Vesta Control Panel - Forum

Community Forum

Skip to content

Advanced search
  • Quick links
    • Main site
    • Github repo
    • Google Search
  • FAQ
  • Login
  • Register
  • Board index Main Section General Discussion
  • Search

Two servers are hacked today via Vestacp

General questions about VestaCP
Locked
  • Print view
Advanced search
22 posts
  • 1
  • 2
  • 3
  • Next
sandy
Posts: 90
Joined: Sat Apr 07, 2018 7:06 pm
Contact:
Contact sandy
Website

Os: CentOS 6x
Web: nginx + php-fpm
Two servers are hacked today via Vestacp

Post by sandy » Sat Apr 07, 2018 8:00 pm

Today afternoon just finished my launch and got email from server provider that your server is sending outbound ddos attack.
upon investigation I found some suspicious processes are running in the server and network usage is full (checked via glances).

Upon more investigation I finally found this suspicious processes are running :

Code: Select all

374491     nginx            nginx: worker process
374492     nginx            nginx: worker process
374493     nginx            nginx: worker process[size=200][/size]
374494     nginx            nginx: worker process
374495     nginx            nginx: cache manager process
411496     named            /usr/sbin/named -u named -c /etc/named.conf
489055     httpd            /usr/sbin/httpd -DFOREGROUND
504853     httpd            /usr/sbin/httpd -DFOREGROUND
1009543    config           dovecot/config
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
1019355    update           cat resolv.conf
1033960    qlzdmvoutu       cat resolv.conf
1033961    qlzdmvoutu       uptime
1033968    qlzdmvoutu       top
1033970    qlzdmvoutu       gnome-terminal
1033973    qlzdmvoutu       pwd
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
I've 7 servers and two of them was running vestacp (centos 7- openvz)
and those two are hacked today others are working just as new.

Seems vestacp is hit by exploit, check your Vesta CP server running on centos 7 immediately.
Top

lukapaunovic
Posts: 73
Joined: Sun Dec 03, 2017 6:30 pm

Re: Two servers are hacked today via Vestacp

Post by lukapaunovic » Sat Apr 07, 2018 8:04 pm

viewtopic.php?f=10&t=16556
Top

sandy
Posts: 90
Joined: Sat Apr 07, 2018 7:06 pm
Contact:
Contact sandy
Website

Os: CentOS 6x
Web: nginx + php-fpm
Re: Two servers are hacked today via Vestacp

Post by sandy » Sat Apr 07, 2018 8:15 pm

who are not hacked for now stop vesta service :

Code: Select all

service vesta stop
Top

vesta-user
Posts: 2
Joined: Sun Apr 08, 2018 8:17 am

Os: CentOS 6x
Web: nginx + php-fpm
Re: Two servers are hacked today via Vestacp

Post by vesta-user » Sun Apr 08, 2018 8:20 am

I think stopping vesta is too much over-reaction!
Just harden the firewall rules (iptables/security group/router/other), netflix and chill.

Image
Top

sandy
Posts: 90
Joined: Sat Apr 07, 2018 7:06 pm
Contact:
Contact sandy
Website

Os: CentOS 6x
Web: nginx + php-fpm
Re: Two servers are hacked today via Vestacp

Post by sandy » Sun Apr 08, 2018 10:06 am

not everyone will have this sophisticated firewall like yours
Top

Prime
Posts: 20
Joined: Sat Apr 07, 2018 8:15 pm

Os: CentOS 6x
Web: apache + nginx
Re: Two servers are hacked today via Vestacp

Post by Prime » Sun Apr 08, 2018 10:43 am

sandy wrote: ↑
Sun Apr 08, 2018 10:06 am
not everyone will have this sophisticated firewall like yours
Wrong, even IPTables can do this if you look into it.
Top

sandy
Posts: 90
Joined: Sat Apr 07, 2018 7:06 pm
Contact:
Contact sandy
Website

Os: CentOS 6x
Web: nginx + php-fpm
Re: Two servers are hacked today via Vestacp

Post by sandy » Sun Apr 08, 2018 3:20 pm

Prime wrote: ↑
Sun Apr 08, 2018 10:43 am
sandy wrote: ↑
Sun Apr 08, 2018 10:06 am
not everyone will have this sophisticated firewall like yours
Wrong, even IPTables can do this if you look into it.
server already suspended
Top

really
Posts: 21
Joined: Mon Mar 05, 2018 3:44 am

Os: CentOS 6x
Web: apache + nginx
Re: Two servers are hacked today via Vestacp

Post by really » Mon Apr 09, 2018 4:39 am

This happened on Debian 8.1 as well, so I doubt it's OS dependent.

I had to put iptables in DROP mode and only allow traffic to my specific IP. I also dropped conntrack's max connections to avoid getting suspended and backed up my shit.

In the meantime I was trying to reinstall the server so I can get on with my life but it seems vesta's developer removed vesta packages from repo because the installer doesn't work anymore. Probably a smart move, since all Vesta server are vulnerable right now.
Top

baoang
Posts: 40
Joined: Fri Feb 23, 2018 7:31 am

Os: CentOS 5x
Web: nginx + php-fpm
Re: Two servers are hacked today via Vestacp

Post by baoang » Mon Apr 09, 2018 4:46 am

really wrote: ↑
Mon Apr 09, 2018 4:39 am
This happened on Debian 8.1 as well, so I doubt it's OS dependent.

I had to put iptables in DROP mode and only allow traffic to my specific IP. I also dropped conntrack's max connections to avoid getting suspended and backed up my shit.

In the meantime I was trying to reinstall the server so I can get on with my life but it seems vesta's developer removed vesta packages from repo because the installer doesn't work anymore. Probably a smart move, since all Vesta server are vulnerable right now.
See the top alert? The team has released a security fix, build 20.
Top

sandy
Posts: 90
Joined: Sat Apr 07, 2018 7:06 pm
Contact:
Contact sandy
Website

Os: CentOS 6x
Web: nginx + php-fpm
Re: Two servers are hacked today via Vestacp

Post by sandy » Mon Apr 09, 2018 4:55 am

really wrote: ↑
Mon Apr 09, 2018 4:39 am
This happened on Debian 8.1 as well, so I doubt it's OS dependent.

I had to put iptables in DROP mode and only allow traffic to my specific IP. I also dropped conntrack's max connections to avoid getting suspended and backed up my shit.

In the meantime I was trying to reinstall the server so I can get on with my life but it seems vesta's developer removed vesta packages from repo because the installer doesn't work anymore. Probably a smart move, since all Vesta server are vulnerable right now.
after installation stop vesta service or change the port to else
Top


Locked
  • Print view

22 posts
  • 1
  • 2
  • 3
  • Next

Return to “General Discussion”



  • Board index
  • All times are UTC
  • Delete all board cookies
  • The team
Powered by phpBB® Forum Software © phpBB Limited
*Original Author: Brad Veryard
*Updated to 3.2 by MannixMD
 

 

Login  •  Register

I forgot my password