Vesta Control Panel - Forum

Community Forum

Skip to content

Advanced search
  • Quick links
    • Main site
    • Github repo
    • Google Search
  • FAQ
  • Login
  • Register
  • Board index Main Section General Discussion
  • Search

Got 10 VestaCP servers exploited

General questions about VestaCP
Locked
  • Print view
Advanced search
549 posts
  • Page 54 of 55
    • Jump to page:
  • Previous
  • 1
  • …
  • 51
  • 52
  • 53
  • 54
  • 55
  • Next
Mark O Polo
Posts: 10
Joined: Wed Mar 29, 2017 7:15 pm

Re: Got 10 VestaCP servers exploited

Post by Mark O Polo » Tue May 08, 2018 4:15 pm

It has been about a month since the 1st post regarding the exploited servers.

At a result of the exploits, one patch was issued. We also know some of the code was reviewed by Rack911labs (Patrick) and he noticed several root compromise vulnerabilities (6).

I know that many users are running with the panel down until there is a general consensus that everything that can be reasonable done is complete.

Can we get a status regarding the dev teams findings and if there are other patches soon to be released?

As always, appreciate your work on the project and security hardening.
Top

ScIT
Support team
Posts: 617
Joined: Mon Feb 23, 2015 4:13 pm

Os: Ubuntu 17x
Web: apache + nginx
Re: Got 10 VestaCP servers exploited

Post by ScIT » Tue May 08, 2018 8:07 pm

+1!
Top

DarthVader
Posts: 31
Joined: Wed Jul 13, 2016 1:35 pm

Re: Got 10 VestaCP servers exploited

Post by DarthVader » Tue May 08, 2018 8:46 pm

+1
Top

RevengeFNF
Posts: 92
Joined: Sat Aug 02, 2014 6:50 pm

Os: CentOS 6x
Web: nginx + php-fpm
Re: Got 10 VestaCP servers exploited

Post by RevengeFNF » Wed May 09, 2018 10:18 am

Mark O Polo wrote: ↑
Tue May 08, 2018 4:15 pm
It has been about a month since the 1st post regarding the exploited servers.

At a result of the exploits, one patch was issued. We also know some of the code was reviewed by Rack911labs (Patrick) and he noticed several root compromise vulnerabilities (6).

I know that many users are running with the panel down until there is a general consensus that everything that can be reasonable done is complete.

Can we get a status regarding the dev teams findings and if there are other patches soon to be released?

As always, appreciate your work on the project and security hardening.
I would also like to have news about this.
Top

Farrow
Posts: 15
Joined: Fri May 16, 2014 4:15 pm

Re: Got 10 VestaCP servers exploited

Post by Farrow » Wed May 09, 2018 11:05 am

I haven't used it since and won't until I'm sure it's been patched fully, It worries me that no one knows for sure how the panel became exploited in the first place. We have had little information on the progress of fixing the vulnerabilities that have been reported which I feel is very important. Vesta was a good little panel but the list of vulnerabilities makes it unusable for me.
Top

kobo1d
Posts: 47
Joined: Sun Nov 27, 2016 7:59 pm

Re: Got 10 VestaCP servers exploited

Post by kobo1d » Wed May 09, 2018 5:03 pm

yea. i have kept my panel shutted down too.

news are very welcome!
Top

imperio
VestaCP Team
Posts: 7000
Joined: Sat Dec 01, 2012 12:37 pm
Contact:
Contact imperio
Website

Re: Got 10 VestaCP servers exploited

Post by imperio » Fri May 11, 2018 7:26 pm

New release with mass security fixes will in Monday or Tuesday
Now we are thinking about the roundcube
Top

sohail_sandy
Posts: 1
Joined: Mon Apr 09, 2018 2:08 am

Os: Ubuntu 15x
Web: apache
Re: Got 10 VestaCP servers exploited

Post by sohail_sandy » Sat May 12, 2018 2:04 pm

albertus wrote: ↑
Sat Apr 07, 2018 2:56 pm
Hello!

Today I was surprised to discover that 10 of our customers servers were being exploited (attacking a chinese IP). All these servers have nothing in common but the fact they all run VestaCP. None of my non-VestaCP servers were affected.

I would like to ask if anyone was also affected. Any chance there's a VestaCP vulnerability being exploited in the wild?

Thank you in advance

Kindly, Albertus
Yes. The server has just gone down. Nobody was able to login to my website and when I tried to log into vestacp dashboard, it also failed. After I SSH into the server, I found that there was no space left on the server. And after a couple of minutes, Digitalocean deactivated networking.

Right now my website is down.
Top

paulokruz
Posts: 8
Joined: Wed Apr 06, 2016 3:16 pm

Re: Got 10 VestaCP servers exploited

Post by paulokruz » Sat May 12, 2018 9:42 pm

I found this entrys in negix error log:

Code: Select all

2018/05/11 16:24:21 [error] 3422#0: *50 open() "/usr/local/vesta/web/sdk" failed (2: No such file or directory), client: 159.203.250.164, server: _, request: "POST /sdk HTTP/1.1", host: "my_domain_name.XXX:8$
2018/05/11 16:24:31 [error] 3422#0: *53 "/usr/local/vesta/web/profilemanager/index.php" is not found (2: No such file or directory), client: 159.203.250.164, server: _, request: "GET /profilemanager/ HTTP/1$
2018/05/11 16:25:16 [error] 3422#0: *135 open() "/usr/local/vesta/web/sdk" failed (2: No such file or directory), client: 159.203.250.164, server: _, request: "POST /sdk HTTP/1.1", host: "my_domain_name.XXX:$
2018/05/11 16:36:49 [error] 3422#0: *1918 open() "/usr/local/vesta/web/Portal/Portal.mwsl" failed (2: No such file or directory), client: 159.203.250.164, server: _, request: "GET /Portal/Portal.mwsl?PriNav$
2018/05/11 16:50:30 [error] 3422#0: *6691 open() "/usr/local/vesta/web/db" failed (2: No such file or directory), client: 159.203.250.164, server: _, request: "GET /db HTTP/1.1", host: "my_domain_name.XXX:80$
Seems calls from my domain url.

It's related to exploited ?
Top

imperio
VestaCP Team
Posts: 7000
Joined: Sat Dec 01, 2012 12:37 pm
Contact:
Contact imperio
Website

Re: Got 10 VestaCP servers exploited

Post by imperio » Sun May 13, 2018 7:45 am

Not related
Top


Locked
  • Print view

549 posts
  • Page 54 of 55
    • Jump to page:
  • Previous
  • 1
  • …
  • 51
  • 52
  • 53
  • 54
  • 55
  • Next

Return to “General Discussion”



  • Board index
  • All times are UTC
  • Delete all board cookies
  • The team
Powered by phpBB® Forum Software © phpBB Limited
*Original Author: Brad Veryard
*Updated to 3.2 by MannixMD
 

 

Login  •  Register

I forgot my password