Vesta Control Panel - Forum

Community Forum

Skip to content

Advanced search
  • Quick links
    • Main site
    • Github repo
    • Google Search
  • FAQ
  • Login
  • Register
  • Board index Main Section General Discussion
  • Search

Got 10 VestaCP servers exploited

General questions about VestaCP
Locked
  • Print view
Advanced search
549 posts
  • Page 32 of 55
    • Jump to page:
  • Previous
  • 1
  • …
  • 30
  • 31
  • 32
  • 33
  • 34
  • …
  • 55
  • Next
headlong
Posts: 10
Joined: Wed Jan 20, 2016 11:12 am

Re: Got 10 VestaCP servers exploited

Post by headlong » Mon Apr 09, 2018 12:08 pm

AnimusAstralis wrote: ↑
Mon Apr 09, 2018 11:58 am
It seems that my CP autoupdated and now I can't access web UI. All services are active. What should I do?
Same bug :( Updated to latest, all services working, except WEB UI
Top

RevengeFNF
Posts: 92
Joined: Sat Aug 02, 2014 6:50 pm

Os: CentOS 6x
Web: nginx + php-fpm
Re: Got 10 VestaCP servers exploited

Post by RevengeFNF » Mon Apr 09, 2018 12:08 pm

Never forget to block the port with a whitelist to certain ip's you use.

I have port 8083 blocked in iptables and i was not a victim of this exploit.
Top

vesta_mtl
Posts: 70
Joined: Wed Dec 21, 2016 2:08 pm

Re: Got 10 VestaCP servers exploited

Post by vesta_mtl » Mon Apr 09, 2018 12:09 pm

AnimusAstralis wrote: ↑
Mon Apr 09, 2018 11:58 am
It seems that my CP autoupdated and now I can't access web UI. All services are active. What should I do?
DigitalOcean (and perhaps Vultr and others) have recently blocked the default Vesta port (8083). Follow these steps to change the port (and optionally add IP firewall) and then see if you can access Vesta GUI at the new port: viewtopic.php?f=10&t=16556&start=280#p68935
Top

bruce7890
Posts: 6
Joined: Sun Apr 08, 2018 1:40 pm

Os: Ubuntu 15x
Web: apache + nginx
Re: Got 10 VestaCP servers exploited

Post by bruce7890 » Mon Apr 09, 2018 12:11 pm

RevengeFNF wrote: ↑
Mon Apr 09, 2018 12:08 pm
Never forget to block the port with a whitelist to certain ip's you use.
That's easier said than done if you're selling access to your server as a web host would...
Top

kobo1d
Posts: 47
Joined: Sun Nov 27, 2016 7:59 pm

Re: Got 10 VestaCP servers exploited

Post by kobo1d » Mon Apr 09, 2018 12:13 pm

or limit access to port 8083 using firewall
no thats not working. i got infected while this port was only available to my ip !!
Last edited by kobo1d on Mon Apr 09, 2018 12:19 pm, edited 2 times in total.
Top

snakom23
Posts: 11
Joined: Fri Aug 26, 2016 1:34 pm

Re: Got 10 VestaCP servers exploited

Post by snakom23 » Mon Apr 09, 2018 12:13 pm

have problem on debian 9 with update. News about?
Top

kobo1d
Posts: 47
Joined: Sun Nov 27, 2016 7:59 pm

Re: Got 10 VestaCP servers exploited

Post by kobo1d » Mon Apr 09, 2018 12:16 pm

RevengeFNF wrote: ↑
Mon Apr 09, 2018 12:08 pm
Never forget to block the port with a whitelist to certain ip's you use.

I have port 8083 blocked in iptables and i was not a victim of this exploit.
i did the same and i got hacked anyway. the port was only available to my ip !!

ACCEPT TCP/ VESTA 8083 xxx.xxx.xxx.xxx (myip)
default policy is drop
Last edited by kobo1d on Mon Apr 09, 2018 12:19 pm, edited 2 times in total.
Top

pipoy
Posts: 112
Joined: Mon Sep 11, 2017 8:02 am

Os: CentOS 6x
Web: apache
Re: Got 10 VestaCP servers exploited

Post by pipoy » Mon Apr 09, 2018 12:17 pm

vesta_mtl wrote: ↑
Mon Apr 09, 2018 12:09 pm
AnimusAstralis wrote: ↑
Mon Apr 09, 2018 11:58 am
It seems that my CP autoupdated and now I can't access web UI. All services are active. What should I do?
DigitalOcean (and perhaps Vultr and others) have recently blocked the default Vesta port (8083). Follow these steps to change the port (and optionally add IP firewall) and then see if you can access Vesta GUI at the new port: viewtopic.php?f=10&t=16556&start=280#p68935
I can confirm that vultr did not block port 8083.
Top

bruce7890
Posts: 6
Joined: Sun Apr 08, 2018 1:40 pm

Os: Ubuntu 15x
Web: apache + nginx
Re: Got 10 VestaCP servers exploited

Post by bruce7890 » Mon Apr 09, 2018 12:18 pm

kobo1d wrote: ↑
Mon Apr 09, 2018 12:13 pm
or limit access to port 8083 using firewall
no thats not working. i got infected while this port was only available to my ip !!
Are you sure? I thought this was all about 8083 being publicly available?
Top

RevengeFNF
Posts: 92
Joined: Sat Aug 02, 2014 6:50 pm

Os: CentOS 6x
Web: nginx + php-fpm
Re: Got 10 VestaCP servers exploited

Post by RevengeFNF » Mon Apr 09, 2018 12:21 pm

bruce7890 wrote: ↑
Mon Apr 09, 2018 12:11 pm
RevengeFNF wrote: ↑
Mon Apr 09, 2018 12:08 pm
Never forget to block the port with a whitelist to certain ip's you use.
That's easier said than done if you're selling access to your server as a web host would...
In those cases, password protect the access to it in nginx or apache configuration, and give the pass to your customer.


Image
Last edited by RevengeFNF on Mon Apr 09, 2018 12:23 pm, edited 1 time in total.
Top


Locked
  • Print view

549 posts
  • Page 32 of 55
    • Jump to page:
  • Previous
  • 1
  • …
  • 30
  • 31
  • 32
  • 33
  • 34
  • …
  • 55
  • Next

Return to “General Discussion”



  • Board index
  • All times are UTC
  • Delete all board cookies
  • The team
Powered by phpBB® Forum Software © phpBB Limited
*Original Author: Brad Veryard
*Updated to 3.2 by MannixMD
 

 

Login  •  Register

I forgot my password