Hello everyone,
I got a server on SyS (OVH) with quite good specifications (32gb ram, octa core, etc, etc)
I installed Proxmox on ZFS mode and setup all my containers, everything was working great.
On securtiy i used proxmox firewall (integrated on GUI) and since in our company we have a static IP, we added SSH and 8006 ports to our IP only. (SSH port was changed aswell)
Last thursday our server attacked some chinese IP (we got hacked and someone used our server to attack the other server).
Here is what i don't get. How did they managed to enter on our server? knowing that ssh/proxmox ports were only open to our IP?
From the syslog i can't find anything related to the attack (under our server) so i have no idea how they managed to enter.
Our ISP also had a problem in their datacenter the same day of the attack so i can only have the log from the 12th october (1pm) the attack happened at 6pm.
the only thing that i can find in syslog at 6pm of that day is
Thank you,
Diogo Jesus
I got a server on SyS (OVH) with quite good specifications (32gb ram, octa core, etc, etc)
I installed Proxmox on ZFS mode and setup all my containers, everything was working great.
On securtiy i used proxmox firewall (integrated on GUI) and since in our company we have a static IP, we added SSH and 8006 ports to our IP only. (SSH port was changed aswell)
Last thursday our server attacked some chinese IP (we got hacked and someone used our server to attack the other server).
Here is what i don't get. How did they managed to enter on our server? knowing that ssh/proxmox ports were only open to our IP?
From the syslog i can't find anything related to the attack (under our server) so i have no idea how they managed to enter.
Our ISP also had a problem in their datacenter the same day of the attack so i can only have the log from the 12th october (1pm) the attack happened at 6pm.
the only thing that i can find in syslog at 6pm of that day is
kernel: nf_conntrack: nf_conntrack: table full, dropping packet
Is there any other way to find older logs? i really need to fix this problem asap.
Thank you,
Diogo Jesus