Vulnerability in SolusVM Debian 10 template - "debianuser" backdoor/default user

@redgreenblue said:
Anyone with VM with Hosthatch running with Debian image provided by Hosthatch should check their VM now. Good probability is that your VM may have been compromised via user debianuser, which is now running cnrig, which appears to be related to CryptoNight. Hosthatch VMs in multiple locations has been observed to have been compromised this way.

From the provider via email:

We have detected a security vulnerability in our Debian 10 template and our records indicate that you have installed a VM with this template. If you have since then reinstalled your VM to any template other than Debian 10, or used an ISO to reinstall your VM, you can ignore this email.

How could this happen?
We use SolusVM as our backend virtualization platform, it is a leading provider operated by Plesk. We are using their official templates. Unfortunately this particular template had an issue which resulted in this security vulnerability. They are aware of the situation.

How was it fixed?
We have patched the template with help from SolusVM and they also helped us to confirm that no other templates are affected.

I also found this Chinese blog post from October 2020, where someone's GreenCloudVPS VPS was compromised through what I assume is the same debianuser account, also running some other crypto thing (xmrig): https://aoyouer.com/posts/server-hacked-record.html, so this has been in the wild for at least four months (probably longer), and likely affects many other providers too

Please check your servers for a debianuser user. If so, you're probably best off wiping the whole thing and restoring from backups.

You should be fine if password authentication is disabled, as in that case you can only access SSH if you have the private key. I'd still recommend deleting the debianuser user if it's present on your system.

If you still use password authentication for SSH, I'd strongly recommend:

  1. Generate an SSH key. You may already have one if you use a service like GitHub that uses SSH keys for authentication. If you don't have one already, an Ed25519 key is good. https://medium.com/risan/upgrade-your-ssh-key-to-ed25519-c6e8d60d3c54
  2. Ensure the key is in ~/.ssh/authorized_keys
  3. Disable PasswordAuthentication in /etc/ssh/sshd_config and restart SSH (service ssh restart)
  4. Double-check that you can still get in (open a new session and test it out) before you exit your active SSH session

SolusVM Debian 10 テンプレートに脆弱性 - "debianuser" バックドア/デフォルトユーザ

@redgreenblue さんが言っていました。
Hosthatch が提供する Debian イメージを使って Hosthatch を実行している VM をお持ちの方は、今すぐ VM をチェックしてください。十分な確率で、あなたの VM は debianuser というユーザを経由して危険にさらされている可能性があります。複数の場所にある Hosthatch の VM がこの方法で侵害されていることが確認されています。

プロバイダからメールで

私たちは Debian 10 のテンプレートにセキュリティ上の脆弱性を検出しましたが、私たちの記録によると、このテンプレートを使用して VM をインストールしたことが判明しています。その後、Debian 10 以外のテンプレートに VM を再インストールしたり、ISO を使って VM を再インストールしたりした場合は、このメールを無視して構いません。

どうしてこのようなことが起こるのでしょうか?
私たちはバックエンド仮想化プラットフォームとして SolusVM を使用していますが、これは Plesk が運営する大手プロバイダです。その公式テンプレートを使用しています。残念ながら、この特定のテンプレートに問題があり、このセキュリティ脆弱性が発生しました。彼らは状況を把握しています。

どのように修正されましたか?
SolusVMの協力を得てテンプレートをパッチし、他のテンプレートが影響を受けていないことを確認するためにも協力してくれました。

私はまた、2020年10月からのこの中国のブログ記事を見つけました。ここでは誰かのGreenCloudVPS VPSが、私が同じdebianuserアカウントであると推測しているものを介して侵害され、他の暗号化されたもの(xmrig)も実行していました: https://aoyouer.com/posts/server-hacked-record.html したがって、これは少なくとも4ヶ月間(おそらくそれ以上)野生の状態にあり、おそらく他の多くのプロバイダにも影響を与えているでしょう。

debianuser ユーザがいるかどうか、サーバをチェックしてください。もしそうであれば、全体を消去してバックアップから復元するのが一番いいでしょう。

パスワード認証が無効になっている場合は、秘密鍵を持っていないと SSH にアクセスできないので、大丈夫でしょう。システム上に debianuser ユーザが存在する場合は、削除することをお勧めします。

