• Debian 11 has reached its end-of-life (vendor EOL date - August 31, 2026). Plesk Obsidian 18.0.81 is the last release to support it.
    If you are running Plesk Obsidian on Debian 11, we recommend you upgrade those servers to Debian 12 using our dist-upgrade tool.
  • We plan to deprecate and remove the support for XML RPC protocol versions earlier than 1.6.9.1 in Plesk Obsidian 18.0.82. We strongly recommend that you update all existing integrations using earlier versions of the XML RPC protocol to comply with the version 1.6.9.1 specification.

The day after the proftp exploit

K

kaboom

Guest
Dear all,

After the proftp exploit about 30 servers were hacked and 3 times our network went down for about 2 hours (+1000M). We had to reinstall 3 servers with 8 rootkits on it and the other 27 servers had all /authback in /tmp with root rights! After the warning email of Parallels our network went down in less then half an hour. All these servers had no secure IP on FTP (eg iptables or firewall) because these are customer servers with changing local Internet IP addresses.

/tmp/Authback installer places a rnd file in /etc and authorized_keys are changed in .ssh

This is the most serious hack for us since 10 years, now everything looks secure again but this joke took a few days of work. Are there any other people with these same problems? Please let me know.

Thanks in advance,
Greetings Kaboom
 
And we put the update out back in october to the atomic and asl-2.0 repos. I'd love to get my hands on any of the malware you collected during your investigation. Maybe we can come up with something to help speed up your recovery here
 
And we put the update out back in october to the atomic and asl-2.0 repos. I'd love to get my hands on any of the malware you collected during your investigation. Maybe we can come up with something to help speed up your recovery here

We have everything under control now, I can send you the "authback" files and all the commands that were executed on the servers if you want?
 
Back
Top