Vesta Control Panel - Forum

Community Forum

Skip to content

Advanced search
  • Quick links
    • Main site
    • Github repo
    • Google Search
  • FAQ
  • Login
  • Register
  • Board index Main Section General Discussion
  • Search

VERY IMPORTANT SERVER HACKED!!

General questions about VestaCP
Post Reply
  • Print view
Advanced search
26 posts
  • 1
  • 2
  • 3
  • Next
Sanity
Posts: 167
Joined: Tue Apr 08, 2014 9:10 am
Contact:
Contact Sanity
Website

Os: Ubuntu 15x
Web: apache + nginx
VERY IMPORTANT SERVER HACKED!!
  • Quote

Post by Sanity » Fri Jun 24, 2016 8:01 pm

vestacp panel has any bug , because someone has hacked my server. I could not enter the control panel vesta , and I had to change the password.

It must be a 0day hack

this is the log vestacp ( all this has made the person who has entered )


23 Jun 2016
09:32:25
changed password
21 Jun 2016
22:01:06
updated nameservers ns1.localhost.ltd ns2.localhost.ltd
21 Jun 2016
22:01:06
changed contact email to [email protected]
21 Jun 2016
22:01:06
changed admin shell to bash
21 Jun 2016
22:01:06
changed password
Top

stephenaxe
Posts: 3
Joined: Tue Jun 21, 2016 2:15 pm

Re: VERY IMPORTANT SERVER HACKED!!
  • Quote

Post by stephenaxe » Fri Jun 24, 2016 10:05 pm

ok thats scarey my server was also hacked on the same day!! ive only just got it back up and running again properly

They also changed my email on the admin account to [email protected]

Looks like there might be an issue on this
Top

Sanity
Posts: 167
Joined: Tue Apr 08, 2014 9:10 am
Contact:
Contact Sanity
Website

Os: Ubuntu 15x
Web: apache + nginx
Re: VERY IMPORTANT SERVER HACKED!!
  • Quote

Post by Sanity » Sat Jun 25, 2016 7:38 am

since I have hacked the server, do not complete the automated backups. creates the temporary file, but never ends.
I tried to do it manually /usr/local/vesta/bin/v-backup but not end.
Top

imperio
VestaCP Team
Posts: 7000
Joined: Sat Dec 01, 2012 12:37 pm
Contact:
Contact imperio
Website

Re: VERY IMPORTANT SERVER HACKED!!
  • Quote

Post by imperio » Sat Jun 25, 2016 4:23 pm

We know about this problem and working on it
New release with bug fixes will be on Monday
Top

Sanity
Posts: 167
Joined: Tue Apr 08, 2014 9:10 am
Contact:
Contact Sanity
Website

Os: Ubuntu 15x
Web: apache + nginx
Re: VERY IMPORTANT SERVER HACKED!!
  • Quote

Post by Sanity » Sat Jun 25, 2016 7:14 pm

the first thing I've done is change the port on the control panel. then add authentication to vesta panel, as a htaccess but ngnix.
Top

mike08
Posts: 160
Joined: Sat Jun 20, 2015 7:12 am

Os: Debian 6x
Web: apache + nginx
Re: VERY IMPORTANT SERVER HACKED!!
  • Quote

Post by mike08 » Sun Jun 26, 2016 7:29 am

Is there a vulnerability report for this issue that we can check and understand more about this issue?

So far I'm not too sure about what the exploit/bug is in this thread, could someone make it clear?
Top

mehargags
Support team
Posts: 1096
Joined: Sat Sep 06, 2014 9:58 pm
Contact:
Contact mehargags
Website Skype

Os: Debian 8x
Web: apache + nginx
Re: VERY IMPORTANT SERVER HACKED!!
  • Quote

Post by mehargags » Tue Jun 28, 2016 8:25 am

does this affect vesta CLI API or the Vesta Admin Web login.
I ask this because I ususally randomize my Vesta Login port for my servers, however I'm not sure if the CLI listener is listening to some different Default port over the web. I can block that in my firewall.

Thanks
Top

tjebbeke
Collaborator
Posts: 783
Joined: Mon May 11, 2015 8:43 am
Contact:
Contact tjebbeke
Website

Os: CentOS 6x
Web: apache + nginx
Re: VERY IMPORTANT SERVER HACKED!!
  • Quote

Post by tjebbeke » Tue Jun 28, 2016 9:00 am

@XoXiLhJ0mn I think mehargags is talking about the Vesta (CLI) API. Wich is accessible over the web. The web API is using the same Apache instance as the control panel if you change or block this port you also affect the API.

Vesta CP is rolling out an update, and I have take a quick look, and it seems that the security bug is fixed.
Top

sseleraci
Posts: 8
Joined: Thu May 26, 2016 5:38 am

Re: VERY IMPORTANT SERVER HACKED!!
  • Quote

Post by sseleraci » Tue Jun 28, 2016 9:56 am

I have exactly the same problem.


Image
Top

m4th3us
Posts: 45
Joined: Thu May 07, 2015 1:40 pm

Re: VERY IMPORTANT SERVER HACKED!!
  • Quote

Post by m4th3us » Tue Jun 28, 2016 10:44 am

Conf vesta (0.9.8-16 AORDEB:stable [amd64])
Conf vesta-nginx (0.9.8-16 AORDEB:stable [amd64])
Conf vesta-php (0.9.8-16 AORDEB:stable [amd64])
i'm running ubuntu 14.04, should i upgrade? i already changed vesta port and disable the service...
Top


Post Reply
  • Print view

26 posts
  • 1
  • 2
  • 3
  • Next

Return to “General Discussion”



  • Board index
  • All times are UTC
  • Delete all board cookies
  • The team
Powered by phpBB® Forum Software © phpBB Limited
*Original Author: Brad Veryard
*Updated to 3.2 by MannixMD
 

 

Login  •  Register

I forgot my password