• If you are still using CentOS 7.9, it's time to convert to Alma 8 with the free centos2alma tool by Plesk or Plesk Migrator. Please let us know your experiences or concerns in this thread:
    CentOS2Alma discussion

The day after the proftp exploit

K

kaboom

Guest
Dear all,

After the proftp exploit about 30 servers were hacked and 3 times our network went down for about 2 hours (+1000M). We had to reinstall 3 servers with 8 rootkits on it and the other 27 servers had all /authback in /tmp with root rights! After the warning email of Parallels our network went down in less then half an hour. All these servers had no secure IP on FTP (eg iptables or firewall) because these are customer servers with changing local Internet IP addresses.

/tmp/Authback installer places a rnd file in /etc and authorized_keys are changed in .ssh

This is the most serious hack for us since 10 years, now everything looks secure again but this joke took a few days of work. Are there any other people with these same problems? Please let me know.

Thanks in advance,
Greetings Kaboom
 
And we put the update out back in october to the atomic and asl-2.0 repos. I'd love to get my hands on any of the malware you collected during your investigation. Maybe we can come up with something to help speed up your recovery here
 
And we put the update out back in october to the atomic and asl-2.0 repos. I'd love to get my hands on any of the malware you collected during your investigation. Maybe we can come up with something to help speed up your recovery here

We have everything under control now, I can send you the "authback" files and all the commands that were executed on the servers if you want?
 
Back
Top