Vesta 2.0 is coming soon! See our progress update: https://vestacp.com/docs/vesta-2-update
Got 10 VestaCP servers exploited
Re: Got 10 VestaCP servers exploited
I would recommend changing URL of roundcube as well. It may be the actual problem and it's better to be safe than sorry.yigits wrote: Sun Apr 08, 2018 10:43 am My two VestaCp installed server is suspended due to attack of the other networks.
I checked one of them and I found gcc.sh in /etc/cron.hourly. It is created on 4 April 2018.
Info: After installation I changed VestaCp port to another port.
Re: Got 10 VestaCP servers exploited
I'm more or less referring to that one shouldn't use software without an SLA for business critical applications as it can cause serious problems. But let's not further dwelve into this as it's unrelated to what this thread is actually about.
Re: Got 10 VestaCP servers exploited
Hi, we should be patience with Vesta team, even we got calls from our frustrated clients.sandy wrote: Sun Apr 08, 2018 10:20 am i didn't understand if vestacp team already gotten SOME BUNCH OF HACKED SERVER FOR TESTING why they are still resting ?
The affected servers are running with vesta > doesnt meant vesta had this bug. Let them to find the issue 1st.
Re: Got 10 VestaCP servers exploited
sure, im writing this words for vesta team actually if they are opensource and free they should consider security on first place. Security whole will harm them and people will stop using vesta.
And i'm a great fan of vesta from years, and got 3-4 times server suspended due to exploits and hacked servers. I've prove if you want let me know
And i'm a great fan of vesta from years, and got 3-4 times server suspended due to exploits and hacked servers. I've prove if you want let me know
Re: Got 10 VestaCP servers exploited
I agree with MAN5, please be patient and let VestaCP team to find that bug.MAN5 wrote: Sun Apr 08, 2018 10:51 amHi, we should be patience with Vesta team, even we got calls from our frustrated clients.sandy wrote: Sun Apr 08, 2018 10:20 am i didn't understand if vestacp team already gotten SOME BUNCH OF HACKED SERVER FOR TESTING why they are still resting ?
The affected servers are running with vesta > doesnt meant vesta had this bug. Let them to find the issue 1st.
Re: Got 10 VestaCP servers exploited
More likely its problem with RoundCube. 23 hours ago critical exploit for it was published. I realize that VastaCP is the awesome product as for freeware.MAN5 wrote: Sun Apr 08, 2018 10:51 amHi, we should be patience with Vesta team, even we got calls from our frustrated clients.sandy wrote: Sun Apr 08, 2018 10:20 am i didn't understand if vestacp team already gotten SOME BUNCH OF HACKED SERVER FOR TESTING why they are still resting ?
The affected servers are running with vesta > doesnt meant vesta had this bug. Let them to find the issue 1st.
@sandy
Even WordPress has more security breaches, if we compare it to Vesta.
You can find bugs and exploits in every software btw. Just bugs in Control Panels are more critical in comparison to MS Word for example.
Re: Got 10 VestaCP servers exploited
Next time i will just install Vesta into Docker container and host there only several sites.
If similar situation occurs i can just stop Docker container and decrease the loss.
If similar situation occurs i can just stop Docker container and decrease the loss.
Re: Got 10 VestaCP servers exploited
only if you use vulnerable plugins/theme under wp and vesta doesn't use plugins/module thoughAKr0nizz wrote: Sun Apr 08, 2018 10:58 amMore likely its problem with RoundCube. 23 hours ago critical exploit for it was published. I realize that VastaCP is the awesome product as for freeware.MAN5 wrote: Sun Apr 08, 2018 10:51 amHi, we should be patience with Vesta team, even we got calls from our frustrated clients.sandy wrote: Sun Apr 08, 2018 10:20 am i didn't understand if vestacp team already gotten SOME BUNCH OF HACKED SERVER FOR TESTING why they are still resting ?
The affected servers are running with vesta > doesnt meant vesta had this bug. Let them to find the issue 1st.
@sandy
Even WordPress has more security breaches, if we compare it to Vesta.
You can find bugs and exploits in every software btw. Just bugs in Control Panels are more critical in comparison to MS Word for example.
-
- Posts: 73
- Joined: Sun Dec 03, 2017 6:30 pm
Re: Got 10 VestaCP servers exploited
I convinced provider to put one of the hacked servers to rescue and I mounted disk.
Info is sent to vestacp info email
please hurry up with investigation as I must reinstall this and get ti up with different panel soon.
Info is sent to vestacp info email
please hurry up with investigation as I must reinstall this and get ti up with different panel soon.