Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Discussed here: https://news.ycombinator.com/item?id=25919235

Though they would have had to also get into the admin server running (probably) WHMCS.

The sudo bug would let a hacker take over a server where the customer code ran, but not the main admin server. They would have needed some other weakness to get that. Perhaps aided by owning one of the customer servers.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: