New on LowEndTalk? Please Register and read our Community Rules.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

Comments
ceres, jupiter, saturn, neptune, eris, mercury
neptune was affected.
I am on Ceres....phew....
or is the "one more node", Ceres
Junglesec replied to my email
Why don't you disconnect the IPMI?!
So you risk it that this machine also gets compromised?!
Name checks out.
Sorry, had to.
We have already pulled all other IPMI Ethernet cables. Only neptune IPMI is online as we will reinstall this soon.
We have managed to decrypt one client's VM data. The VPS is unusable after decrypting but www and mysql is intact. So that's something.
Edit: It can boot now but most of the apps aren't running as expected. Probably can be fixed but we will just take data and rebuild.
0.037 bitcoin = 25,000 Chinese Yuan.
And the attacker told me that he will not attack HostCram servers anymore.
Okay, I take back what I said then before.
I thought by you words, your IPMI would be still at risk and connected.
The first "bulletproof" junglesec ransomware provider
As if they know what belongs to whom unless they get IP subnets from the host to whitelist them.
That's right. Already checked our subnet against his logs.
What about the other group? I mean are they the only one doing this?
One of my servers at TempestHosting, which doesn't have public access to IPMI, has been hacked, so I'm not sure if the issue is really an IPMI flaw that's being exploited.
It is not. In your case. Obviously.
We have assigned everyone affected a new VPS with 6 months free service as compensation.
Also helping with restoring their data on their new VPS.
Hello, im in one of the unnafected nodes, but I cant access my server, and its not showing on the panel.
Is that ceres? We did a complete sweep, added some new codes and secured it properly.
Reboots are necessary. Should be up in a few minutes.
Now is all working.
Thanks Shakib, sorry this happened to you, I think you have been the best provider, the few times I needed support is always on point.