もしまだ SSH にパスワード認証を使っているのであれば、強くお勧めします。

  1. SSH 鍵を生成する。認証に SSH 鍵を使う GitHub のようなサービスを使っていれば、すでに鍵を持っているかもしれません。もしまだ持っていないのであれば、Ed25519 鍵が良いでしょう。 https://medium.com/risan/upgrade-your-ssh-key-to-ed25519-c6e8d60d3c54
  2. 鍵が ~/.ssh/authorized_keys にあることを確認します。
  3. etc/ssh/sshd_config で PasswordAuthentication を無効にして SSH を再起動する (service ssh restart)
  4. アクティブな SSH セッションを終了する前に、まだログインできることをダブルチェックしてください (新しいセッションを開いてテストしてください)。

[RackNerd] NEW YEAR Shared Hosting 60GB $9.38/y

Shared Hosting Specials, now with MailChannels!

RackNerd’s shared hosting platform is now leveraging MailChannels to improve email delivery rates to specific email services if and as needed. This feature is implemented at no additional charge.

Shared - 60 GB - $9.38 per YEAR!
Perfect for entry-level websites.
60 GB SSD Disk Space
3 TB Monthly Transfer (FREE Double the bandwidth, just comment your order#)
Unlimited Databases
Host 3 Domains
Free SSL Certificates
cPanel Control Panel
Softaculous Script Installer
CloudLinux Powered
LiteSpeed Web Server
Free Offsite Daily Backups (JetBackup)
NEW! MailChannels Hybrid - Premium Email Delivery
Only $9.38 per year!
ORDER NOW: https://my.racknerd.com/cart.php?a=add&pid=432

今借りてるとこの契約期間が切れたら乗り換えようか。

[VirMach] Ryzen NVMe1G $38/2yr

NVMe1G
1GB DDR4 RAM – 2400MHz-2666MHz (Dedicated)
25GB NVMe – RAID1/RAID10, 6GB-14GB/s (Dedicated, Shared IO*)
1 vCore CPU – Ryzen 3.5GHz (Fair Use**)
2500GB Bandwidth – 1Gbps Port (Shared)
1x IPv4 Address – IPv6 Available
$27 annually | $38 biennially (Every 2 Years) – Additional 10% off first term, use code NVMe1G

NVMe2G
2GB DDR4 RAM – 2400MHz-2666MHz (Dedicated)
50GB NVMe – RAID1/RAID10, 6GB-14GB/s (Dedicated, Shared IO*)
2 vCore CPU – Ryzen 3.5GHz (Fair Use**)
5000GB Bandwidth – 1Gbps Port (Shared)
1x IPv4 Address – IPv6 Available
$48 annually | $72 biennially (Every 2 Years) – Additional 20% off first term, use code NVMe2G
https://virmach.com/special-offers/

[MyW] 2021 LIFETIME OFFERS 25GB €40

MyW Shared and Reseller Hosting in LA and DE, Lifetimes!!!
Tech specifications: RAID 5 SSD, DirectAdmin, MailChannels, CloudLinux, BitNinja.
2GB Shared Account, in LA or DE, for 9.99€ LIFETIME, order now at https://myw.pt/manager/cart.php?a=add&pid=10

Reseller Plan 25 GB Lifetime - LET25GB
For 40€(5061円), plus VAT if applicable, order now: https://myw.pt/manager/cart.php?a=add&pid=297

いつもの2GBと50GB,100GB。今回は25GBが追加。あと、新たにBitNinjaが搭載された気がする。

[RackNerd] FLASH SALE LIMITED QTY

CyberMonday

FLASH DEAL - 2GB RAM KVM VPS in Los Angeles DC-02

Just like the last flash sale, this is also provisioned within our highly desirable Los Angeles DC-02 location. In this location we are leveraging Multacom's network blend - providing an Asia & Australia Optimized Network. Also, up to 100 IPv6 addresses can be allocated to any Los Angeles DC-02 VPS, at no additional charge just by opening a support ticket to request it!

First come, first serve. If you do not complete payment for your order within 5 minutes after your order, we will cancel it out so that others have a chance to order it, due to limited quantity.

