Vesta Control Panel - Forum

Community Forum

Skip to content

Advanced search
  • Quick links
    • Main site
    • Github repo
    • Google Search
  • FAQ
  • Login
  • Register
  • Board index Main Section General Discussion
  • Search

All VestaCP installations being attacked Topic is solved

General questions about VestaCP
Locked
  • Print view
Advanced search
231 posts
  • Page 15 of 24
    • Jump to page:
  • Previous
  • 1
  • …
  • 13
  • 14
  • 15
  • 16
  • 17
  • …
  • 24
  • Next
kandalf
Posts: 87
Joined: Tue May 13, 2014 11:53 pm

Re: All VestaCP installations being attacked

Post by kandalf » Tue Oct 09, 2018 11:15 pm

imperio wrote: ↑
Tue Oct 09, 2018 5:03 pm
kandalf wrote: ↑
Fri Oct 05, 2018 10:11 am
How can we know if our server is compromised?
if this file /usr/bin/dhcprenew exists on your server it means that it is hacked
Thank you very much, this was exactly what I was looking for.

My server are safe.
Top

pksh71
Posts: 3
Joined: Tue Jun 26, 2018 7:47 am

Os: CentOS 5x
Web: nginx + php-fpm
Re: All VestaCP installations being attacked

Post by pksh71 » Wed Oct 10, 2018 6:24 am

hi

My 3 servers at Hetzner also Hacked yesterday. hacker used it DDOS to a chines IP.
its service vesta was off.

what can i do?
Top

mehargags
Support team
Posts: 1096
Joined: Sat Sep 06, 2014 9:58 pm
Contact:
Contact mehargags
Website Skype

Os: Debian 8x
Web: apache + nginx
Re: All VestaCP installations being attacked

Post by mehargags » Wed Oct 10, 2018 6:40 am

Send access to your server to vesta team so we can check more
Top

pqpk2009
Posts: 45
Joined: Sun Mar 27, 2016 2:23 am

Re: All VestaCP installations being attacked

Post by pqpk2009 » Wed Oct 10, 2018 8:01 am

SSHD permissions were closed, but there was still an attack.

Problem finding procedure

/usr/local/vesta/nginx/sbin/vesta-nginx
Top

ScIT
Support team
Posts: 617
Joined: Mon Feb 23, 2015 4:13 pm

Os: Ubuntu 17x
Web: apache + nginx
Re: All VestaCP installations being attacked

Post by ScIT » Wed Oct 10, 2018 8:03 am

pqpk2009 wrote: ↑
Wed Oct 10, 2018 8:01 am
SSHD permissions were closed, but there was still an attack.

Problem finding procedure

/usr/local/vesta/nginx/sbin/vesta-nginx
was this a new attack? if yes, please send us server access using pm.
Top

neto737
Posts: 5
Joined: Thu Jun 16, 2016 7:51 pm

Re: All VestaCP installations being attacked

Post by neto737 » Wed Oct 10, 2018 9:13 am

Keep your servers safe, use keyfile instead password for SSH, and disable login with password. You can also change default SSH port. I’ve done it and everything is ok with my server.
Top

pqpk2009
Posts: 45
Joined: Sun Mar 27, 2016 2:23 am

Re: All VestaCP installations being attacked

Post by pqpk2009 » Wed Oct 10, 2018 9:32 am

ScIT wrote: ↑
Wed Oct 10, 2018 8:03 am
pqpk2009 wrote: ↑
Wed Oct 10, 2018 8:01 am
SSHD permissions were closed, but there was still an attack.

Problem finding procedure

/usr/local/vesta/nginx/sbin/vesta-nginx
was this a new attack? if yes, please send us server access using pm.
> Format: ASN | IP | Timestamp (UTC) | RPC response
> 24940 | *.*.*.* | 2018-10-09 06:41:17 | 100000 4 111/udp; 100000 3 111/udp; 100000 2 111/udp; 100000 4 111/udp; 100000 3 111/udp; 100000 2 111/udp;
> 24940 | *.*.*.* | 2018-10-09 06:56:55 | 100000 4 111/udp; 100000 3 111/udp; 100000 2 111/udp; 100000 4 111/udp; 100000 3 111/udp; 100000 2 111/udp;
Top

dpeca
VestaCP Team
Posts: 473
Joined: Wed Nov 25, 2015 7:30 pm

Re: All VestaCP installations being attacked

Post by dpeca » Wed Oct 10, 2018 9:46 am

pqpk2009 wrote: ↑
Wed Oct 10, 2018 9:32 am
ScIT wrote: ↑
Wed Oct 10, 2018 8:03 am
pqpk2009 wrote: ↑
Wed Oct 10, 2018 8:01 am
SSHD permissions were closed, but there was still an attack.

