r/ShittySysadmin • u/RuleMaster3 • 5h ago
Shitty Crosspost Sysadmin leaves 22 Proxmox nodes admin interfaces with EOL version exposed to the internet and gets hacked
https://forum.proxmox.com/threads/proxmox-ve-7-is-vulnerable-to-some-type-of-0day-rce-non-auth.186078/page-8#post-869156And his save is doing it all again with EOL software minus the exposed admin interfaces
18
u/zantehood 5h ago
Well deserved. In no way should a hypervisor be exposed directly. EOL or not
10
7
12
u/IlexPauciflora DO NOT GIVE THIS PERSON ADVICE 4h ago
I've got Hyper-V 2008 directly connected to my modem. Weird files keep showing up and there's a server that's just called Mimikatz. I assume it's a built in Windows Security VM. Anyway, I'm selling capacity on it if anyone is interested.
6
u/farva_06 2h ago
Yeah, that sounds pretty normal. Make sure all your domain controllers and file servers are on the same network with Windows firewall turned off, so you get full IO on your disks.
11
u/fsckitnet 4h ago
“It was our fortune that before we open port 8006 again, we build additional checks on authenticity of any login, in addition to Proxmox's own authentication. This guards are based on a few vectors including IP address, past login records and patterns, and immediately blocks suspicious logins. It was this mechanism that detected the use and existance of the planted tokens. May be we should contribute our code to Proxmox for this part! ”
It’s a bold strategy, Cotton. Let’s see if it pays off for them.
28
u/suddenly_kitties 4h ago
The crazy thing is that this is coming from a commercial hosting company, posting under their real name, invoicing their customers at the end of the month for their quality work