Not sure, but is it maybe just the missing ' ?
That could also be the case. I created the user on pbs, so that is why I am using that. I also just gave it full admin rights and deleted the user afterwards.
What driver are you using to run the Mellanox cards?
For reference this is what I'm using in our production servers for ceph storage and I can't saturate the mesh network that way using the Debian Linux Firmware drivers, granted I can't tinker...
Hi everyone,
I’m currently running Proxmox Virtual Environment (PVE) 7.4-17, and for the past two days I’ve been experiencing an issue with one of my Windows Server 2012 VMs.
The VM sometimes starts successfully and I can briefly access...
Found it. It is a complete compromise of the web interface. No pre-requisites, just a vulnerable proxmox version.
There was a bug patched in pve-access-control (potentially by accident) in 2023.
I will submit it to MITRE so a CVE can be issued...
Sure, but who will put in the time to determine what CVE was used? Then we know for sure which versions are affected. Until then, up to date Proxmox appears to be safe.
Short update, sorry for the long silence and missing communication. It has proven quite difficult to tame AI scrapers, which required us to block expensive operations from public access. Like the scrapers will fire in the thousands of db heavy...
Found it. It is a complete compromise of the web interface. No pre-requisites, just a vulnerable proxmox version.
There was a bug patched in pve-access-control (potentially by accident) in 2023.
I will submit it to MITRE so a CVE can be issued...
Found it. It is a complete compromise of the web interface. No pre-requisites, just a vulnerable proxmox version.
There was a bug patched in pve-access-control (potentially by accident) in 2023.
I will submit it to MITRE so a CVE can be issued...
22/8006
This is 100% an auth bypass on 8006.
Else I don't see why the attackers would just straight up use the "Shell" function of the Web Interface as the first thing they did -- I confirmed this by timestamps, all files I found so far were...
Nothing relevant in all of these.
They have also cleaned the systemd journals.
There's also a service for the miner being installed, using libhide:
# systemctl cat PVE-1
# /etc/systemd/system/PVE-1.service
# Managed-by: install_and_mine.sh...
Hi all,
After the kernel moved from the 7.0.2 base to 7.0.6-2-pve, my Windows VMs
intermittently freeze and only a hard reset recovers them. The 7.0.2 base
(the PVE 9.2 default) has been stable. I am currently pinned back to
7.0.2-7-pve and...
That's a crypto miner. Seems this 0-day is being abused by multiple parties - one ransomware, one to mine crypto.
I have a few LLMs working on the codebase with these facts, hopefully we have some answers in a few hours.