It looks like you're new here. If you want to get involved, click one of these buttons!
FYI:
Released: 28 November 2012
This release fixes an XSS Vulnerability within the SolusVM user interface.
DESCRIPTION : XSS Vulnerability VULNERABLE SYSTEMS : SolusVM master v1.13.02 and below RESOLUTION : Update to SolusVM v1.13.03 SEVERITY : Low CHECKED BY : Phillip Bandelow SIGNED OFF BY : Jason Smith
http://docs.solusvm.com/release_versions_stable?&#section11303
Comments
@soluslabs
Thanks for keeping us up to date on here
Order now: **Chicago** / **Buffalo** / **Los Angeles** / **Atlanta**
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksThanks for the heads up, appreciated.
[COLOR="SeaGreen"]█[/COLOR][COLOR="Red"]█[/COLOR]• [URL="http://www.onepoundwebhosting.co.uk"][COLOR="Red"][SIZE="2"][B][I][U]OnePoundWebHosting[/U][/I][/B][/SIZE][/COLOR][/URL] • [COLOR="Red"]█[/COLOR][COLOR="SeaGreen"]█[/COLOR]• [COLOR="SeaGreen"]UK Shared & Reseller Hosting[/COLOR] • [COLOR="SeaGreen"]Domain Registration[/COLOR] • [COLOR="SeaGreen"]█[/COLOR][COLOR="Red"]█[/COLOR]• [COLOR="Red"]UK XEN VPS[/COLOR] • [COLOR="Red"]PV & HVM[/COLOR] • [COLOR="Red"]█[/COLOR][COLOR="SeaGreen"]█[/COLOR]• [COLOR="SeaGreen"]99.9% Uptime Guarantee[/COLOR] • [COLOR="SeaGreen"]UK Ltd Company, Established 2006[/COLOR]
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksGoing to install this in UAT and see if there are any issues before rolling it out. Thanks @ soluslabs.
Internap VPS, Web Hosting and more - Cloud Shards | Need a VPS Upgrade?
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksKnow what would be nice? When you log into the solus admin panel, and it mentions the update on the dashboard... if there was some kind of link right there to pop up a changelog. Would not have even thought it was a security update unless I checked the website.
:D updated
EDIT: LOL! right after I posted this, I received the email from SolusLabs regarding the exploit.
- Spam
- Abuse
- Troll
0 • Disagree Agree Thanks@soluslabs Is this a fix for the problem that caused ChicagoVPS to lose 1000 containers? Or have they still not actually reported that to you?
Unless otherwise specified, opinions posted are my own, not those of any person or company I work for
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksWe can assume there was no issue.
- Spam
- Abuse
- Troll
0 • Disagree Agree Thanks@soluslabs any more info?
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksNo & No
As in what?
- Spam
- Abuse
- Troll
0 • Disagree Agree Thanks@soluslabs what the actual exploit was?
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksFor all we know there is no exploit.
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksI presume you mean the XSS? There is no more information.
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksI assumed @Jack was refering to ChicagoVPS, not the XSS
- Spam
- Abuse
- Troll
0 • Disagree Agree Thanks@Jack @soluslabs
No, Chris set the API to allow ANY remote IP and someone brute forced the API key that was intended for WHMCS and destroyed those servers
Order now: **Chicago** / **Buffalo** / **Los Angeles** / **Atlanta**
- Spam
- Abuse
- Troll
0 • Disagree Agree Thanks@CVPS_Chris
Internap VPS, Web Hosting and more - Cloud Shards | Need a VPS Upgrade?
- Spam
- Abuse
- Troll
0 • Disagree Agree Thanks@concerto49
Why did you tag him?
Order now: **Chicago** / **Buffalo** / **Los Angeles** / **Atlanta**
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksBecause this whole thread kept mentioning him. He'll read it anyway.
Internap VPS, Web Hosting and more - Cloud Shards | Need a VPS Upgrade?
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksBut solusvm only connect to allowed IPs? (/etc/xyz///....solusvm/..../allow.dat file)
Cheap Windows VPS .. (Freeeeeeeeee) ... Do you know what is autoboot? no?
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksThis thread has nothing to do with ChicagoVPS and is not related in any way.
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksI know, but others don't, people just don't seem to understand that ChicagoVPS was COMPROMISED and NOT exploited...
Order now: **Chicago** / **Buffalo** / **Los Angeles** / **Atlanta**
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksWe're talking about the remote API generally used to provision servers from WHMCS ;-)
Order now: **Chicago** / **Buffalo** / **Los Angeles** / **Atlanta**
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksGreat keep up the good work Solus.
- Spam
- Abuse
- Troll
0 • Disagree Agree Thanks