Vesta Control Panel - Forum

Community Forum

Skip to content

Advanced search
  • Quick links
    • Main site
    • Github repo
    • Google Search
  • FAQ
  • Login
  • Register
  • Board index Main Section General Discussion
  • Search

All VestaCP installations being attacked Topic is solved

General questions about VestaCP
Locked
  • Print view
Advanced search
231 posts
  • Page 6 of 24
    • Jump to page:
  • Previous
  • 1
  • …
  • 4
  • 5
  • 6
  • 7
  • 8
  • …
  • 24
  • Next
dpeca
VestaCP Team
Posts: 473
Joined: Wed Nov 25, 2015 7:30 pm

Re: All VestaCP installations being attacked

Post by dpeca » Wed Sep 26, 2018 10:21 am

albertus wrote: ↑
Wed Sep 26, 2018 2:22 am
There are things called "callback" that connect from the inside to the outside giving a shell.
100% not true, because, if something ''inside'' is ''calling'', then all datacenters will be hacked - in Europe you have very big datacenters that is completly UNTOUCHED by this hack.
Why?
Because only OVH is scanned - keyword is SCANNED - because hacker is scanning IP rangs.
Otherwise, in case that something is ''calling from inside'', then all datacenters in Europe will be also 'burned' - which is not happening.
Top

eduzro
Posts: 31
Joined: Wed Apr 08, 2015 10:11 am

Re: All VestaCP installations being attacked

Post by eduzro » Wed Sep 26, 2018 10:46 am

Do you think that disabling vesta service + disabling the access to the default vesta port can prevent the hacking?
Top

L4ky
Posts: 3
Joined: Tue Jul 25, 2017 9:35 am

Re: All VestaCP installations being attacked

Post by L4ky » Wed Sep 26, 2018 10:50 am

So the vulnerability is in the web interface?

I protected vesta, roundcube and phpmyadmin with HTTP Basic Auth... that should be enough.
Top

dpeca
VestaCP Team
Posts: 473
Joined: Wed Nov 25, 2015 7:30 pm

Re: All VestaCP installations being attacked

Post by dpeca » Wed Sep 26, 2018 10:59 am

eduzro wrote: ↑
Wed Sep 26, 2018 10:46 am
Do you think that disabling vesta service + disabling the access to the default vesta port can prevent the hacking?
Not sure at all.
At this moment, at least I don't have any clue what is entry point.
Top

dpeca
VestaCP Team
Posts: 473
Joined: Wed Nov 25, 2015 7:30 pm

Re: All VestaCP installations being attacked

Post by dpeca » Wed Sep 26, 2018 11:04 am

Not even sure it's related to Vesta.
For example, serious issue in kernel, published yesterday - https://access.redhat.com/security/cve/cve-2018-14634
Top

eduzro
Posts: 31
Joined: Wed Apr 08, 2015 10:11 am

Re: All VestaCP installations being attacked

Post by eduzro » Wed Sep 26, 2018 11:35 am

dpeca wrote: ↑
Wed Sep 26, 2018 11:04 am
Not even sure it's related to Vesta.
For example, serious issue in kernel, published yesterday - https://access.redhat.com/security/cve/cve-2018-14634
I don't think it's because of this issue, as it first needs the access data of an unprivileged user (One of my servers which was hacked had only the admin user).
Top

dpeca
VestaCP Team
Posts: 473
Joined: Wed Nov 25, 2015 7:30 pm

Re: All VestaCP installations being attacked

Post by dpeca » Wed Sep 26, 2018 11:52 am

I'm not saying it's related to kernel issue, just that I'm not 100% sure it's related to Vesta...
Top

lukapaunovic
Posts: 73
Joined: Sun Dec 03, 2017 6:30 pm

Re: All VestaCP installations being attacked

Post by lukapaunovic » Wed Sep 26, 2018 12:29 pm

dpeca wrote: ↑
Wed Sep 26, 2018 10:21 am
albertus wrote: ↑
Wed Sep 26, 2018 2:22 am
There are things called "callback" that connect from the inside to the outside giving a shell.
100% not true, because, if something ''inside'' is ''calling'', then all datacenters will be hacked - in Europe you have very big datacenters that is completly UNTOUCHED by this hack.
Why?
Because only OVH is scanned - keyword is SCANNED - because hacker is scanning IP rangs.
Otherwise, in case that something is ''calling from inside'', then all datacenters in Europe will be also 'burned' - which is not happening.
I think he is talking about the reverse shell.

http://pentestmonkey.net/cheat-sheet/sh ... heat-sheet
Top

dpeca
VestaCP Team
Posts: 473
Joined: Wed Nov 25, 2015 7:30 pm

Re: All VestaCP installations being attacked

Post by dpeca » Wed Sep 26, 2018 12:33 pm

The same arguments are still here - why EU datracenters is untouched then....
Top

itismejoey
Posts: 1
Joined: Wed Sep 26, 2018 12:35 pm

Os: CentOS 5x
Web: apache + nginx
Re: All VestaCP installations being attacked

Post by itismejoey » Wed Sep 26, 2018 12:40 pm

I've been on and off the phone with OVH for the last 24 hours. I was able to get into a rescue ssh mode of my server, but they will not restore the server back to normal (even with removing everything to do with Vesta. Does anyone know if this is anything to do with the same thing last April? I am being told not to reinstall Vesta at all until I know for sure that everything is fixed. Doesn't seem like anyone from Vesta has mentioned anything yet? I guess i'll follow this thread for more.
Top


Locked
  • Print view

231 posts
  • Page 6 of 24
    • Jump to page:
  • Previous
  • 1
  • …
  • 4
  • 5
  • 6
  • 7
  • 8
  • …
  • 24
  • Next

Return to “General Discussion”



  • Board index
  • All times are UTC
  • Delete all board cookies
  • The team
Powered by phpBB® Forum Software © phpBB Limited
*Original Author: Brad Veryard
*Updated to 3.2 by MannixMD
 

 

Login  •  Register

I forgot my password