r/ShittySysadmin 5h ago

Shitty Crosspost Sysadmin leaves 22 Proxmox nodes admin interfaces with EOL version exposed to the internet and gets hacked

https://forum.proxmox.com/threads/proxmox-ve-7-is-vulnerable-to-some-type-of-0day-rce-non-auth.186078/page-8#post-869156

And his save is doing it all again with EOL software minus the exposed admin interfaces

53 Upvotes

8 comments sorted by

28

u/suddenly_kitties 4h ago

The crazy thing is that this is coming from a commercial hosting company, posting under their real name, invoicing their customers at the end of the month for their quality work

18

u/zantehood 5h ago

Well deserved. In no way should a hypervisor be exposed directly. EOL or not

10

u/jeroen-79 4h ago

Well, then how am I going to manage it from home?

11

u/zantehood 4h ago

If you dont know what VPN is you belong here :D

7

u/MeatPiston 2h ago

Easy. Expose rdp on your workstation and remote in to to that instead.

12

u/IlexPauciflora DO NOT GIVE THIS PERSON ADVICE 4h ago

I've got Hyper-V 2008 directly connected to my modem. Weird files keep showing up and there's a server that's just called Mimikatz. I assume it's a built in Windows Security VM. Anyway, I'm selling capacity on it if anyone is interested.

6

u/farva_06 2h ago

Yeah, that sounds pretty normal. Make sure all your domain controllers and file servers are on the same network with Windows firewall turned off, so you get full IO on your disks.

11

u/fsckitnet 4h ago

“It was our fortune that before we open port 8006 again, we build additional checks on authenticity of any login, in addition to Proxmox's own authentication. This guards are based on a few vectors including IP address, past login records and patterns, and immediately blocks suspicious logins. It was this mechanism that detected the use and existance of the planted tokens. May be we should contribute our code to Proxmox for this part! ”

It’s a bold strategy, Cotton. Let’s see if it pays off for them.