VestaCP, the web management panel recommended by this site, has been exposed to vulnerabilities. Here are the detection and removal methods. All commands are run under SSH: If /etc/cron.hourly/gcc.sh is displayed, it means a Trojan has been planted. 2. If a Trojan is installed, back up all data 3. Block gcc.sh 4. Find the Trojan. It has two versions: one is called update, and the second (update) has a randomly generated name (such as ahzihydns, rangqpbjp). lsof -n |grep /tmp/update Similar to update, stop them from entering the city Then delete them Finally kill them If /etc/init.d/update exists, delete it. b. Deleting random Trojans is more difficult. First check whether there is a process in usr/bin. Processes like this, let's try to stop and delete the process. View the list of files to be deleted: Delete /usr/bin/xmpwotmqnr, /usr/bin/lluoohrpal, and /lib/libudev.so. Check whether there is any malicious code left in /etc/init.d. for example: If there are many such files, you can find them through find and then delete them 5. Use clamav to check Install clamav on Debian/Ubuntu Then, start scanning 6. Finally, it is recommended to use the specified IP for login IP. via: https://itldc.com/blog/vozmozhnaya-uyazvimost-v-vesta-i-sposob-lecheniya-ot-trojan-ddos_xor/ |
<<: LoveServers: $5/month/512MB memory/250GB space/1TB traffic/KVM/UK
>>: Graphic tutorial on installing Baota Linux panel on VPS and independent server
The ranking is in no particular order, and only r...
PakCloudHost seems to be a business that has been...
Attention Required: https://www.namecheap.com/dom...
PQ.hosting, a Russian merchant and a formal compa...
CyclonesServers has been introduced several times...
Hengchuang Technology is an IDC brand operated by...
xeovo, there have been rumors that it is going to...
LetBox is an American hosting company. I have int...
Swiftnode, an American hosting company, was found...
Backblaze was founded in 2007 and focuses on prov...
SecureWebCloud is a foreign business established ...
FlameHosting, an American hosting provider, seems...
FantomNetworks, an American hosting provider loca...
Websound: A UK hosting company, registered as a f...
Weji Host, a Chinese merchant, formerly 50kvm (in...