Very interesting to note that most of the hosting we heard of complains (hertzner, OVH, virtualizor, Locaweb, etc) are not in the list of partners, and for the special case of the wildfire spread in Brasil was mostly for this kind of hosting that...
Yes, my view is indeed quite limited: The Internet would be in a better state if people would not run EOL systems on it.
But you are missing my actual point: It's pointless to clean an infected system since you might have missed an unknown...
I can't say anything about the other parts of the writeup, but the "recommendation" for cleanup/rebuild irritates me:
I can't agree with this. This is a lot of work while you still could overlook something or the bad actor (now that the attack...
Proxmox VE 7.1 - cryptojacking rootkit + root SSH backdoor: full teardown
TL;DR
Two PVE 7 hosts were compromised and running an XMRig cryptominer hidden by a preload rootkit. The same "install_and_mine.sh / libhide" toolchain planted:
A...
What could be done to improve your feeling? Maybe switch to HyperV or VMware or Citrix and connect them directly to the internet without updating for years? I don't expect anyone to not update those for years at a time. How's Proxmox different...
Then you are still vulnerable due to the known and unknown security issues in PVE8 (which is EOL) and Debian Bookworm. The fix is to upgrade to the latest supported version of PVE aka PVE9 with every updated installed. Everything else is just...
Well, if that makes any difference (I'm not a troll and have been registered for years):
* I had a few bare metal customers with publicly accessible proxmox 7.2 URLs that were hacked;
* Same message as these other users (ramsomware note)
* No...
Hi,
how can you be sure that there is a "unauthenticated RCE" touching PVE7/8 systems ?
All the systems mentionned was affected by :
https://forum.proxmox.com/threads/proxmox-virtual-environment-security-advisories.149331/post-860952...
I was hit with this same attack the night of the 28th luckily had backups i setup less than 24 hrs prior to happening. Seems they went around just scanning for vulnerable hosts exposed to the public. I had 2 hosts exposed to the public one 7.3-6...
This is highly unlikely. Any Software has bugs and in System stuff like the Kernel every bug is an security issue. Since right now every week ai-assisted Security research discover previously unknown bugs it‘s just not realistic to assume that a...
Could be a coincidence, or related to the fact that we have a sh**tload of occurrences in Brasil because of outdated version and bad sysadmins on small providers, that rely exclusively on next next finish installations and the mindset of using...
I disagree. I think it's more toxic to have EOL systems (like PVE7) on the Internet. It makes the world for all a worse place. I also think it's toxic to register accounts to cry about about an "Proxmox security issue" which quite obviouvsly...
Having read that post (& translating the Chinese!) & all comments, I believe it is a scam. Read it carefully.
I don't think so. I've already stated above:
Systems without current system updates can be hacked, nothing is "new" or "urgent" on this. And PVE7 and PVE8 won't get any security updates any more so it's somehow expected that they get owned. Even if you don't connect them directly to the...