Vesta Control Panel - Forum

Community Forum

Skip to content

Advanced search
  • Quick links
    • Main site
    • Github repo
    • Google Search
  • FAQ
  • Login
  • Register
  • Board index Main Section General Discussion
  • Search

Possibly infected passwd file?

General questions about VestaCP
Post Reply
  • Print view
Advanced search
4 posts • Page 1 of 1
br5dy
Posts: 11
Joined: Wed Nov 23, 2016 9:19 pm

Os: Debian 8x
Web: apache + nginx
Possibly infected passwd file?
  • Quote

Post by br5dy » Wed Apr 11, 2018 12:49 pm

Can someone please post an ORIGINAL /etc/passwd file that VestaCP installer sets up? After this recent infection, I'm seeing some new users that look suspicious. Thanks!

Here's what my file looks like. Anything look suspicious??? I've obfuscated known users.

Image
Top

yoko eagle
Posts: 33
Joined: Sat Jan 20, 2018 3:45 am

Os: Debian 8x
Web: apache + nginx
Re: Possibly infected passwd file?
  • Quote

Post by yoko eagle » Wed Apr 11, 2018 2:47 pm

br5dy wrote: ↑
Wed Apr 11, 2018 12:49 pm
Can someone please post an ORIGINAL /etc/passwd file that VestaCP installer sets up? After this recent infection, I'm seeing some new users that look suspicious. Thanks!

Here's what my file looks like. Anything look suspicious??? I've obfuscated known users.
You can do fresh install yourself and then compare the files.
I think no one will post their password file here.
Top

br5dy
Posts: 11
Joined: Wed Nov 23, 2016 9:19 pm

Os: Debian 8x
Web: apache + nginx
Re: Possibly infected passwd file?
  • Quote

Post by br5dy » Wed Apr 11, 2018 4:44 pm

Okay, FYI, anybody else noticed RSYSLOG being installed or is this part of VestaCP?

I went ahead and disabled it using these instructions. Not sure if this is a third party service that uses this or if the trojan was sending syslog data to a remote server....
Top

skamasle
Collaborator
Posts: 592
Joined: Mon Feb 29, 2016 6:36 pm

Re: Possibly infected passwd file?
  • Quote

Post by skamasle » Wed Apr 11, 2018 5:39 pm

Why you think is infected ?

If you have all in false or no-login shell no access from ssh can be made from that users
Top


Post Reply
  • Print view

4 posts • Page 1 of 1

Return to “General Discussion”



  • Board index
  • All times are UTC
  • Delete all board cookies
  • The team
Powered by phpBB® Forum Software © phpBB Limited
*Original Author: Brad Veryard
*Updated to 3.2 by MannixMD
 

 

Login  •  Register

I forgot my password