Scenario:
- One machine with proxmox
- Second machine with PBS
VMs on proxmox machine are DELETED, all the VM data is wiped.
After that, the proxmox machine is physically compromised.
What to expect: no data leak
Whan actually happens:
- PBS encryption key is available in /etc/pve on the...
in one of our (lazy infrequent) security scans we stumbled upon a running rpcbind. it seems that it was installed around 8.0.4.
trying to remove it tells us that pve depends on it:
The following packages will be REMOVED:
libpve-guest-common-perl* libpve-storage-perl* nfs-common* proxmox-ve*...
The pvecm qdevice setup requires an ssh connection to the QD, which is not there for "casting votes". As QDs are meant to be run externally, why is this not the other (natural) way around, i.e. generating script for one to execute on the QD, possibly provide the feature (as a perk) by calling...
Dear all,
I am trying to build a home server where i want to run few services, such as Nextcloud, as LXC contianers. I am relatively new to networking and before posting here i have read several pieces of documentation. Nevertheless, i still have doubts regarding the best setup for my use case...
Hi,
I noticed that if I set the OUTPUT policy to DROP, I need to add a few rules by default for SSH, migrations to work if I add another ringX address. Could it be that some rules that gets set by default for INPUT may have been forgotten in output ?
I see the usual ports...
Hello everyone,
I followed this guide : https://pve.proxmox.com/wiki/Fail2ban
Then implemented all the attempts @ https://forum.proxmox.com/threads/pve-8-0-%E2%80%93-fail2ban-log-locations-missing.129338/
When I manually trigger the maxretrys nothing happens. When I run the test code provided...
Hello,
i was wondering why only can choose Yubico and OATH/TOTP. I would like to enforce that all users are required to configure webauthn. Am i missing something, or is that option no available? Thank for your help.
Kind regards
schaurian
Hello !
My SOC reported an issue on my newly installed v8 (in place upgrade)
The SOC client (Covalence by Field Effet) was installed yesterday, just before 7to8 upgrade
shellcheck v. 0.9.0-1 is installed on this host. CVE-2021-28794 - 9.8/10
The unofficial ShellCheck extension before 0.13.4...
Hi,
I've purchased a HUNSN mini PC like this one (amazon link) and installed Proxmox VE 7 on it and it seems to run fine so far. After trying to find a way of passing-through a M.2 Wifi/BT card (like this one, amazon link) to a debian VM, and not finding one, I reached out to the seller which...
Hey all!
Perhaps a bit of a beginner question here, especially on the security side. I got a notice for 2 vulnerabilities with open ssh version that is running on ProxMox. It is mentioning that OpenSSH_8.4p1 is vulnerable on CVE-2023-28531 and CVE-2008-3844.
Interestingly I think both of...
Hello guys,
Last weekend I managed to install and setup my first home server with Proxmox. I have used an a old desktop PC, boosted a bit the memory and succsefully installed Proxmox VE. Everything seems to be working just fine and I am enjoying my setup. However, I may need help for few...
A friend starting into using Proxmox asked me a question today which I didn't offhand know the answer to and couldn't find a definitive answer on here.
How do you know the LXC templates are trustworthy?
LXC containers (as in the templates pulled down from pveam), I'm guessing they're pulled...
Building proxmox box which will host 20+ VMs.
Need to ensure that:
1. VMs cannot talk to hypervisor, but VMs can all reach the internet
2. VMs cannot talk to other VMs
3. VMs cannot read or write to other VMs
4. Need to ensure that VMs cannot read or write to hypervisor
Purpose is to avoid...
Has anyone experimented with Falco driver in Proxmox / Linux kernel and using it to secure containers?
Use Case: Running Falco on a Linux host or running Falco userspace program in a container, with a driver installed on the underlying host.
https://falco.org/docs/getting-started/
Hi,
After checking quite a few articles found here and on some other websites, it's still not clear for me how one can add custom IPTables rules for each VM.
Checking the current host with just one VM at the moment I can see:
-A tap100i0-IN -p udp -m udp --sport 67 --dport 68 -j ACCEPT
-A...
I'm migrating from VMWare-ESX to Proxmox. Previously I managed to used Private vlan on vmware and enhanced security for my customers and also used /32 IP address per customer.
now I am not able to find a solution for this case in Proxmox.
cloud anyone guide, what they have done to increase L2...
Abend zusammen,
Wie „sicher“ ist eigentlich PCI-Passthrough?
Ich bin aktuell am überlegen folgende Konstellation zu bauen:
1 Host mit einer zusätzlichen Netzwerkkarte. Die Karte hat 2x 10G.
Die beiden Ports sollen per PCI-Passthrough an eine Virtuelle OPNsense weiter gereicht werden.
Hinter...
Hi,
i got 2 questions to properly secure my data. The setup is one server running PVE an another server running PBS. All on premise. The VMs are stored on thin-provisioned LVMs that are encrypted using LUKS. The key is stored on a hardware token. I am really happy with that. Works great and...
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.