全球主机交流论坛

 找回密码
 注册

QQ登录

只需一步,快速开始

CeraNetworks网络延迟测速工具IP归属甄别会员请立即修改密码
查看: 3467|回复: 8

hostigation给我发邮箱说中了Ebury Trojan?

[复制链接]
发表于 2014-3-21 11:10:17 | 显示全部楼层 |阅读模式
Hostigation received third party information that your VPS may be compromised with the Ebury Trojan. The Ebury trojan steals SSH login credentials from incoming and outgoing SSH connections and forwards them to a dropzone server in specially crafted DNS packets. The trojan is normally found in a binary directory on Unix-based systems in one of the following locations:

/usr/bin/ssh
/usr/bin/sshd
/usr/bin/ssh-add

According to the data we received, your VPS was sending harvested SSH credentials to a dropzone server. They only guaranteed way to remove this trojan is to reinstall your VPS. If your VPS is OpenVZ, we can provide you with a small amount of backup space so you may retrieve critical files once your VPS is reinstalled. Due to the nature of this trojan, any infected KVM VPS will have to be reinstalled completely from scratch.

For more information on Ebury, please see https://www.cert-bund.de/ebury-faq

The information we received about your VPS was provided by US-CERT, we have no additional information as to how you may have been exploited.

Jakob McCann
Hostigation.com
Like us on FB https://www.FB.com/hostigation.hosting
Follow on 推特 @hostigation
发表于 2014-3-21 11:11:15 | 显示全部楼层
https://www.cert-bund.de/ebury-faq
https://www.hkcert.org/my_url/zh/blog/13031201?nid=208144

詳細內容如上
提議是重安裝 VPS。
发表于 2014-3-21 22:33:08 | 显示全部楼层
Hostigation 发表于 2014-3-21 11:11
https://www.cert-bund.de/ebury-faq
https://www.hkcert.org/my_url/zh/blog/13031201?nid=208144

你们母鸡是不是全部中毒了?

我的也是告诉中毒了,今天让我重装了系统
发表于 2014-3-22 01:54:34 | 显示全部楼层
确实,我朋友的几台hostigation都提示中了这个,用的wdcp,在其他公司的vps暂时没发现,不知道不是hostgation某台vps被感染导致其他用户也被感染
发表于 2014-3-23 17:32:07 | 显示全部楼层
sunday 发表于 2014-3-22 01:54
确实,我朋友的几台hostigation都提示中了这个,用的wdcp,在其他公司的vps暂时没发现,不知道不是hostgati ...

需要澄清母雞沒有中毒~如果母雞中毒了大家早要格式化了
发表于 2014-3-23 21:52:45 | 显示全部楼层
我也主动自宫了 还没来得及恢复
发表于 2014-3-24 00:01:13 | 显示全部楼层
Hostigation 发表于 2014-3-23 17:32
需要澄清母雞沒有中毒~如果母雞中毒了大家早要格式化了

嗯嗯,我朋友已经在备份资料和重装系统ing

希望hostigation 大大能提供一些信息,一般这个trojan是如何感染到vps的,
您需要登录后才可以回帖 登录 | 注册

本版积分规则

Archiver|手机版|小黑屋|全球主机交流论坛

GMT+8, 2024-5-8 19:20 , Processed in 0.074220 second(s), 9 queries , Gzip On, MemCache On.

Powered by Discuz! X3.4

© 2001-2023 Discuz! Team.

快速回复 返回顶部 返回列表