FLASH DEAL - 2GB RAM KVM VPS in Los Angeles DC-02

2x vCPU Cores
30 GB SSD Cached RAID-10 Storage
2 GB RAM
3000GB Monthly Premium Bandwidth (FREE Double the bandwidth, just comment your order#)
1Gbps Public Network Port
Full Root Admin Access
1 Dedicated IPv4 Address
Up to 100x IPv6 Addresses upon request
KVM / SolusVM Control Panel - Reboot, Reinstall, Manage rDNS, & much more
LOCATION: Los Angeles DC-02 (Looking Glass: http://lg-lax02.racknerd.com/ -- Optimized Routes to Asia, Oceania, Australia, New Zealand, and more!)
Limited Quantity: 40
FLASH SALE PRICING: $12/Year (recurring price, price will not increase upon renewal if you happen to be lucky enough to snatch one of these!)

Order Link: https://my.racknerd.com/cart.php?a=add&pid=397 - NO PROMO CODE NEEDED! Go straight to check out.

FLASH DEAL - 2.2 GB KVM VPS Ashburn

FLASH DEAL - 2.2 GB KVM VPS Ashburn
2x vCPU Cores
35 GB Pure SSD RAID-10 Storage
2.2 GB (2304MB) RAM
3000GB Monthly Premium Bandwidth (FREE Double the bandwidth, just comment your order#)
1Gbps Public Network Port
Full Root Admin Access
1 Dedicated IPv4 Address
KVM / SolusVM Control Panel - Reboot, Reinstall, Manage rDNS, & much more
LOCATION: Ashburn
Limited Quantity: 35
FLASH SALE PRICING: $12.89/Year (recurring price, price will not increase upon renewal if you happen to be lucky enough to snatch one of these!)

Order Link: https://my.racknerd.com/cart.php?a=add&pid=398 - NO PROMO CODE NEEDED! Go straight to check out.

NewYear

FLASH SALE - 2 GB KVM VPS (San Jose, LA, or Amsterdam)

FLASH SALE - 2 GB KVM VPS (San Jose, LA, or Amsterdam)
2x vCPU Cores
30 GB Pure SSD RAID-10 Storage (SSD Cached in LA)
2 GB RAM
5000GB Monthly Premium Bandwidth
1Gbps Public Network Port
Full Root Admin Access
1 Dedicated IPv4 Address
KVM / SolusVM Control Panel - Reboot, Reinstall, Manage rDNS, & much more
LOCATION: San Jose, Los Angeles DC-02, or Amsterdam
Limited Quantity: 40
FLASH SALE PRICING: $13.21/Year (recurring price, price will not increase upon renewal if you happen to be lucky enough to snatch one of these!)

Order Link: https://my.racknerd.com/cart.php?a=add&pid=443 - NO PROMO CODE NEEDED! Go straight to check out.

FLASH SALE - 4 GB KVM VPS (San Jose, LA, or Amsterdam)

FLASH SALE - 4 GB KVM VPS (San Jose, LA, or Amsterdam)
3x vCPU Cores
50 GB Pure SSD RAID-10 Storage (SSD Cached in LA)
4 GB RAM
4000GB Monthly Premium Bandwidth
1Gbps Public Network Port
Full Root Admin Access
1 Dedicated IPv4 Address
KVM / SolusVM Control Panel - Reboot, Reinstall, Manage rDNS, & much more
LOCATION: San Jose, Los Angeles DC-02, or Amsterdam
Limited Quantity: 40
FLASH SALE PRICING: $18.88/Year (recurring price, price will not increase upon renewal if you happen to be lucky enough to snatch one of these!)

Order Link: https://my.racknerd.com/cart.php?a=add&pid=444 - NO PROMO CODE NEEDED! Go straight to check out.

