back to article Security breach at Opscode as attackers download databases

Opscode, the commercial side of the open source Chef configuration management tool beloved by Google, Facebook, and IBM, has warned customers that a flaw in an unnamed third-party application has left its wiki and ticketing system pwned. "The attacker gained escalated privileges and downloaded the user database for the wiki …

COMMENTS

This topic is closed for new posts.
  1. Anonymous Coward
    Anonymous Coward

    Cookery?

    'Chef configuration management tool beloved by Google'

    I know, I'm being pedantic.....

  2. Anonymous Coward
    Anonymous Coward

    Breaches/attacks like this can happen to any company. Their response time and reaction to this was exemplary. You really have to give them that.

    1. Wzrd1 Silver badge

      True, but I'm also dubious on that number.

      Suddenly, masses of layers evaporated.

      *So* not happening!

      Now, real world version:

      "We noted the attack and blocked it. It ended five minutes after our efforts.

      The attack could still be continuing, it could be alive and well in the city of mention in the CDC report.

  3. silent_count

    Was the user database encrpted? And if not, why wasnt it?

  4. lamont

    If you note the announcement mentions that the user passwords in the database were cryptographically hashed (and via a strong hashing algorithm).

    The contents of the database was the public wiki and ticket system which is already indexed by google.

  5. John Smith 19 Gold badge
    Thumb Up

    Better handled than how RSA did it?

    Yes

  6. Phil Bennett
    Coat

    Missed opportunity

    "Chef doesn't use salt" surely?

This topic is closed for new posts.

Other stories you might like