Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Shells Virtual Desktop
BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Rabisu - Hosting Solutions
Shells Virtual Desktop
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

All my dedi infected with Junglesec Ransomware from Fiberstate colo

bikramabikrama Member
edited November 2024 in General

All the dedicated AMD server hosted with fiberstate are now infected with Ransomware. I even not able to do root login @fiberstate due to open ipmi provided by @fiberstate

Thanked by 1mustafamw3
«134

Comments

  • there is another thread today about a ransomware here,
    probably both interlinked.

    something related to ipmi

  • @seenu said:
    there is another thread today about a ransomware here,
    probably both interlinked.

    something related to ipmi

    Look like it is @fiberstate issues as servers with them are getting affected. We have almost more 100+ dedi in other colos none have issue. But all server in @fiberstate got Ransomware!

  • plumbergplumberg Veteran, Megathread Squad

    I just hope you have the backups of important data.

  • @plumberg said:
    I just hope you have the backups of important data.

    We have backup of all the data, We do have automatic remote backup every 2hrs, But to restore data will take much time. And i am not sure if after restore of data it can again be hacked. May be they might have added some backdoor anything possible not sure.

    Thanked by 1plumberg
  • plumbergplumberg Veteran, Megathread Squad

    @bikrama said:

    @plumberg said:
    I just hope you have the backups of important data.

    We have backup of all the data, We do have automatic remote backup every 2hrs, But to restore data will take much time. And i am not sure if after restore of data it can again be hacked. May be they might have added some backdoor anything possible not sure.

    I hope the operations/ restore happen fast for you guys.
    Any vulnerability can be attacked any time, with any provider. Lets see what @fiberstate rep has to say on this.

    Maybe they will clarify how many are impacted and what is the resolution.

  • HostSlickHostSlick 🚩 Host Rep Tag Suspended
    edited November 2024

    Running IPMI on public IPs or what?

  • Statement @fiberstate ?

  • I have a dedi with fibrestate too...backing up my data now lol

  • fiberstatefiberstate Member, Patron Provider

    We do not manage colocation servers, entirely up to the customer to secure IPMI and or setup a solution to do such. There are many variations of hardware that are sent to us, it's entirely the customers responsibility to secure machines and IPMI.

  • plumbergplumberg Veteran, Megathread Squad

    @bikrama said:
    All the dedicated AMD server hosted with fiberstate are now infected with Ransomware. I even not able to do root login @fiberstate due to open ipmi provided by @fiberstate

    Yours is colocation? Or rental from Fiberstate?

  • wuckwuck Member
    edited November 2024

    If thats a colocation why would provider have to secure their server IPMI since they don't setup those

    Thanked by 1Moopah
  • fiberstatefiberstate Member, Patron Provider

    @bikrama Do you have a ticket number, please?

  • We recommend to activate your Disaster Recovery Plan.

  • plumbergplumberg Veteran, Megathread Squad

    So what happened here? The attacker picked on a vulnerability of the ipmi software?

  • -_- No Fiber, This your stupidity, why you give IPMI public IP in 2024 ??

    Give customers Vlan and VPN segregated, this is your mess and shows lost face, and disrespectful to customers whom you've outed.

  • @fiberstate said:
    We do not manage colocation servers, entirely up to the customer to secure IPMI and or setup a solution to do such. There are many variations of hardware that are sent to us, it's entirely the customers responsibility to secure machines and IPMI.

    It is not colocation server, It is rented server from you.

  • @plumberg said:
    So what happened here? The attacker picked on a vulnerability of the ipmi software?

    Just weak management of physical hardware. You can Google they literally didn't change the default password.

  • @fiberstate said:
    @bikrama Do you have a ticket number, please?

    We just request to reinstall our server with Ubuntu 22.04 , I will share ticket number in pm

  • fiberstatefiberstate Member, Patron Provider

    Your title mentioned colo. We do not see any ticket at the moment mentioning this, can you please open and or give us your ticket number @bikrama

  • fiberstatefiberstate Member, Patron Provider

    @bikrama said:

    @fiberstate said:
    @bikrama Do you have a ticket number, please?

    We just request to reinstall our server with Ubuntu 22.04 , I will share ticket number in pm

    Thank you. We'll follow up on it.

  • @bikrama said:

    @fiberstate said:
    We do not manage colocation servers, entirely up to the customer to secure IPMI and or setup a solution to do such. There are many variations of hardware that are sent to us, it's entirely the customers responsibility to secure machines and IPMI.

