Proxmox VE 7.1 - cryptojacking rootkit + root SSH backdoor: full teardown
TL;DR
Two PVE 7 hosts were compromised and running an XMRig cryptominer hidden by a preload rootkit. The same "install_and_mine.sh / libhide" toolchain planted:
A...
Found it. It is a complete compromise of the web interface. No pre-requisites, just a vulnerable proxmox version.
There was a bug patched in pve-access-control (potentially by accident) in 2023.
I will submit it to MITRE so a CVE can be issued...
To be honest, I'm sick of this whole discussion. The newly registered users who were actually affected have already admitted that running an outdated system was a mistake. Meanwhile, some of the so-called veteran users on this forum just keep...
You're absolutely right, and I accept the failure on my side.
Just to clarify, this is informational, not a complaint. I'm sharing it so you're aware that this actually happened in our environment and can take it into account.
Thanks to the Proxmox team for reviewing my report. At least they took it seriously, unlike the users on this forum who think that a Debian 11 installation is hacked simply because it's EOL (and no, the OpenSSH bug doesn't affect Debian 11; it's...
problem confirmed: https://forum.proxmox.com/threads/proxmox-virtual-environment-security-advisories.149331/page-4#post-867929
on
dpkg-query -W libpve-a*
libpve-access-control 6.4-3
the server was hacked too
We had the same. Hacked 2 servers pve 6 and 7 this night. Yes we know we have to update. Bit we wunder, because there is no non auth issue out for proxmox
Thanks @fabian and the Proxmox team for these.
These problems have been coming so thick and fast that its getting harder and harder to just keep up with what's happening.
It's at the point now that if you have a server with an uptime of a week...
7.0 and 6.8 already contained the fix, 6.17 with the fix is on pve-test at the moment:
- proxmox-kernel-6.8.12-31-pve
- proxmox-kernel-6.17.13-16-pve
- proxmox-kernel-7.0.6-2-pve