• The BIND DNS server has already been deprecated and removed from Plesk for Windows.
    If a Plesk for Windows server is still using BIND, the upgrade to Plesk Obsidian 18.0.70 will be unavailable until the administrator switches the DNS server to Microsoft DNS. We strongly recommend transitioning to Microsoft DNS within the next 6 weeks, before the Plesk 18.0.70 release.
  • The Horde component is removed from Plesk Installer. We recommend switching to another webmail software supported in Plesk.

The day after the proftp exploit

K

kaboom

Guest
Dear all,

After the proftp exploit about 30 servers were hacked and 3 times our network went down for about 2 hours (+1000M). We had to reinstall 3 servers with 8 rootkits on it and the other 27 servers had all /authback in /tmp with root rights! After the warning email of Parallels our network went down in less then half an hour. All these servers had no secure IP on FTP (eg iptables or firewall) because these are customer servers with changing local Internet IP addresses.

/tmp/Authback installer places a rnd file in /etc and authorized_keys are changed in .ssh

This is the most serious hack for us since 10 years, now everything looks secure again but this joke took a few days of work. Are there any other people with these same problems? Please let me know.

Thanks in advance,
Greetings Kaboom
 
And we put the update out back in october to the atomic and asl-2.0 repos. I'd love to get my hands on any of the malware you collected during your investigation. Maybe we can come up with something to help speed up your recovery here
 
And we put the update out back in october to the atomic and asl-2.0 repos. I'd love to get my hands on any of the malware you collected during your investigation. Maybe we can come up with something to help speed up your recovery here

We have everything under control now, I can send you the "authback" files and all the commands that were executed on the servers if you want?
 
Back
Top