    It is not colocation server, It is rented server from you.

    Thanked by 1darkimmortal
  • yoursunnyyoursunny Member, IPv6 Advocate

    Mentally strong people unplug the IPMI cord and perform remote management through KVM switch over VGA + PS/2.

  • bikramabikrama Member
    edited November 2024

    @fiberstate said:

    @bikrama said:

    @fiberstate said:
    @bikrama Do you have a ticket number, please?

    We just request to reinstall our server with Ubuntu 22.04 , I will share ticket number in pm

    Thank you. We'll follow up on it.

    Ticket #XTM-154706 - cannot SSH or IPMI.

    This server had almost 4 times hardware failure in last 6 month from renting server from you guys, Check all ticket. Sometimes hdd issue, sometimes you replace network card, sometimes you replace board and so on. Now it is affected by ransomware and we had to complete reinstall again.

  • fiberstatefiberstate Member, Patron Provider

    @bikrama said:

    @fiberstate said:

    @bikrama said:

    @fiberstate said:
    @bikrama Do you have a ticket number, please?

    We just request to reinstall our server with Ubuntu 22.04 , I will share ticket number in pm

    Thank you. We'll follow up on it.

    Ticket #XTM-154706 - cannot SSH or IPMI.

    This server had almost 4 times hardware failure in last 6 month from renting server from you guys, Check all ticket. Sometimes hdd issue, sometimes you replace network card, sometimes you replace board and so on. Now it is affected by ransomware and we had to complete reinstall again.

    We show this ticket was handled and fully resolved for you earlier today.

  • @fiberstate said:

    @bikrama said:

    @fiberstate said:

    @bikrama said:

    @fiberstate said:
    @bikrama Do you have a ticket number, please?

    We just request to reinstall our server with Ubuntu 22.04 , I will share ticket number in pm

    Thank you. We'll follow up on it.

    Ticket #XTM-154706 - cannot SSH or IPMI.

    This server had almost 4 times hardware failure in last 6 month from renting server from you guys, Check all ticket. Sometimes hdd issue, sometimes you replace network card, sometimes you replace board and so on. Now it is affected by ransomware and we had to complete reinstall again.

    We show this ticket was handled and fully resolved for you earlier today.

    The server was only reinstalled with new OS, But IPMI is still open so it can again get attack with ransomware. It is not permanent solution to just reinstall the OS

    Thanked by 1darkimmortal
  • plumbergplumberg Veteran, Megathread Squad

    @fiberstate so is this customer infected with JungleSec?

  • un_usedun_used Member
    edited November 2024

    @bikrama said: The server was only reinstalled with new OS, But IPMI is still open so it can again get attack with ransomware. It is not permanent solution to just reinstall the OS

    Can you show masqueraded screenshot without public info showing they gave the IPMI motherboard public IP? This is egg on face all over again like my Green Cloud VM

  • fiberstatefiberstate Member, Patron Provider

    @bikrama said:

    @fiberstate said:

    @bikrama said:

    @fiberstate said:

    @bikrama said:

    @fiberstate said:
    @bikrama Do you have a ticket number, please?

    We just request to reinstall our server with Ubuntu 22.04 , I will share ticket number in pm

    Thank you. We'll follow up on it.

    Ticket #XTM-154706 - cannot SSH or IPMI.

    This server had almost 4 times hardware failure in last 6 month from renting server from you guys, Check all ticket. Sometimes hdd issue, sometimes you replace network card, sometimes you replace board and so on. Now it is affected by ransomware and we had to complete reinstall again.

    We show this ticket was handled and fully resolved for you earlier today.

    The server was only reinstalled with new OS, But IPMI is still open so it can again get attack with ransomware. It is not permanent solution to just reinstall the OS

    Your IPMI is secure. We've provided you the necessary information on your ticket.

  • @un_used said:

    @bikrama said: The server was only reinstalled with new OS, But IPMI is still open so it can again get attack with ransomware. It is not permanent solution to just reinstall the OS

    Can you show masqueraded screenshot without public info showing they gave the IPMI motherboard public IP? This is egg on face all over again like my Green Cloud VM

    It's standard. My Fiberstate dedi rental came with a public IPMI IP + login. It's also unclear how I'm expected to secure it against any IPMI exploit that could be used to install ransomware.

Sign In or Register to comment.