Vesta Control Panel - Forum

Community Forum

Skip to content

Advanced search
  • Quick links
    • Main site
    • Github repo
    • Google Search
  • FAQ
  • Login
  • Register
  • Board index Main Section General Discussion
  • Search

All VestaCP installations being attacked Topic is solved

General questions about VestaCP
Locked
  • Print view
Advanced search
231 posts
  • Page 16 of 24
    • Jump to page:
  • Previous
  • 1
  • …
  • 14
  • 15
  • 16
  • 17
  • 18
  • …
  • 24
  • Next
dpeca
VestaCP Team
Posts: 473
Joined: Wed Nov 25, 2015 7:30 pm

Re: All VestaCP installations being attacked

Post by dpeca » Wed Oct 10, 2018 9:54 am

pqpk2009 wrote: ↑
Wed Oct 10, 2018 9:51 am
This is the email sent by the German security agency. The other two infected servers are PM.
I know, because I get the same email when I forget to close NFS ports.
But that mail is just warning to you to close NFS ports.
Top

pqpk2009
Posts: 45
Joined: Sun Mar 27, 2016 2:23 am

Re: All VestaCP installations being attacked

Post by pqpk2009 » Wed Oct 10, 2018 10:01 am

ScIT wrote: ↑
Wed Oct 10, 2018 8:03 am
pqpk2009 wrote: ↑
Wed Oct 10, 2018 8:01 am
SSHD permissions were closed, but there was still an attack.

Problem finding procedure

/usr/local/vesta/nginx/sbin/vesta-nginx
was this a new attack? if yes, please send us server access using pm.
I have sent PM server root information.

Tell me your IP, I add it to SSHD.
Top

imperio
VestaCP Team
Posts: 7000
Joined: Sat Dec 01, 2012 12:37 pm
Contact:
Contact imperio
Website

Re: All VestaCP installations being attacked

Post by imperio » Wed Oct 10, 2018 11:57 am

Alls who servers was hacked, let us know when your servers was installed.
Top

flanders
Posts: 11
Joined: Thu Jun 12, 2014 4:46 pm

Os: CentOS 6x
Web: nginx + php-fpm
Re: All VestaCP installations being attacked

Post by flanders » Wed Oct 10, 2018 1:13 pm

my server was installed in september.
Then I rebuild it changing the panel port ( I already used custom ssh port, access ssh with key, access without password). From my last change (panel port) it is working well.
I'm using hetzner with centos 7 / apache+nginx+php7.2+mariadb10.3+csf
Top

pqpk2009
Posts: 45
Joined: Sun Mar 27, 2016 2:23 am

Re: All VestaCP installations being attacked

Post by pqpk2009 » Wed Oct 10, 2018 2:17 pm

/usr/bin/dhcprenew

My infected server does not have this file.
Top

ScIT
Support team
Posts: 617
Joined: Mon Feb 23, 2015 4:13 pm

Os: Ubuntu 17x
Web: apache + nginx
Re: All VestaCP installations being attacked

Post by ScIT » Thu Oct 11, 2018 7:06 am

pqpk2009 wrote: ↑
Wed Oct 10, 2018 2:17 pm
/usr/bin/dhcprenew

My infected server does not have this file.
The 2 we checked had it.
Top

kandalf
Posts: 87
Joined: Tue May 13, 2014 11:53 pm

Re: All VestaCP installations being attacked

Post by kandalf » Thu Oct 11, 2018 8:51 am

pqpk2009 wrote: ↑
Wed Oct 10, 2018 2:17 pm
/usr/bin/dhcprenew

My infected server does not have this file.
But how do you find that the servers were infected?
Top

Falzo
Posts: 60
Joined: Mon Mar 28, 2016 8:49 am

Re: All VestaCP installations being attacked

Post by Falzo » Thu Oct 11, 2018 10:36 am

so anything new on that? from what we can read so far here, is that only a few servers have been hit and the attacker somehow gained ssh access?
some had the vesta service running, some not... if that's the case a potential hacker would have needed to somehow get to know the admins password?

to those affected: do you allow admin for ssh access (default) and/or did you change the admin password after installation?

I haven't been affected this time (yet) and now am guessing that could be just because I don't allow admin for shell access...
BUT if the scenario is right, the (my) passwords could still be compromised, right? I don't like that idea.
Top

eduzro
Posts: 31
Joined: Wed Apr 08, 2015 10:11 am

Re: All VestaCP installations being attacked

Post by eduzro » Thu Oct 11, 2018 12:15 pm

My server was hacked in september. The Vesta service was running and I had SSH access enabled just for the admin user. I set the password with the installation command. I don't know if the file /usr/bin/dhcprenew was in the server.
Top

imperio
VestaCP Team
Posts: 7000
Joined: Sat Dec 01, 2012 12:37 pm
Contact:
Contact imperio
Website

Re: All VestaCP installations being attacked

Post by imperio » Thu Oct 11, 2018 1:12 pm

flanders,
Thank you for the information
eduzro, when your server was installed ?
Top


Locked
  • Print view

231 posts
  • Page 16 of 24
    • Jump to page:
  • Previous
  • 1
  • …
  • 14
  • 15
  • 16
  • 17
  • 18
  • …
  • 24
  • Next

Return to “General Discussion”



  • Board index
  • All times are UTC
  • Delete all board cookies
  • The team
Powered by phpBB® Forum Software © phpBB Limited
*Original Author: Brad Veryard
*Updated to 3.2 by MannixMD
 

 

Login  •  Register

I forgot my password