全球主机交流论坛

 找回密码
 注册

QQ登录

只需一步,快速开始

CeraNetworks网络延迟测速工具IP归属甄别会员请立即修改密码
查看: 1690|回复: 17

[美国VPS] Hetnzer账户被黑,上个月被刷了9台服务器,290欧元

[复制链接]
发表于 2023-3-15 12:42:13 | 显示全部楼层 |阅读模式
很久没有登Hetnzer,邮箱突然收到账单290欧,进去看了下,九台服务器在运行,查看上个月登陆ip是45.136.248.X、45.154.98.X、45.140.174.X,请问写工单减免费用有希望吗?
 楼主| 发表于 2023-3-15 20:13:28 | 显示全部楼层
Hetnzer把账单销掉了,不用给了,大家尽量要二次验证
Support - Hetzner Online GmbH
18:49 (1小时前)
发送至 我

Dear Mr Woo

we have removed the invoice and set the balance to € 0.
Please enable 2FA for your account to secure it better.


Kind regards

Customer Data Analytics

Hetzner Online GmbH
Sigmundstrasse 135
90431 Nürnberg
发表于 2023-3-15 12:44:01 | 显示全部楼层
这个估计没戏
发表于 2023-3-15 12:45:12 | 显示全部楼层
HZ的密码设置要很复杂的,这别人怎么黑的?
 楼主| 发表于 2023-3-15 12:47:04 | 显示全部楼层
水牛 发表于 2023-3-15 12:45
HZ的密码设置要很复杂的,这别人怎么黑的?

我也搞不清楚,刚看到官网有个提醒是钓鱼邮箱:
Phishing emails are currently being sent in the name of Hetzner. You can identify the email by the following signs:
- Subject: Hetzner: Ihr Domainname wurde gesperrt. / Ihr Domainname läuft innerhalb von 3 Tagen ab.
- Sender: "'ce04676a@atlasfisio.es" / "d94e7079@vurpillat.org" / "'8bde0c4d@atlasfisio.es" / Customer Service-TravelCenter "customerservice@travelcenter.uk" / Hetzner Online GmbH "04c7bb95@atlasfisio.es"

It tries to get you to go to a fake login site for Hetzner Accounts so that it can steal your login data. Do not open this email or click on any links it contains. If you accidentally went to this phishing site and entered your login data, please contact our support team as soon as possible. Write a support request using your account on konsoleH, Robot or Cloud Console. If that is not possible, call the relevant support team. If you are able to, we also recommend that you immediately change your password and that you delete the phishing mail.

You could also enable 2-Factor-Authentication (2FA) in Accounts which helps to protect your account.
发表于 2023-3-15 12:49:15 | 显示全部楼层
服务器有开通邮件,一个月了,你没发现?
 楼主| 发表于 2023-3-15 12:50:38 | 显示全部楼层
奧巴马 发表于 2023-3-15 12:49
服务器有开通邮件,一个月了,你没发现?

我之前自己新建,有发邮箱,这个都没有
发表于 2023-3-15 12:57:59 来自手机 | 显示全部楼层
wooxiaowei 发表于 2023-3-15 12:50
我之前自己新建,有发邮箱,这个都没有

有可能用api开的?看看有没api?
发表于 2023-3-15 13:01:33 | 显示全部楼层
有点怕啊,二次验证登录会不会安全点,我就是用的authy。
发表于 2023-3-15 13:02:01 | 显示全部楼层
设置了二次验证吗?如果没有的话建议考虑一下密码泄露或者session被盗用。后面那种建议你检查一下其他常用账号。不然还会有其他账单的。别问我怎么知道,都是教训
发表于 2023-3-15 13:50:57 | 显示全部楼层
吓的我直接开二次验证
您需要登录后才可以回帖 登录 | 注册

本版积分规则

Archiver|手机版|小黑屋|全球主机交流论坛

GMT+8, 2024-4-30 01:28 , Processed in 0.063618 second(s), 10 queries , Gzip On, MemCache On.

Powered by Discuz! X3.4

© 2001-2023 Discuz! Team.

快速回复 返回顶部 返回列表