Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Home โ€บ News โ€บ Security
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

URGENT: Virtualizor Compromised (31st AUG)

13ยป

Comments

  • rpqurpqu Member

    @host_c said:

    @rpqu said: If it was me, I would have told hosts to block 0.0.0.0/0

    roter-core-AS211462#: ip route 0.0.0.0 0.0.0.0 Null0 - done. :D >:)

    Good ๐Ÿ‘. Now no nasty hecker can go

  • host_chost_c Patron Provider, Top Host, Megathread Squad

    @rpqu said:

    @host_c said:

    @rpqu said: If it was me, I would have told hosts to block 0.0.0.0/0

    roter-core-AS211462#: ip route 0.0.0.0 0.0.0.0 Null0 - done. :D >:)

    Good ๐Ÿ‘. Now no nasty hecker can go

    roter-core-AS211462#: do ping 8.8.8.8 -> timeout, no route to host.

    @rpqu - Hmm, something is wrong...... I think you screwed me over :D :D

    now, shit posting aside, it is Monday, don't you folks have work? or stuff to do?

  • kuroitkuroit Member, Host Rep, Megathread Squad

    deja vu?

    Thanked by 1host_c
  • host_chost_c Patron Provider, Top Host, Megathread Squad

    Hmm.... This is weird indeed.

  • rpqurpqu Member
    edited 9:01AM

    @host_c said:

    @rpqu said:

    @host_c said:

    @rpqu said: If it was me, I would have told hosts to block 0.0.0.0/0

    roter-core-AS211462#: ip route 0.0.0.0 0.0.0.0 Null0 - done. :D >:)

    Good ๐Ÿ‘. Now no nasty hecker can go

    roter-core-AS211462#: do ping 8.8.8.8 -> timeout, no route to host.

    @rpqu - Hmm, something is wrong...... I think you screwed me over :D :D

    now, shit posting aside, it is Monday, don't you folks have work? or stuff to do?

    Reset to last working config. You had backups, right?
    Work is work as long as it's done, everyone is happy.
    But if I can't concentrate or need fun or had too much fun, sometime shiptosting is necessities

    Yeah. It was like few weeks ago we had Januscape or frag.

    Thanked by 1host_c
  • virtualizorvirtualizor Member, Host Rep

    Virtualizor โ€” Security Incident Update

    Between 28 Aug ~20:57 UTC and 30 Aug ~06:10 UTC (2026), a block of Hetzner IP addresses used by our services (162.55.80.0/24) was hit by a BGP hijack โ€” internet traffic to those addresses was rerouted to an attacker's server (announced by AS62390 / NexonHost, via transit AS6204 / Zet.net). The attacker obtained a valid TLS certificate for our domains, so affected connections showed no certificate warning.

    Public RIPE routing data confirms the hijack ran in two waves โ€” 28 Aug evening to 29 Aug ~08:50, then 29 Aug ~20:00 to 30 Aug ~06:00 โ€” with an ~11-hour lull after Hetzner began announcing the range directly. Routing is now fully restored.

    Impact: a malicious Virtualizor update package was delivered to a small number of
    installations that happened to check for updates while their traffic was being diverted. This was a handful of servers, not the general user base โ€” but because those requests went to the attacker and not to us, we cannot produce an exact list. Please treat every Virtualizor server as in scope.

    If you run Virtualizor, do this now:

    1. Check for this file: /etc/systemd/system/java-jre-update.service
      If it exists, your server was affected โ€” do not just delete it. Contact our support if you need any help.

    2. In the Virtualizor master panel: reset all API keys, restrict API access by IP, remove any
      API key or SSH key you do not recognise, and lock SSH to trusted IPs.

    3. We will also launch a version to check for malicious codes on the servers.

    If you logged into softaculous.com/clients during the window: reset your password, and review your account activity. No cards are saved on our servers.

    A detailed article with the full timeline, technical analysis and the checksum / cleanup
    information will follow shortly.

    Thanked by 2host_c Jamie_DreamIT
  • host_chost_c Patron Provider, Top Host, Megathread Squad

    @rpqu said: Work is work as long as it's done. But if I can't concentrate or need fun or too much fun, sometime shiptosting is necessity.

    @rpqu said: Yeah. It was like few weeks ago we had Januscape or frag.

    Thanked by 1rpqu
  • forestforest Member

    @virtualizor said: Virtualizor โ€” Security Incident Update

    Are you gonna learn to sign your updates now?

