Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

URGENT: Virtualizor Compromised (31st AUG)

2»

Comments

  • AlbaHostAlbaHost Member, Patron Provider

    @Radi said:
    *8 update was released on 20th August?

    Only if you have ticked for beta release in your virtualizor panel, otherwise they publish always earlier on their blog but live updates take place late i.e a week or two.

  • RadiRadi Host Rep, Veteran

    @AlbaHost said:

    @Radi said:
    *8 update was released on 20th August?

    Only if you have ticked for beta release in your virtualizor panel, otherwise they publish always earlier on their blog but live updates take place late i.e a week or two.

    I am on *7 and ticked Stable, well now changed to "NEVER".

  • aphexaphex Member

    @forest said: Let me guess, none of the hosts whose nodes were compromised will actually fully reinstall from scratch?

    Let me guess #2, virtualizor doesn't know what PKI or signing things is?

    Thanked by 1forest
  • AlbaHostAlbaHost Member, Patron Provider

    @Radi said:

    @AlbaHost said:

    @Radi said:
    *8 update was released on 20th August?

    Only if you have ticked for beta release in your virtualizor panel, otherwise they publish always earlier on their blog but live updates take place late i.e a week or two.

    I am on *7 and ticked Stable, well now changed to "NEVER".

    Well if you had on Stable which is by default you will be better of to check your hypervisors as the fake update that pushed malware 1-2 days ago from virtualizor servers/mirrors was automatic update.

  • JerryHouJerryHou Veteran

    with these AI tools, everyone can become a vibe hacker in minutes...

  • forestforest Member

    @aphex said:

    @forest said: Let me guess, none of the hosts whose nodes were compromised will actually fully reinstall from scratch?

    Let me guess #2, virtualizor doesn't know what PKI or signing things is?

    Oh for sure. I didn't even believe for a moment that Virtualizor would be professional enough to sign releases.

  • chatboxchatbox Member

    OMG ! Would OVH be one of those affected ? have few VPS with them :|

  • d2411d2411 Member

    @Chunkserve also use Virtualizor

    Thanked by 1JohnnySac
  • AndruAndru Member

    @naranjatech use Virtualizor to.

  • Thanked by 1host_c
  • forestforest Member

    And iHostArt. :D

    Thanked by 2Void host_c
  • MurvMurv Member, Megathread Squad

    Virtualizor makes slop panels look good

    Thanked by 1forest
  • TrKTrK Veteran

    virtualizor got virtualizord.

  • host_chost_c Patron Provider, Top Host, Megathread Squad

    @Jamie_DreamIT said:
    Virtualizor has been compromised, their BGP hijack a few days ago seems to have a deployed a malicious package.

    • RESET/LIMIT ALL API CREDENTIALS IN THE VIRT MASTER PANEL BY IP
    • CHECK FOR SUSPICIOUS KEYS AND ENSURE SSH IS LOCKED DOWN
    • CHECK IF THIS FILE EXISTS ( /etc/systemd/system/java-jre-update.service )

    If you're an affected host, NOC or provider and would want to work together, please DM me, we'll appreciate any assistance here.

    Comms are being sent for existing customers, at this stage, we don't see evidence of VPS's being compromised.

    Good luck to other providers out there.

Sign In or Register to comment.