Vesta Control Panel - Forum

Community Forum

Skip to content

Advanced search
  • Quick links
    • Main site
    • Github repo
    • Google Search
  • FAQ
  • Login
  • Register
  • Board index
  • Search

Search found 12 matches

Go to advanced search

Advanced search
Search found 12 matches
  • 1
  • 2
  • Next
by albertus
Fri Oct 19, 2018 4:48 pm
Forum: General Discussion
Topic: All VestaCP installations being attacked
Replies: 230
Views: 983812

Re: All VestaCP installations being attacked

Falzo , stop the insults. We have all said in this thread. More information you can find here https://www.welivesecurity.com/2018/10/18/new-linux-chachaddos-malware-distributed-servers-vestacp-installed/ In the next time I'll give you a warning. Excuse me, I don't think there were any insults from ...
  • Jump to post
by albertus
Wed Oct 17, 2018 7:14 pm
Forum: General Discussion
Topic: All VestaCP installations being attacked
Replies: 230
Views: 983812

Re: All VestaCP installations being attacked

The Vesta service was running and I had SSH access enabled just for the admin user. I set the password with the installation command. thanks for the info, that's interesting... I tried to investigate some more and checked some servers I installed in august and came across this entries in auth.log a...
  • Jump to post
by albertus
Mon Oct 08, 2018 7:20 pm
Forum: General Discussion
Topic: Security discussion
Replies: 26
Views: 32929

Re: Security discussion

I see we have 4 options: a) Rely on the community to find the exploited vulnerability and then fork VestaCP into something else. b) Make a fund to offer a prize for whoever finds the hole, and then fork VestaCP. c) Forget about VestaCP d) Rely on the core dev team. Meaning no ETA no info until they ...
  • Jump to post
by albertus
Wed Sep 26, 2018 2:22 am
Forum: General Discussion
Topic: All VestaCP installations being attacked
Replies: 230
Views: 983812

Re: All VestaCP installations being attacked

He obviously entered via SSH because he deleted /var/log/secure and auth.log . But mistery is HOW he got SSH. No, not that obvious to me, dpeca. There are things called "callback" that connect from the inside to the outside giving a shell. So, if people having SSH off got hacked I would look for so...
  • Jump to post
by albertus
Tue Sep 25, 2018 10:34 pm
Forum: General Discussion
Topic: All VestaCP installations being attacked
Replies: 230
Views: 983812

Re: All VestaCP installations being attacked

Hello,

Everyone running SSH on port 22? Did anyone here get hacked while having SSH firewalled by IP or running on a non-standard port?

Thank you
  • Jump to post
by albertus
Tue Sep 25, 2018 6:06 pm
Forum: General Discussion
Topic: All VestaCP installations being attacked
Replies: 230
Views: 983812

Re: All VestaCP installations being attacked

My dev server got compromise as the password for admin user got changed, lucky I had the shell for admin user set to rssh so that attempt to run the payload in /var/tmp got blocked. Heres the attempted command run via ssh from ip:45.76.146.8 command: echo "9WlgVjGkot" | sudo -S -p "" chmod 0777 /va...
  • Jump to post
by albertus
Tue Sep 25, 2018 12:46 pm
Forum: General Discussion
Topic: All VestaCP installations being attacked
Replies: 230
Views: 983812

Re: All VestaCP installations being attacked

ctrlpac wrote: ↑
Tue Sep 25, 2018 12:41 pm
albertus wrote: ↑
Tue Sep 25, 2018 12:36 pm
Don't worry pal. VestaCP developers will take care of it, give them a month.
A month? :x
How long it took them last time?
  • Jump to post
by albertus
Tue Sep 25, 2018 12:36 pm
Forum: General Discussion
Topic: All VestaCP installations being attacked
Replies: 230
Views: 983812

Re: All VestaCP installations being attacked

Don't worry pal. VestaCP developers will take care of it, give them a month.
  • Jump to post
by albertus
Tue Sep 25, 2018 12:10 pm
Forum: General Discussion
Topic: All VestaCP installations being attacked
Replies: 230
Views: 983812

Re: All VestaCP installations being attacked

Hello

Same here. I got 10 servers hacked.
All servers were attacking 144.0.2.180 (China). Last time VestaCP was hit by a zero day it was also discovered thanks to that attack. Too similar.

I'm done with VestaCP. Can't trust it anymore.

Good luck guys
  • Jump to post
by albertus
Sun Apr 08, 2018 9:55 pm
Forum: General Discussion
Topic: Got 10 VestaCP servers exploited
Replies: 548
Views: 1071649

Re: Got 10 VestaCP servers exploited

Problem to many of us is that we have dynamic IPs from our ISPs and it can make accessing the vesta difficult since one ip is changed there iptables will have to be updated via ssh. And I have clients that want to be able to access the admin panel to add new webistes Completely understandable, This...
  • Jump to post

Search found 12 matches
  • 1
  • 2
  • Next

Go to advanced search



  • Board index
  • All times are UTC
  • Delete all board cookies
  • The team
Powered by phpBB® Forum Software © phpBB Limited
*Original Author: Brad Veryard
*Updated to 3.2 by MannixMD
 

 

Login  •  Register

I forgot my password