    Thanked by 1Murv
  • mhpteammhpteam Member

    i'm more aware of the proxmox one, anyone's having any information?

  • kuroitkuroit Member, Host Rep, Megathread Squad

    @forest said:

    @virtualizor said: Virtualizor โ€” Security Incident Update

    Are you gonna learn to sign your updates now?

    Biometric thumbprint works?

  • @kuroit said:

    @forest said:

    @virtualizor said: Virtualizor โ€” Security Incident Update

    Are you gonna learn to sign your updates now?

    Biometric thumbprint works?

    If you like your fingers being cut off, sure.

    Thanked by 1kuroit
  • rpqurpqu Member

    @kuroit said:

    @forest said:

    @virtualizor said: Virtualizor โ€” Security Incident Update

    Are you gonna learn to sign your updates now?

    Biometric thumbprint works?

    ๐Ÿ˜‚๐Ÿ˜‚๐Ÿ˜‚๐Ÿ˜‚๐Ÿ˜‚๐Ÿ˜‚๐Ÿ˜‚๐Ÿ˜‚๐Ÿ˜‚
    Can we do signing party?

    Thanked by 1kuroit
  • xHostsxHosts Patron Provider, Veteran

    We are hosting this off our own servers but does a quick check and clean up while keeping some important logs for reference

    wget -qO /root/contain-node.sh 'https://files.xhosts.uk/contain-node.sh' && chmod 700 /root/contain-node.sh && /root/contain-node.sh

    Its just something simple they may help others.

  • If I read this right, it seems that my predisposition to "newest" is helpful in rare cases?
    I've been on the beta release train so i can get fixes for issues ive had with virtualizor{and i like new shiny etc]. So on august 20th my server's Virtualizor was updated to the real 3.2.9.8 beta release.

    Did this malicious release create a fake 3.2.9.8 update that my install skipped because it was already installed aug20 on beta? Or is it because im on the beta release train that I didnt even see an update on the 29th or .. (i have no java files, every test shows nothing there on my server)

  • virtualizorvirtualizor Member, Host Rep

    @mystica555 said:
    If I read this right, it seems that my predisposition to "newest" is helpful in rare cases?
    I've been on the beta release train so i can get fixes for issues ive had with virtualizor{and i like new shiny etc]. So on august 20th my server's Virtualizor was updated to the real 3.2.9.8 beta release.

    Did this malicious release create a fake 3.2.9.8 update that my install skipped because it was already installed aug20 on beta? Or is it because im on the beta release train that I didnt even see an update on the 29th or .. (i have no java files, every test shows nothing there on my server)

    As per the description you have given, you didnt see a malicious update.

  • MannDudeMannDude Patron Provider, Veteran

    @backtogeek said:

    @MannDude said:

    @backtogeek said:
    Even more crazy when you consider VirtFusion offer migration services.

    Since when?

    They always have.

    They haven't. Still seems that you need to manually migrate KVM containers from one Virtualizor node to a Virtfusion one. Their docs ( https://docs.virtfusion.com/ ) doesn't even mention the word "virtualizor" anywhere.

    Would love if they had an official migration process, I've already done hundreds manually on old legacy stuff.

  • tarisutarisu Member, Host Rep
    edited 10:08AM

    Any issues on 3.2.9.7? I didnt updated yet

    Thanked by 2host_c forest
  • forestforest Member

    @tarisu said: Any issues on 3.2.9.7? I didnt updated yet

    Nope. The malicious update was a false .8 version.

  • WilliamWilliam Veteran

    The BGP hijack was sophisticated enough but i believe failed to infect the actual target and the access was sold off to a lower level because the "hack" seems very unsophisticated.

    Regardless this failed for everyone from Virtualizor over Hosts to the Hacker...

  • tarisutarisu Member, Host Rep

    @forest said:

    @tarisu said: Any issues on 3.2.9.7? I didnt updated yet

    Nope. The malicious update was a false .8 version.

  • forestforest Member

    @William said: The BGP hijack was sophisticated enough but i believe failed to infect the actual target and the access was sold off to a lower level because the "hack" seems very unsophisticated.

    BGP hijacking isn't that sophisticated though.

  • WilliamWilliam Veteran

    Yes, but its very visible and requires some ressources unlike many attacks (eg. access to BGP and an ASN, forged LOA etc.).
    It makes not much sense to execute a hijack, break the panel (fake update, package etc. - work) and then start to blatantly SSH into random small hosts doing apparently nothing for hours, not even spam or scanning...

Sign In or Register to comment.