engineering your ISP, hosting provider, etc. is a very real attack vector. Do not trust them.
Reminds me of the "N" twitter username story: https://medium.com/@N/how-i-lost-my-50-000-twitter-username-...
Ugh. We need to remember that social engineering your ISP, hosting provider, etc. is a very real attack vector. Do not trust them.
Reminds me of the "N" twitter username story: https://medium.com/@N/how-i-lost-my-50-000-twitter-username-...
> So NFOrce reset the server's root password for him
So a couple of things:
I do my hosting with gandi (moving away from self hosting as Comcast business is...well anyways...). I had setup TOTP with their service and my phone died and I lost my OTP key (lesson learned - always backup OTP keys - hint gitlab developers...). I had submitted a ticket and they called the number that was on the account and had me answer a few questions. I don't remember what the questions were - but they weren't certainly "can you reboot this server?".
The simple fact that the company used that as verification should be a red flag.
Here is another red flag - why does the hosting provider have the ability to reset a VM's root password? Gandi states that in their FAQ that they won't reset the root password - though they give you instructions on how to do that.
Though if he had access to KVM (through virtsh or virt-manager ?) he could have easily reset it himself (which would require a reboot). Perhaps he wanted to be discrete as possible?