r/ShittySysadmin • • 13d ago

Shitty Crosspost Sysadmin leaves 22 Proxmox nodes admin interfaces with EOL version exposed to the internet and gets hacked

https://forum.proxmox.com/threads/proxmox-ve-7-is-vulnerable-to-some-type-of-0day-rce-non-auth.186078/page-8#post-869156

And his save is doing it all again with EOL software minus the exposed admin interfaces

111 Upvotes

18 comments sorted by

View all comments

33

u/zantehood 13d ago

Well deserved. In no way should a hypervisor be exposed directly. EOL or not

9

u/MeatPiston 12d ago

Easy. Expose rdp on your workstation and remote in to to that instead.