Problem finding procedure

/usr/local/vesta/nginx/sbin/vesta-nginx
was this a new attack? if yes, please send us server access using pm.
> Format: ASN | IP | Timestamp (UTC) | RPC response
> 24940 | *.*.*.* | 2018-10-09 06:41:17 | 100000 4 111/udp; 100000 3 111/udp; 100000 2 111/udp; 100000 4 111/udp; 100000 3 111/udp; 100000 2 111/udp;
> 24940 | *.*.*.* | 2018-10-09 06:56:55 | 100000 4 111/udp; 100000 3 111/udp; 100000 2 111/udp; 100000 4 111/udp; 100000 3 111/udp; 100000 2 111/udp;
Dude, this does not look as attack to me.
If you leaved NFS ports open, Hetzner will just warn you.
It does not mean that server did any attack.
Top

pqpk2009
Posts: 45
Joined: Sun Mar 27, 2016 2:23 am

Re: All VestaCP installations being attacked

Post by pqpk2009 » Wed Oct 10, 2018 9:51 am

dpeca wrote: ↑
Wed Oct 10, 2018 9:46 am
pqpk2009 wrote: ↑
Wed Oct 10, 2018 9:32 am
ScIT wrote: ↑
Wed Oct 10, 2018 8:03 am


was this a new attack? if yes, please send us server access using pm.
> Format: ASN | IP | Timestamp (UTC) | RPC response
> 24940 | *.*.*.* | 2018-10-09 06:41:17 | 100000 4 111/udp; 100000 3 111/udp; 100000 2 111/udp; 100000 4 111/udp; 100000 3 111/udp; 100000 2 111/udp;
> 24940 | *.*.*.* | 2018-10-09 06:56:55 | 100000 4 111/udp; 100000 3 111/udp; 100000 2 111/udp; 100000 4 111/udp; 100000 3 111/udp; 100000 2 111/udp;
Dude, this does not look as attack to me.
If you leaved NFS ports open, Hetzner will just warn you.
It does not mean that server did any attack.
This is the email sent by the German security agency. The other two infected servers are PM.
Top

pqpk2009
Posts: 45
Joined: Sun Mar 27, 2016 2:23 am

Re: All VestaCP installations being attacked

Post by pqpk2009 » Wed Oct 10, 2018 9:52 am

pqpk2009 wrote: ↑
Wed Oct 10, 2018 9:51 am
dpeca wrote: ↑
Wed Oct 10, 2018 9:46 am
pqpk2009 wrote: ↑
Wed Oct 10, 2018 9:32 am


> Format: ASN | IP | Timestamp (UTC) | RPC response
> 24940 | *.*.*.* | 2018-10-09 06:41:17 | 100000 4 111/udp; 100000 3 111/udp; 100000 2 111/udp; 100000 4 111/udp; 100000 3 111/udp; 100000 2 111/udp;
> 24940 | *.*.*.* | 2018-10-09 06:56:55 | 100000 4 111/udp; 100000 3 111/udp; 100000 2 111/udp; 100000 4 111/udp; 100000 3 111/udp; 100000 2 111/udp;
Dude, this does not look as attack to me.
If you leaved NFS ports open, Hetzner will just warn you.
It does not mean that server did any attack.
This is the email sent by the German security agency. The other two infected servers are PM to ScIT.
Top


Locked
  • Print view

231 posts
  • Page 15 of 24
    • Jump to page:
  • Previous
  • 1
  • …
  • 13
  • 14
  • 15
  • 16
  • 17
  • …
  • 24
  • Next

Return to “General Discussion”



  • Board index
  • All times are UTC
  • Delete all board cookies
  • The team
Powered by phpBB® Forum Software © phpBB Limited
*Original Author: Brad Veryard
*Updated to 3.2 by MannixMD
 

 

Login  •  Register

I forgot my password