Vesta Control Panel - Forum

Community Forum

Skip to content

Advanced search
  • Quick links
    • Main site
    • Github repo
    • Google Search
  • FAQ
  • Login
  • Register
  • Board index Main Section General Discussion
  • Search

Got 10 VestaCP servers exploited

General questions about VestaCP
Locked
  • Print view
Advanced search
549 posts
  • Page 50 of 55
    • Jump to page:
  • Previous
  • 1
  • …
  • 48
  • 49
  • 50
  • 51
  • 52
  • …
  • 55
  • Next
wildwolf
Posts: 8
Joined: Mon Apr 09, 2018 9:38 am

Os: Ubuntu 15x
Web: nginx + php-fpm
Re: Got 10 VestaCP servers exploited

Post by wildwolf » Thu Apr 12, 2018 5:26 pm

dpeca wrote: ↑
Thu Apr 12, 2018 2:57 pm
https://roundcube.net/news/2018/04/11/s ... date-1.3.6
As far as I can tell, for that vulnerability to be exploited, you need to be logged into RoundCube.

Moreover, the traces will be visible in the web server access log, since command are injected into the query string.
Top

lukapaunovic
Posts: 73
Joined: Sun Dec 03, 2017 6:30 pm

Re: Got 10 VestaCP servers exploited

Post by lukapaunovic » Thu Apr 12, 2018 6:37 pm

If archive vulnerability has been fixed and roundcube is being updated from the repo then there's no sense in disabling it now, right?
Top

dpeca
VestaCP Team
Posts: 473
Joined: Wed Nov 25, 2015 7:30 pm

Re: Got 10 VestaCP servers exploited

Post by dpeca » Thu Apr 12, 2018 6:57 pm

lukapaunovic wrote: ↑
Thu Apr 12, 2018 6:37 pm
If archive vulnerability has been fixed and roundcube is being updated from the repo then there's no sense in disabling it now, right?
And CentOS already has Roundcube 1.3.6 in yum repo?
Top

yoko eagle
Posts: 33
Joined: Sat Jan 20, 2018 3:45 am

Os: Debian 8x
Web: apache + nginx
Re: Got 10 VestaCP servers exploited

Post by yoko eagle » Thu Apr 12, 2018 7:04 pm

dpeca wrote: ↑
Thu Apr 12, 2018 2:57 pm
https://roundcube.net/news/2018/04/11/s ... date-1.3.6
Hi,
Is this security fix for Roundcube already included in the latest vesta version?
Or do I have to install it separately?
Anyone guide me please.
Thanks!
Top

imperio
VestaCP Team
Posts: 7000
Joined: Sat Dec 01, 2012 12:37 pm
Contact:
Contact imperio
Website

Re: Got 10 VestaCP servers exploited

Post by imperio » Thu Apr 12, 2018 7:05 pm

dpeca wrote: ↑
Thu Apr 12, 2018 6:57 pm
lukapaunovic wrote: ↑
Thu Apr 12, 2018 6:37 pm
If archive vulnerability has been fixed and roundcube is being updated from the repo then there's no sense in disabling it now, right?
And CentOS already has Roundcube 1.3.6 in yum repo?
Yes
Top

kandalf
Posts: 87
Joined: Tue May 13, 2014 11:53 pm

Re: Got 10 VestaCP servers exploited

Post by kandalf » Thu Apr 12, 2018 8:14 pm

But the hack was done through Roundcube?
Did anyone already reproduced the hack?
Top

lukapaunovic
Posts: 73
Joined: Sun Dec 03, 2017 6:30 pm

Re: Got 10 VestaCP servers exploited

Post by lukapaunovic » Thu Apr 12, 2018 8:29 pm

No & no
Top

vishne0
Posts: 5
Joined: Mon Apr 09, 2018 3:47 pm

Os: CentOS 6x
Web: apache + nginx
Re: Got 10 VestaCP servers exploited

Post by vishne0 » Fri Apr 13, 2018 7:06 am

Just to update you all I am running updated vesta on different port with all the other security settings on server since last 3 days and no Infection yet.
Top

rlasmar
Posts: 7
Joined: Fri Oct 07, 2016 3:46 pm

Re: Got 10 VestaCP servers exploited

Post by rlasmar » Fri Apr 13, 2018 4:04 pm

I wasn't hacked.

I have the vestacp installed 1 year on digitalocean, and I dind't installed mail (exim,dovecot,spamassim,clamav). Maybe the reason that I am not hacked.

At the moment of attack, I was using vesta Version 0.9.8-17.
Top

homicide
Posts: 5
Joined: Fri May 16, 2014 8:50 pm

Re: Got 10 VestaCP servers exploited

Post by homicide » Fri Apr 13, 2018 5:55 pm

rlasmar wrote: ↑
Fri Apr 13, 2018 4:04 pm
I wasn't hacked.

I have the vestacp installed 1 year on digitalocean, and I dind't installed mail (exim,dovecot,spamassim,clamav). Maybe the reason that I am not hacked.

At the moment of attack, I was using vesta Version 0.9.8-17.
I only have 2 dedicated servers, they are in different data centers. The one that got hacked had exim/dovecot/spam/clam enabled (every service was enabled). The one that did not get hacked did not have any of those services enabled. Coincidence?

As for ports, both had the panel on default 8083. As for Vesta software both were on 0.9.8-19. One difference was that hacked server was running Centos 7 while the server that was not hacked had Centos 6.9.
Top


Locked
  • Print view

549 posts
  • Page 50 of 55
    • Jump to page:
  • Previous
  • 1
  • …
  • 48
  • 49
  • 50
  • 51
  • 52
  • …
  • 55
  • Next

Return to “General Discussion”



  • Board index
  • All times are UTC
  • Delete all board cookies
  • The team
Powered by phpBB® Forum Software © phpBB Limited
*Original Author: Brad Veryard
*Updated to 3.2 by MannixMD
 

 

cron

Login  •  Register

I forgot my password