Virtualizor compromised again - very very bad
AnthonySmith
AdministratorProviderOG 




Just read on OGF that virtualizor has been compromised badly, anyone using it needs to look into this asap.
http://virtualizor.com/blog/security-incident-bgp-hijacking/
Something about injected packages after being compromised in another area so if you have pulled any updates or have auto updates it may already be to late.
Saving grace may be that the auto update was about as reliable as an eastern block politician if I remember.
Time to move on from this shit show of a panel in my opinion, huge red flag if you use it now.
TierHive - Hourly VPS - NAT Native - /24 per customer - DE, UK, SG, CA, USA x4, FR x2, AU, PL, NL, JP
FREE tokens on sign up, try before you buy. | Static Hosting Free for life: https://tierhive.com/static-hosting/
Comments
Here we go again. . .
Most people treat AI like gospel. Those people fail.
Treat AI like a drunk intern with occasional good idea, And you will succeeds.
The list includes but is not limited to:
We are sharing our basic bash script that allows you to quickly check and do a basic cleanup of the known files and services.
This will do basic checks and quarantine these while keeping logs for later
wget -qO /root/contain-node.sh 'https://files.xhosts.uk/contain-node.sh' && chmod 700 /root/contain-node.sh && /root/contain-node.sh
So the tl;dr version is virtualizor themselves were compromised and someone managed to push malicious packages via their domain/distribution to hosts hypervisors that either ran updates or had auto update enabled.
Ultimately leading to a backdoor being set up and the attackers gaining full remote root access to hosts hypervisors.
It's likely many hosts that are compromised don't even know yet and ultimately anything running virtualizor should be considered compromised at this point.
If your host runs virtualizor you should probably consider your VPS compromised or at risk.
Honestly at this stage if hosts are not planning to move away from virtualizor by the end of the year I don't really understand what you are doing, there are many options and lots of help available, I am even happy to assist myself if I can if the migration task feels overwhelming.
My understanding from contacts is that the lead developer removed himself from virtualizor a few years ago, and the people left behind have done a terrible job since.
TierHive - Hourly VPS - NAT Native - /24 per customer - DE, UK, SG, CA, USA x4, FR x2, AU, PL, NL, JP
FREE tokens on sign up, try before you buy. | Static Hosting Free for life: https://tierhive.com/static-hosting/
Thanks for sharing that here too.
TierHive - Hourly VPS - NAT Native - /24 per customer - DE, UK, SG, CA, USA x4, FR x2, AU, PL, NL, JP
FREE tokens on sign up, try before you buy. | Static Hosting Free for life: https://tierhive.com/static-hosting/
http://virtualizor.com/blog/security-incident-bgp-hijacking/
TierHive - Hourly VPS - NAT Native - /24 per customer - DE, UK, SG, CA, USA x4, FR x2, AU, PL, NL, JP
FREE tokens on sign up, try before you buy. | Static Hosting Free for life: https://tierhive.com/static-hosting/
I feel like this probably also impacted Softaculous more broadly, so if you run cPanel with it, you might want to start reaching out and checking stuff.
TierHive - Hourly VPS - NAT Native - /24 per customer - DE, UK, SG, CA, USA x4, FR x2, AU, PL, NL, JP
FREE tokens on sign up, try before you buy. | Static Hosting Free for life: https://tierhive.com/static-hosting/
yes it might be possible
KhanWebHost Cheap Shared Hosting | Cheap KVM VPS (DE,UK,US,FR) | KVM Sale - LES Offers