1/5日まで [OVHcloud] Up to 30% off

Deals at a glance:
Special Edition servers by OVHcloud: Europe & North America hosted - Up to 30% off
Essential & Game servers by SoYouStart: Europe & North America hosted - 30% off

Explore all offers

Asia (US$): https://www.ovh.com/asia/deals/
Australia (A$): https://www.ovh.com.au/deals/
Singapore (S$): https://www.ovh.com/sg/deals/
Rest of the world (US$): https://www.ovh.com/world/deals/
or to be redirected to your local OVH website, visit https://www.ovh.com/deals/

GAME-1
Holidays sale - 30 %
Intel i7-4790K 4c / 8t 4GHz
16GB DDR3 1333MHz
1x120 GB SSD
Available datacentres: 2
$28.99/m
Order

12/26 [VisualWebTechnologies] Black Friday Special Sale 2020

https://billing.visualwebtechnologies.com/store/black-friday-special-sale
VISUALWEBTECHNOLOGIES BF- Shared-LEB-35GB
35GB Pure SSD Disk Space
1TB Monthly Transfer
Unlimited Databases
Host up to: 5 Domains
Free SSL Certificates
Free Migrations
Softaculous Script Installer
Apache Web Server
No CloudLinux
cPanel Control Panel
JUST $12.99/YEAR
Order Here
https://billing.visualwebtechnologies.com/cart.php?a=add&pid=398

BF DirectAdmin3 Available
20 GB NVMe-based Storage
Unlimited Bandwidth
Unlimited MySQL Databases
8 Addon Domains
Unlimited Subdomains
Unlimited Email Accounts
99.9% Uptime
DIrectadmin +Cloudlinux + Litespeed
Softaculous, SSL, etc.
No Coupon Code Required
$14.99/YEAR
https://billing.visualwebtechnologies.com/cart.php?a=add&pid=400

[naranja.tech] Xmas offer

All orders include:
IPv4 + IPv6
SSD RAID 10
KVM Virtualization
Located in The Netherlands
RECURRING OFFERS
Coupon code: ZY0A7Y8NMJ

1 vCore - 1GB Ram - 20GB SSD Disk - 1TB BW - 9 €/year (+vat if applicable) - Order Now

1 vCore - 2GB Ram - 40GB SSD Disk - 2TB BW - 18 €/year (+vat if applicable) - Order Now

2 vCores - 4GB Ram - 80GB SSD Disk - 4TB BW - 36 €/year (+vat if applicable) - Order Now
https://clients.naranja.tech/cart.php?gid=1

[Hostigger] VMware ESXI

TR-VPS-P1
1 Core CPU
2 GB RAM
20 GB SSD
2 TB Bandwidth
1 Gbit/s Port (Shared)
$35,88/yr $12,56/yearly [65% Discount] - Order Now
https://clients.hostigger.com/index.php?cmd=module&module=77&cid=513

TR-VPS-P2
1 Core CPU
3 GB RAM
30 GB SSD
2 TB Bandwidth
1 Gbit/s Port (Shared)
$47,88/yr $16,76/yearly [65% Discount] - Order Now
https://clients.hostigger.com/index.php?cmd=module&module=77&cid=514

12/24 [WebHorizon] Happy Holidays - New Year 2021 | KVM VPS Singapore | NAT VPS Bundle

VPS - KVM1G SG
1GB DDR4 ECC RAM
7GB NVMe SSD RAID 1 disk
1vCore Coffee Lake @3.7+Ghz
1 x IPv4
125GB High-speed Bandwidth per month, then unlimited at reduced speeds.
£15/YEAR Recurring - Order Now
https://my.webhorizon.in/order/config/index/BF/?group_id=21&pricing_id=307

VPS - KVM2G SG
2GB DDR4 ECC RAM
14GB NVMe SSD RAID 1 disk
1vCore Coffee Lake @3.7+Ghz
1 x IPv4
250GB High-speed Bandwidth per month, then unlimited at reduced speeds.
£24.8/YEAR Recurring - Order Now
https://my.webhorizon.in/order/config/index/BF/?group_id=21&pricing_id=308

6 x 128MB NAT VPS Bundle
Includes 1 VPS each in 6 Locations around the world. - Japan, Singapore, Netherlands, Switzerland, New York & Los Angeles.
Each VPS gets:-
128MB ECC RAM
1GB RAID 1/10 disk
1vCore @3+ Ghz
1 x NAT IPv4 + /112 IPv6
0.25TB High-speed Bandwidth per month, then unlimited at reduced speed.
£10/YEAR Recurring - Order Now
https://my.webhorizon.in/order/config/index/BF/?group_id=21&pricing_id=330
.
- Japan includes 70GB High-speed Bandwidth per month, then unlimited at reduced speed.