Vesta 2.0 is coming soon! See our progress update: https://vestacp.com/docs/vesta-2-update
Search found 11 matches
- Mon Apr 09, 2018 12:09 am
- Forum: General Discussion
- Topic: Got 10 VestaCP servers exploited
- Replies: 548
- Views: 1105018
Re: Got 10 VestaCP servers exploited
Updated to V20 but still monitoring.
for the POST log, it seems like the hacker removed my IP from his pool. No trace of access from him since.
for the POST log, it seems like the hacker removed my IP from his pool. No trace of access from him since.
- Sun Apr 08, 2018 2:38 pm
- Forum: General Discussion
- Topic: Got 10 VestaCP servers exploited
- Replies: 548
- Views: 1105018
Re: Got 10 VestaCP servers exploited
I'm glad to hear. Can't wait to see the commit.
- Sun Apr 08, 2018 2:29 pm
- Forum: General Discussion
- Topic: Got 10 VestaCP servers exploited
- Replies: 548
- Views: 1105018
Re: Got 10 VestaCP servers exploited
@StudioMaX, could you delete the quote?
I have rebooted my VPS to rescue mode for inspection.
I have rebooted my VPS to rescue mode for inspection.
- Sun Apr 08, 2018 2:03 pm
- Forum: General Discussion
- Topic: Got 10 VestaCP servers exploited
- Replies: 548
- Views: 1105018
Re: Got 10 VestaCP servers exploited
@SS88, Thanks for you suggestion.
Guys, I think the guy from the IP in my previous post is also observing this forum. I should have been more careful posting the IP address. I think he might have already removed my IP from his exploited pool.
Is there any safer channel we can discuss?
Guys, I think the guy from the IP in my previous post is also observing this forum. I should have been more careful posting the IP address. I think he might have already removed my IP from his exploited pool.
Is there any safer channel we can discuss?
- Sun Apr 08, 2018 1:42 pm
- Forum: General Discussion
- Topic: Got 10 VestaCP servers exploited
- Replies: 548
- Views: 1105018
Re: Got 10 VestaCP servers exploited
@StudioMaX
That's what I'm looking for the how to. lol
That's what I'm looking for the how to. lol
- Sun Apr 08, 2018 1:30 pm
- Forum: General Discussion
- Topic: Got 10 VestaCP servers exploited
- Replies: 548
- Views: 1105018
Re: Got 10 VestaCP servers exploited
Just a few secs after starting Vesta, here what I got from the log:
x.x.x.x - - [08/Apr/2018:09:15:00 -0400] "GET / HTTP/1.1" 302 154 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:59.0) Gecko/20100101 Firefox/59.0"
x.x.x.x - - [08/Apr/2018:09:15:01 -0400] "GET / HTTP/1.1" 302 5 "-" "Mozilla/5.0 ...
x.x.x.x - - [08/Apr/2018:09:15:00 -0400] "GET / HTTP/1.1" 302 154 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:59.0) Gecko/20100101 Firefox/59.0"
x.x.x.x - - [08/Apr/2018:09:15:01 -0400] "GET / HTTP/1.1" 302 5 "-" "Mozilla/5.0 ...
- Sun Apr 08, 2018 1:14 pm
- Forum: General Discussion
- Topic: Got 10 VestaCP servers exploited
- Replies: 548
- Views: 1105018
Re: Got 10 VestaCP servers exploited
Up and running. Finger cross!
- Sun Apr 08, 2018 1:01 pm
- Forum: General Discussion
- Topic: Got 10 VestaCP servers exploited
- Replies: 548
- Views: 1105018
Re: Got 10 VestaCP servers exploited
Since I'm likely to be hacked again. I will investigate this scenario, the executable file is posted through Roundcube and is run with one of vulnerability in Vesta core. So I will start Vesta service again with log enabled. Hopefully, it is hacked again.
- Sun Apr 08, 2018 12:39 pm
- Forum: General Discussion
- Topic: Got 10 VestaCP servers exploited
- Replies: 548
- Views: 1105018
Re: Got 10 VestaCP servers exploited
lukapaunovic,
is your server up and running? May I access your log files?
is your server up and running? May I access your log files?
- Sun Apr 08, 2018 12:27 pm
- Forum: General Discussion
- Topic: Got 10 VestaCP servers exploited
- Replies: 548
- Views: 1105018
Re: Got 10 VestaCP servers exploited
FYI, I have stopped VestaCP service on all of my VPSes at the moment.