So, you are:
Running a OS that is EOL since two years
Exposing it to the internet
Disabling the firewall
If this is not a troll, I hope the lesson was learned...
To be honest, I'm sick of this whole discussion. The newly registered users who were actually affected have already admitted that running an outdated system was a mistake. Meanwhile, some of the so-called veteran users on this forum just keep...
Well, if that makes any difference (I'm not a troll and have been registered for years):
* I had a few bare metal customers with publicly accessible proxmox 7.2 URLs that were hacked;
* Same message as these other users (ramsomware note)
* No...
That someone is the person who have set up the environment.
Everyone manages their own environment as they see fit. The problem is that sometimes that person has no idea of what they are doing. Every once in a while a new vulnerability comes up...
The usual use of the zero-day term is for vulnerabilities that are being exploited while there is no fix yet (for a supported/current version). That is something the administrator cannot do much about. This vulnerability is probably already fixed...
Well, if that makes any difference (I'm not a troll and have been registered for years):
* I had a few bare metal customers with publicly accessible proxmox 7.2 URLs that were hacked;
* Same message as these other users (ramsomware note)
* No...
Hi,
how can you be sure that there is a "unauthenticated RCE" touching PVE7/8 systems ?
All the systems mentionned was affected by :
https://forum.proxmox.com/threads/proxmox-virtual-environment-security-advisories.149331/post-860952...
This is both irresponsible and to be expected. Someone should warn then against doing this.
This is helpful (for people running outdated versions).
There have been several SSH vulnerabilities in the (internet) news. People should know better or...
I was hit with this same attack the night of the 28th luckily had backups i setup less than 24 hrs prior to happening. Seems they went around just scanning for vulnerable hosts exposed to the public. I had 2 hosts exposed to the public one 7.3-6...
Indeed it is, no issues until now, no weird things happening. Unfortunately, I couldn't get my hands on any infected environment to better understand what was the situation, what could be the failure points, etc. (all the environments I manage...
As with the flooding of the log.. Is there a way to make the system pause the error pumping ? Like if we get back after a week.. it will be uber clog for no reason..
Or maybe a service stop after x min of detection of an error ..?
Well, if that makes any difference (I'm not a troll and have been registered for years):
* I had a few bare metal customers with publicly accessible proxmox 7.2 URLs that were hacked;
* Same message as these other users (ramsomware note)
* No...
To me, it doesn't even make sense we are commenting about Virtualizor and Hetzner on this thread, since the issue is that we may or may not have a security issue within old versions of Proxmox itself, and it isn't even slightly clear yet. Can we...
Hi,
how can you be sure that there is a "unauthenticated RCE" touching PVE7/8 systems ?
All the systems mentionned was affected by :
https://forum.proxmox.com/threads/proxmox-virtual-environment-security-advisories.149331/post-860952...
Der Lizenz-Punkt von @Johannes S ist eigentlich der spannendere, das Codestyle-Argument erledigt sich ja mit genug Nachdruck im Review. Beim DCO unterschreibst du nicht nur "ich steh dafür grade", sondern auch dass du das Recht hast, den Code...