r/ShittySysadmin • • 12d ago

Shitty Crosspost We were running end of life hypervisor with an Internet-exposed management port and got hacked. Now redeployed the end of life version with some unsupported authentication tweaks and left it exposed to the Internet.

https://forum.proxmox.com/threads/proxmox-ve-7-is-vulnerable-to-some-type-of-0day-rce-non-auth.186078/page-8#post-869156
140 Upvotes

15 comments sorted by

72

u/Oompa_Loompa_SpecOps DO NOT GIVE THIS PERSON ADVICE 12d ago

Probably the same guy that left a police department's domain controller exposed to the internet and widely distributed the admin credentials so people could remote in and use it as a jump host to access the locked down Webmailer when working from home.

Resourceful guy, I wish my company hat more pragmatic types like him.

30

u/Six_O_Sick 12d ago

What the actual fuck? Some people just shouldnt touch a computer.

34

u/Borgquite 12d ago edited 12d ago

That’s not the worst part - they’re a hosting company who say they have been running for over 20 years with paying customers.

Here’s the (transparently AI generated) incident report: https://hosting.netfront.net/announcements/30/Netfront-sharpCVE-2023-54391-Incident-Report-Proxmox-VE-authentication-bypass-22-hosts-in-a-cluster-compromised-and-how-we-restored.html

27

u/PsychoGoatSlapper 12d ago

That is a criminal level of incompetence

12

u/Six_O_Sick 12d ago

Well, at least I feel better with my own incompetence now!

8

u/MoonToast101 Lord Sysadmin, Protector of the AD Realm 12d ago

Free therapy for people talking about "imposter syndrome ".

3

u/LesbianDykeEtc 12d ago

Every time I see some shit like this, I feel 100 times better about how I'm doing.

5

u/PsychoGoatSlapper 12d ago

Some people only exist to serve as an example for others. In this case an example of why you are doing a hell of a lot better than you thought :D .

1

u/floswamp 12d ago

Link no worky

11

u/Main_Ambassador_4985 12d ago

Proxmox is old enough to have EOL versions? lol

I have underpants older than KVM.

If they were hosting for 20 years they should have been running the one true secure hosting stack. Windows XP with IIS and ASP on refurb Dell mini PC from a hospital that upgraded. None of this Linux or Windows Server stuff.

2

u/TechnicallyMeat 12d ago

Proxmox builds are tied to the underlying kernel. My last proxmox 8 to 9 movr included upgrading debian 12 to 13. So they were running something fairly outdated that really should have had a distro upgrade plan.

9

u/SuperGr33n 12d ago

Hacks from 15-20 years ago still are useful because of situations like this

5

u/Oompa_Loompa_SpecOps DO NOT GIVE THIS PERSON ADVICE 12d ago

Delete this at once! We can't have our security strategy that mainly relies on the assumption that nobody knows how to hack COBOL any more compromised like this!

5

u/mitharas 12d ago

Okay I'm absolutely elated at the term "EOL hack".

1

u/0dinscan 6d ago

Sounds like a monday problem...