Vesta Control Panel - Forum

Community Forum

Skip to content

Advanced search
  • Quick links
    • Main site
    • Github repo
    • Google Search
  • FAQ
  • Login
  • Register
  • Board index Main Section General Discussion
  • Search

All VestaCP installations being attacked Topic is solved

General questions about VestaCP
Locked
  • Print view
Advanced search
231 posts
  • Page 9 of 24
    • Jump to page:
  • Previous
  • 1
  • …
  • 7
  • 8
  • 9
  • 10
  • 11
  • …
  • 24
  • Next
luizjr
Posts: 8
Joined: Thu Dec 21, 2017 5:52 pm
Contact:
Contact luizjr
Website Facebook Skype Twitter

Os: Ubuntu 17x
Web: apache + nginx
Re: All VestaCP installations being attacked

Post by luizjr » Fri Sep 28, 2018 12:13 am

dpeca wrote: ↑
Wed Sep 26, 2018 12:33 pm
The same arguments are still here - why EU datracenters is untouched then....
If this is true as 10 of my servants left, being that they are in Montreal in Canada
Top

dpeca
VestaCP Team
Posts: 473
Joined: Wed Nov 25, 2015 7:30 pm

Re: All VestaCP installations being attacked

Post by dpeca » Fri Sep 28, 2018 1:08 am

I didn't think of OVH datacenters in EU, because it looks like attacker scans all OVH datacenters, including EU datacenters.

I rather thought of EU companies that has EU datacenters... OVH competitors...

Because he obviously knows only OVH IP rangs...
Maybe IP rangs of Digitalocean and AWS too...
Top

luizjr
Posts: 8
Joined: Thu Dec 21, 2017 5:52 pm
Contact:
Contact luizjr
Website Facebook Skype Twitter

Os: Ubuntu 17x
Web: apache + nginx
Re: All VestaCP installations being attacked

Post by luizjr » Fri Sep 28, 2018 1:16 am

dpeca wrote: ↑
Fri Sep 28, 2018 1:08 am
I didn't think of OVH datacenters in EU, because it looks like attacker scans all OVH datacenters, including EU datacenters.

I rather thought of EU companies that has EU datacenters... OVH competitors...

Because he obviously knows only OVH IP rangs...
Maybe IP rangs of Digitalocean and AWS too...
Based on all the information, do you have any idea how to solve it?
I have 2 servers that have been locked back in the air for investigation.

I can share one with you via private message.
Top

dpeca
VestaCP Team
Posts: 473
Joined: Wed Nov 25, 2015 7:30 pm

Re: All VestaCP installations being attacked

Post by dpeca » Fri Sep 28, 2018 1:45 am

luizjr wrote: ↑
Fri Sep 28, 2018 1:16 am
Based on all the information, do you have any idea how to solve it?
I have 2 servers that have been locked back in the air for investigation.

I can share one with you via private message.
Generally, Serghey and Anton do investigations, you can send SSH logins to [email protected]
My rang is 'Collaborator', I'm personally not sure if it means that I'm core developer, even I have permission to push commits directly to official github.
Serghey and Anton probably reviewed a lot machines in last few days, maybe they are busy with doing it.
Let it be your decision if you want to send me login for investigation.
You can send it to [email protected], they will forward it to me if they are busy with other investigations.
Or you can send it to me anyway, I will share with them if they want to investigate too.
You decide, since I'm only 'Collaborator', and since you will share probably sensitive data from server in that case.

Keep in mind that I can do that for 9 hours until now.
(it's 3:48 AM night at my country, it's really late... i must sleep :)
Top

compiz
Posts: 29
Joined: Sat Jul 07, 2018 1:26 pm
Contact:
Contact compiz
Website

Os: CentOS 6x
Web: nginx + php-fpm
Re: All VestaCP installations being attacked

Post by compiz » Fri Sep 28, 2018 5:28 am

May I add that also my vestacp is being attacked for a few days now, i don't have user pwd for room, just ssh and it seems it is working well for protection but i see all the time exim4 is down and I can't access e-mails nor a few domains, latest one is, I made a nextcloud site and I can't access it at all from nextcloud clients but only from web interface
Top

bountysite
Posts: 1
Joined: Fri Sep 28, 2018 12:39 pm

Os: CentOS 6x
Web: apache + nginx
Re: All VestaCP installations being attacked

Post by bountysite » Fri Sep 28, 2018 12:58 pm

hello,

Has anyone been able to detect the vulnerability?
From the updates, it seems like an exploit without login.
Top

lukapaunovic
Posts: 73
Joined: Sun Dec 03, 2017 6:30 pm

Re: All VestaCP installations being attacked

Post by lukapaunovic » Fri Sep 28, 2018 2:36 pm

We are at DEFCON 1
Top

pqpk2009
Posts: 45
Joined: Sun Mar 27, 2016 2:23 am

Re: All VestaCP installations being attacked

Post by pqpk2009 » Fri Sep 28, 2018 2:59 pm

I have more than 100 servers that are attacked by VESTA, which is a large number of SSHD attacks.

The server without VESTA is not attacked.
Top

pqpk2009
Posts: 45
Joined: Sun Mar 27, 2016 2:23 am

Re: All VestaCP installations being attacked

Post by pqpk2009 » Fri Sep 28, 2018 3:02 pm

I have more than 100 servers that are attacked by VESTA, which is a large number of SSHD attacks.

The server without VESTA is not attacked.
Top

maman
Posts: 17
Joined: Mon Aug 27, 2018 3:05 pm

Os: CentOS 4x
Web: apache
Re: All VestaCP installations being attacked

Post by maman » Fri Sep 28, 2018 4:12 pm

I have 5 servers with OVH in multiple locations. none of them affected.

What i do is I use my own VestaCP Improved installer (CentOS only)

For those of you with other OS you can read what steps I do to hardening VestaCP here:
=> https://github.com/erikdemarco/VestaCP-Improved

Lastly I never never never ever use vestacp default installation without any additional hardening steps.
Top


Locked
  • Print view

231 posts
  • Page 9 of 24
    • Jump to page:
  • Previous
  • 1
  • …
  • 7
  • 8
  • 9
  • 10
  • 11
  • …
  • 24
  • Next

Return to “General Discussion”



  • Board index
  • All times are UTC
  • Delete all board cookies
  • The team
Powered by phpBB® Forum Software © phpBB Limited
*Original Author: Brad Veryard
*Updated to 3.2 by MannixMD
 

 

Login  •  Register

I forgot my password