Vesta Control Panel - Forum

Community Forum

Skip to content

Advanced search
  • Quick links
    • Main site
    • Github repo
    • Google Search
  • FAQ
  • Login
  • Register
  • Board index Main Section General Discussion
  • Search

All VestaCP installations being attacked Topic is solved

General questions about VestaCP
Locked
  • Print view
Advanced search
231 posts
  • Page 5 of 24
    • Jump to page:
  • Previous
  • 1
  • …
  • 3
  • 4
  • 5
  • 6
  • 7
  • …
  • 24
  • Next
digitalocean-jd
Posts: 2
Joined: Tue Sep 25, 2018 7:32 pm

Os: Ubuntu 15x
Web: apache + nginx
Re: All VestaCP installations being attacked

Post by digitalocean-jd » Tue Sep 25, 2018 8:35 pm

realjumy wrote: ↑
Tue Sep 25, 2018 8:33 pm

I'm having a lot of SSH penetration attempts since this morning, coming from everywhere.
Frankly it would surprising if you didn't before. Most of us get thousands+ per day on every computer connected to the internet.
Top

dpeca
VestaCP Team
Posts: 473
Joined: Wed Nov 25, 2015 7:30 pm

Re: All VestaCP installations being attacked

Post by dpeca » Tue Sep 25, 2018 8:39 pm

Yes, login attempts are something that is happening nonstop...
Top

realjumy
Posts: 50
Joined: Sun Jul 06, 2014 12:51 pm

Re: All VestaCP installations being attacked

Post by realjumy » Tue Sep 25, 2018 9:26 pm

I just published some random attempts. But I never had this many coming from the EU...
Top

albertus
Posts: 12
Joined: Sat Apr 07, 2018 2:45 pm

Os: CentOS 6x
Web: apache + nginx
Re: All VestaCP installations being attacked

Post by albertus » Tue Sep 25, 2018 10:34 pm

Hello,

Everyone running SSH on port 22? Did anyone here get hacked while having SSH firewalled by IP or running on a non-standard port?

Thank you
Top

dpeca
VestaCP Team
Posts: 473
Joined: Wed Nov 25, 2015 7:30 pm

Re: All VestaCP installations being attacked

Post by dpeca » Tue Sep 25, 2018 11:39 pm

He obviously entered via SSH because he deleted /var/log/secure and auth.log .
But mistery is HOW he got SSH.
Top

albertus
Posts: 12
Joined: Sat Apr 07, 2018 2:45 pm

Os: CentOS 6x
Web: apache + nginx
Re: All VestaCP installations being attacked

Post by albertus » Wed Sep 26, 2018 2:22 am

dpeca wrote: ↑
Tue Sep 25, 2018 11:39 pm
He obviously entered via SSH because he deleted /var/log/secure and auth.log .
But mistery is HOW he got SSH.
No, not that obvious to me, dpeca. There are things called "callback" that connect from the inside to the outside giving a shell. So, if people having SSH off got hacked I would look for something like that.
Top

mericson
Posts: 44
Joined: Thu Apr 06, 2017 12:37 am

Re: All VestaCP installations being attacked

Post by mericson » Wed Sep 26, 2018 5:34 am

MrCraac wrote: ↑
Tue Sep 25, 2018 2:30 pm
Hi, 21 servers hacked , all hosted by OVH. All of them with random ports.
We really need to have feedback about what was the issue and how it worked, until then , our servers are going back to plesk :(
Was there any evidence of port scanning prior to the attack targeting the VestaCP port? There must have been port scanning if the ports were truly random (each server with a different random port).
Top

lexusextreme
Posts: 3
Joined: Tue Mar 20, 2018 3:43 pm

Os: CentOS 5x
Web: apache + nginx
Re: All VestaCP installations being attacked

Post by lexusextreme » Wed Sep 26, 2018 6:11 am

My Vestacp (installed from 12/9/2018, Ubuntu 18.04) also was hacked.
I got an email from VPS provider they said my server was used for DDOS attack and Vesta CP was the cause of the issue.
Image
Top

realjumy
Posts: 50
Joined: Sun Jul 06, 2014 12:51 pm

Re: All VestaCP installations being attacked

Post by realjumy » Wed Sep 26, 2018 9:30 am

mericson wrote: ↑
Wed Sep 26, 2018 5:34 am
MrCraac wrote: ↑
Tue Sep 25, 2018 2:30 pm
Hi, 21 servers hacked , all hosted by OVH. All of them with random ports.
We really need to have feedback about what was the issue and how it worked, until then , our servers are going back to plesk :(
Was there any evidence of port scanning prior to the attack targeting the VestaCP port? There must have been port scanning if the ports were truly random (each server with a different random port).
All my servers were objective of port scanning since always. The matter is if they managed to enter that way.

Can anyone confirm that fail2ban works properly?
Top

slaapkopamy
Posts: 12
Joined: Sun Sep 03, 2017 5:43 pm
Contact:
Contact slaapkopamy
Website

Os: Debian 7x
Web: apache + nginx
Re: All VestaCP installations being attacked

Post by slaapkopamy » Wed Sep 26, 2018 9:33 am

realjumy wrote: ↑
Wed Sep 26, 2018 9:30 am
mericson wrote: ↑
Wed Sep 26, 2018 5:34 am
MrCraac wrote: ↑
Tue Sep 25, 2018 2:30 pm
Hi, 21 servers hacked , all hosted by OVH. All of them with random ports.
We really need to have feedback about what was the issue and how it worked, until then , our servers are going back to plesk :(
Was there any evidence of port scanning prior to the attack targeting the VestaCP port? There must have been port scanning if the ports were truly random (each server with a different random port).
All my servers were objective of port scanning since always. The matter is if they managed to enter that way.

Can anyone confirm that fail2ban works properly?
to bad for me.. I turned fail2ban off weeks ago because of the much ram usage... I added a second ip address and now running via a extra firewall for filtering my network traffic, its now little bit safer to use i hope
Top


Locked
  • Print view

231 posts
  • Page 5 of 24
    • Jump to page:
  • Previous
  • 1
  • …
  • 3
  • 4
  • 5
  • 6
  • 7
  • …
  • 24
  • Next

Return to “General Discussion”



  • Board index
  • All times are UTC
  • Delete all board cookies
  • The team
Powered by phpBB® Forum Software © phpBB Limited
*Original Author: Brad Veryard
*Updated to 3.2 by MannixMD
 

 

Login  •  Register

I forgot my password