New on LowEndTalk? Please Register and read our Community Rules.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
Comments
It's software written like PHP 4, they don't understand digital signatures, everything is on a single hetzner machine, and the target for most of its customers is people that don't know how to install wordpress on cpanel
The criticism about signed updates and infrastructure design is fair. The rest is just pointless elitism. Using a control panel doesn’t mean someone can’t administer a server; it means they prefer automation over doing repetitive work manually. Also, if we’re going to criticise Virtualizor for things like CAA, it’s worth noting that other panels don’t necessarily have CAA configured either. Judge the actual security architecture, not the customers using the product.
"nerat" could mean 'Not rat" from russian slang "не рат", also qwins is hosting who being widely advertised on russian "hacking forums" (like lolzteam which is operated on russian government hostings)
so attackers could be russian slaves
this domain proves theory too
And well, also the fact that their dashboard (web.ne-rat.xyz) was in Russian.
The thing is that qwins ltd is reselling before it was from dataforest (which dataforest was fast to kick them out), and now the domain mentioned and the IP is from femo it solution limited and the upstream is aurologic GmbH!
im so shocked
aurologic and dataforest is most used dedi providers russians use to resell vps
i saw decent amount russian hosts who selling 2 bucks vps for their local community and 90% of them has upstream aurologic or dataforest (mostly dataforest)
cuz they cant go to europe to setup colo for obvious reasons, so since aurologic and dataforest support byoip (for like 20 eur setup fee) and has cool prices even today thats almost the only way to start hosting
(and i think you guys know that aurologic dont really care who their customers are, they still provide services to aeza LOL after a 1.5 since aeza ceo was arrest and since year US sanctioned them)
Don’t want to sound stupid, but I migrated around 1,300 VMs from Virtualizor to VF using OpenClaw + Opus. I did it gradually in batches of around 20, and the whole process took about a week back in July, with only a couple of hours of downtime while rerouting everything.
After their last security compromise, I’d had enough and haven’t looked back since. It’s probably the worst and buggiest panel I’ve ever used. I can’t believe I stuck with it for so long, especially now that I can fit around 30–40% more VMs on the exact same hardware with VF. Makes me think something with Virtualizor’s memory ballooning or resource management wasn’t working properly.
Its a scary feeling, that something will happen again.
A update of 3.2.9 is currently showing but nothing on their change log at this time ….
I'd wait a little before clicking the "Update now" button...
Press it! No risk, no fun 🤣
Also, it could be worse. You could let me in your house and the result would be that all your cheese is gone. Certainly way worse than this.
So while @virtualizor seems to have "ignored" my comment, they actually seem to have got the message ...
THAT alone (not having a CAA record) IMO clearly showed that they either are clueless or utterly careless re their customers, or both.
Or it confirms that someone wanted the attack to look "russian" ...
The (sad) fact is that attribution usually is really hard.
Looks like at least 270 Virtualizor hosts were compromised, from what I can see on Censys
Looks like Virtualizor pushed an update to try and get rid of the malware:
inb4 "Mythos 6 breaks sandbox and hacks Virtualizor" articles
Why not migrate to VirtFusion? Most customers would be understanding even if it causes some downtime, as it would spare them the mental burden of constantly wondering when the next drama will unfold.
Does VirtFusion support LVM Thin storage?
Omg. What the fccc
edit: oops I don't think lvm, but yes thin. however, very easy to migrate.
Yeah, thin provisioning itself isn't really the issue. My concern is the extra filesystem/qcow2 COW layer.
We're currently using LVM Thin with block devices for our KVM nodes. From what I understand VirtFusion's default local storage is file-backed qcow2 on ext4.
With qcow2, small random writes can result in additional allocation and metadata I/O due to the qcow2 cluster/COW layer on top of the host filesystem. I remember this being discussed quite a bit in the Proxmox community as write amplification.
That's one of the reasons I'd prefer to keep LVM Thin rather than move all of our VPS storage to qcow2 files.
The qcow2 images can be generated with
preallocation=fullandnocow=on.I agree that putting each VM image on LVM is better than a bunch of qcow2 files on a filesystem though, but for other reasons (it's a lot easier to corrupt a filesystem, even one like ZFS, than it is to corrupt LVM metadata).
Yes, they got what they deserved because they often 'hack' their own users.
wait how about softaculous?
Providers still using Virtualizor really need to ditch it and switch to VirtFusion already.
virtualizor, softaculous, and webuzo got all ssl cert compromised so it's fun to triple check all of them!
Thanks for including @hostnamaste in the list and for checking with the providers.
We have investigated this on our side and also confirmed with our technical team. We have checked the reported indicators and run the official Virtualizor security scan, and we have found no signs of compromise on our Virtualizor infrastructure.
Everything is clean from our side at this time. 👍
maybe this is a sign, and gods giving you one more chance to switch to Virtfusion. The next time Virtualizor gets hacked, u may not be so lucky 😂