Vesta Control Panel - Forum

Community Forum

Skip to content

Advanced search
  • Quick links
    • Main site
    • Github repo
    • Google Search
  • FAQ
  • Login
  • Register
  • Board index Main Section General Discussion
  • Search

All VestaCP installations being attacked Topic is solved

General questions about VestaCP
Locked
  • Print view
Advanced search
231 posts
  • Page 1 of 24
    • Jump to page:
  • 1
  • 2
  • 3
  • 4
  • 5
  • …
  • 24
  • Next
realjumy
Posts: 50
Joined: Sun Jul 06, 2014 12:51 pm

All VestaCP installations being attacked

Post by realjumy » Wed Sep 19, 2018 3:40 pm

Hello everyone.

Since this morning I have noticed that all the VestaCP installations I have, and all the VestaCP installations of my friends, are being attacked. All of them had extra features such as Fail2Ban and the VestaCP panel port changed to a non-standard one.

In one case at least, the attack have been stopped by my hosting company. All the other installations simply stopped working.

I know that they have access to my ssh and that they added functions to clean the history of the ssh on log out, so I don't think this is easy to check, but please, check all of your logs, and check for hidden, strange files/folders.
Top

k26
Posts: 12
Joined: Sat Feb 10, 2018 4:56 am

Os: CentOS 6x
Web: apache + nginx
Re: All VestaCP installations being attacked

Post by k26 » Thu Sep 20, 2018 6:22 am

hello, some of my sites are down as well today, I'm not an expert yet of centos/vestacp
what can I do to stop the attack, to correct and make my site up again ?
also, how can that happen ? Is VestaCP secure enough ?
Top

realjumy
Posts: 50
Joined: Sun Jul 06, 2014 12:51 pm

Re: All VestaCP installations being attacked

Post by realjumy » Thu Sep 20, 2018 10:35 am

k26 wrote: ↑
Thu Sep 20, 2018 6:22 am
hello, some of my sites are down as well today, I'm not an expert yet of centos/vestacp
what can I do to stop the attack, to correct and make my site up again ?
also, how can that happen ? Is VestaCP secure enough ?
Usually VestaCP is fairly secure, but sometimes some vulnerabilities are exploited by undesirable people. Check all your logs constantly to be sure that all your servers are safe.
Top

bggg
Posts: 3
Joined: Sun Sep 23, 2018 2:17 pm

Os: CentOS 5x
Web: apache + nginx
Re: All VestaCP installations being attacked

Post by bggg » Sun Sep 23, 2018 2:28 pm

Thanks for this. I usually ignore system update etc.

Just to make sure the checklist for hardening the system:
viewtopic.php?t=14346
Top

realjumy
Posts: 50
Joined: Sun Jul 06, 2014 12:51 pm

Re: All VestaCP installations being attacked

Post by realjumy » Tue Sep 25, 2018 7:19 am

Thanks for the link.

Today I woke up with the same problem. My servers and my friend's servers have been compromised.

Our servers were following all those recommendations, and even so they have fallen. The only thing they had in common is having VestaCP installed. I wiped my servers the other day, and the security was strengthen.
Last edited by realjumy on Tue Sep 25, 2018 8:10 am, edited 1 time in total.
Top

realjumy
Posts: 50
Joined: Sun Jul 06, 2014 12:51 pm

Re: All VestaCP installations being attacked

Post by realjumy » Tue Sep 25, 2018 8:03 am

Actually, I just checked and a famous website where they compare different panels and servers configurations, and that I know it was using VestaCP, is also down. There might be some vulnerability somewhere in VestaCP.

If a developer wants to know more, I still have access to two of the infected servers.
Top

trom
Posts: 39
Joined: Tue Jul 14, 2015 3:16 am

Re: All VestaCP installations being attacked

Post by trom » Tue Sep 25, 2018 9:16 am

now problem is solved?
If I install new vesta on new server?
Top

realjumy
Posts: 50
Joined: Sun Jul 06, 2014 12:51 pm

Re: All VestaCP installations being attacked

Post by realjumy » Tue Sep 25, 2018 9:32 am

The problem is still the same. I will not install any instance of VestaCP until I'm 100% sure they sorted this problem. I have 4 servers myself with important data, and I'm not taking any risk.
Top

skurudo
VestaCP Team
Posts: 8099
Joined: Fri Dec 26, 2014 2:23 pm
Contact:
Contact skurudo
Website Facebook Google+ Skype
Twitter

Re: All VestaCP installations being attacked

Post by skurudo » Tue Sep 25, 2018 11:39 am

realjumy wrote: ↑
Tue Sep 25, 2018 8:03 am
If a developer wants to know more, I still have access to two of the infected servers.
Hello,
if you can provide access to those servers, please do it via [email protected]
Top

ctrlpac
Posts: 4
Joined: Tue Sep 25, 2018 12:01 pm

Os: Debian 8x
Web: apache
Re: All VestaCP installations being attacked

Post by ctrlpac » Tue Sep 25, 2018 12:04 pm

realjumy wrote: ↑
Tue Sep 25, 2018 9:32 am
The problem is still the same. I will not install any instance of VestaCP until I'm 100% sure they sorted this problem. I have 4 servers myself with important data, and I'm not taking any risk.
I've PM'ed you for that. I'm a computer forense analyst. I could help ;)
Top


Locked
  • Print view

231 posts
  • Page 1 of 24
    • Jump to page:
  • 1
  • 2
  • 3
  • 4
  • 5
  • …
  • 24
  • Next

Return to “General Discussion”



  • Board index
  • All times are UTC
  • Delete all board cookies
  • The team
Powered by phpBB® Forum Software © phpBB Limited
*Original Author: Brad Veryard
*Updated to 3.2 by MannixMD
 

 

Login  •  Register

I forgot my password