Vesta Control Panel - Forum

Community Forum

Skip to content

Advanced search
  • Quick links
    • Main site
    • Github repo
    • Google Search
  • FAQ
  • Login
  • Register
  • Board index Main Section General Discussion
  • Search

All VestaCP installations being attacked Topic is solved

General questions about VestaCP
Locked
  • Print view
Advanced search
231 posts
  • Page 14 of 24
    • Jump to page:
  • Previous
  • 1
  • …
  • 12
  • 13
  • 14
  • 15
  • 16
  • …
  • 24
  • Next
Spheerys
Posts: 225
Joined: Tue Dec 29, 2015 12:36 pm

Os: Debian 7x
Web: apache + nginx
Re: All VestaCP installations being attacked

Post by Spheerys » Mon Oct 08, 2018 7:02 pm

I'm a little be disapointed by the fact we still don't have any clue to investigate about this hack.
We were several to ask how to check if ours servers are under attack, but we don't have any clear anwser to chek, and to understand the attack.

People which have hundred hacked servers : please give us more information, at least to check if we are impacted or not.
Top

jcerdan
Posts: 13
Joined: Mon Apr 09, 2018 7:36 pm

Os: Ubuntu 15x
Web: apache + nginx
Re: All VestaCP installations being attacked

Post by jcerdan » Tue Oct 09, 2018 8:54 am

Hi,

I think the issue is in VestaCP web interface.
Is there a possibilty for Vesta Dev Team to separate Vesta in little projects?

1) Vesta-core with API script
2) Vesta Web Interface
3) Vesta -softaculous & vesta-ioncube

This way, anybody would install only what they really want and develop its own web frontend, shared on github or not.
Also, security for Vesta Team should be focused on Vesta-core and API, letting other developers enter and modify/enhance Vesta Web interface.

Regards,
Top

Spheerys
Posts: 225
Joined: Tue Dec 29, 2015 12:36 pm

Os: Debian 7x
Web: apache + nginx
Re: All VestaCP installations being attacked

Post by Spheerys » Tue Oct 09, 2018 9:06 am

We can maybe hardener VestaCP with a .htpasswd ?
Top

jcerdan
Posts: 13
Joined: Mon Apr 09, 2018 7:36 pm

Os: Ubuntu 15x
Web: apache + nginx
Re: All VestaCP installations being attacked

Post by jcerdan » Tue Oct 09, 2018 11:07 am

You can do that, but I don't know if API calls will be affected by the .htaccess.
Also, you can create a sort of "bridge" in PHP via another server to access VestaCP web interface, by translating POST and GET calls, but that's a little bit harder.

Best thing for now is restrict access to VestaCP Panel by IP and if Dev Team can separate VestaCP in projects that will allow other devs to create new Web interfaces to Vesta-core and API.
Top

agus
Posts: 10
Joined: Fri Aug 18, 2017 2:59 am

Os: CentOS 6x
Web: apache + nginx
Re: All VestaCP installations being attacked

Post by agus » Tue Oct 09, 2018 1:33 pm

jcerdan wrote: ↑
Tue Oct 09, 2018 11:07 am
You can do that, but I don't know if API calls will be affected by the .htaccess.
Also, you can create a sort of "bridge" in PHP via another server to access VestaCP web interface, by translating POST and GET calls, but that's a little bit harder.

Best thing for now is restrict access to VestaCP Panel by IP and if Dev Team can separate VestaCP in projects that will allow other devs to create new Web interfaces to Vesta-core and API.
how to do this?
Top

jcerdan
Posts: 13
Joined: Mon Apr 09, 2018 7:36 pm

Os: Ubuntu 15x
Web: apache + nginx
Re: All VestaCP installations being attacked

Post by jcerdan » Tue Oct 09, 2018 2:33 pm

Hi @agus,

search in this forum and you'll find
Top

imperio
VestaCP Team
Posts: 7000
Joined: Sat Dec 01, 2012 12:37 pm
Contact:
Contact imperio
Website

Re: All VestaCP installations being attacked

Post by imperio » Tue Oct 09, 2018 4:42 pm

We are thinking, what we can do with this

The project continues to develop. Don't worry
Top

joni
Posts: 60
Joined: Sat Aug 27, 2016 9:22 pm

Os: Ubuntu 18x
Web: nginx + php-fpm
Re: All VestaCP installations being attacked

Post by joni » Tue Oct 09, 2018 4:50 pm

Ohh thank you for info, we were in panic
Top

imperio
VestaCP Team
Posts: 7000
Joined: Sat Dec 01, 2012 12:37 pm
Contact:
Contact imperio
Website

Re: All VestaCP installations being attacked

Post by imperio » Tue Oct 09, 2018 5:03 pm

kandalf wrote: ↑
Fri Oct 05, 2018 10:11 am
How can we know if our server is compromised?
if this file /usr/bin/dhcprenew exists on your server it means that it is hacked
Top

joni
Posts: 60
Joined: Sat Aug 27, 2016 9:22 pm

Os: Ubuntu 18x
Web: nginx + php-fpm
Re: All VestaCP installations being attacked

Post by joni » Tue Oct 09, 2018 5:43 pm

imperio wrote: ↑
Tue Oct 09, 2018 5:03 pm
kandalf wrote: ↑
Fri Oct 05, 2018 10:11 am
How can we know if our server is compromised?
if this file /usr/bin/dhcprenew exists on your server it means that it is hacked
Hallo,
..and what should we do? will just deleting this file help saving us from other problems or we must reinstall the servers?
Top


Locked
  • Print view

231 posts
  • Page 14 of 24
    • Jump to page:
  • Previous
  • 1
  • …
  • 12
  • 13
  • 14
  • 15
  • 16
  • …
  • 24
  • Next

Return to “General Discussion”



  • Board index
  • All times are UTC
  • Delete all board cookies
  • The team
Powered by phpBB® Forum Software © phpBB Limited
*Original Author: Brad Veryard
*Updated to 3.2 by MannixMD
 

 

Login  •  Register

I forgot my password