Server compromised after update to 1.10.3

Hello there,

I’ve been using HestiaCP on multiple servers for many years, and so far, so good.

However, at the moment I’m dealing with a critical situation. One of the servers (luckily, just one!) with a pretty much default installation (MySQL + PHP-FPM, etc.) got compromised. There are over 50 Magento 2 shops hosted there, mostly in dev/test versions. They have all been compromised as well.

You might think: “Yeah, dev sites, shitty developers, outdated Magento” - yes, that’s all true. However, with PHP-FPM running separately for each user, it’s a bit weird that ALL sites were compromised, and looks like not only sites.

Did they all have viruses? Were they all attacked at exactly 6:59 AM? Is it possible? I guess not really.

There is a common point.

I started digging deeper and noticed that every index.php file had been replaced with a WordPress maintenance page. Also, many (but not all, and not everywhere) directories now contain an index.html file with exactly the same content as these “new” index.php files.

And when I say every index.php, I mean EVERY one. Yes, thats right. Including HestiaCP files.

All of them, across all sites and users, had the correct ownership. There were also HestiaCP files owned by root whose contents had been replaced. So I started wondering… what the f*** happened here?

I dug even deeper. Most of the logs had been cleaned up. There were no suspicious scripts running in the background. Nothing really suspicious that I could find.

I’m not accusing anyone or demanding anything. I’m just wondering: am I the only one who has experienced something like this, or has anyone else seen a similar situation?

Everything had been working fine for several years, including before the latest upgrade. But maybe the upgrade isn’t the actual cause - perhaps it’s just a coincidence?

You might ask whether anyone else had root/admin access to the server. No. Just me. And access was via SSH key only.

The auth logs were clean (or cleaned..). According to the logs, nobody had logged in for days.

At this point, I’m completely out of ideas.

Any help would be really appreciated.

Best!

Has a vulnerability been found in your outdated Magento shops?
All the evidences you’re describing point to a malicious exploitation…

Yes. These magentos are outdated, compromised etc, and were compromised since months.

But how someone gained root access? Used some lately found with AI privilege escalation bugs?

Maybe they were there from time ago. Check this thread and investigate if this can be your case:

Thank you for your answer.

I’ve checked that option already - Web-terminal is, and was always disabled.

Perhaps plugins gave root access to the server, also web terminal even disabled could cause the problem, it should be removed.

Do you have any idea how to confirm it? Trace it?

I dont believe its from the terminal, there are a lot of servers, none report something like this, you have to trace magento it self and their plugins.

Maybe magento and then over a privilege explotion, but that’s just guessing - as the server got infiltrated and logs cleared, its probaly impossible to find out now. I would make backups of each user, wipe the server, restore the backups and check for any fishy leftovers (maldet), then proceed with upgrade the magento instances.

Looks like there are maaany requests related to PolyShell: unrestricted file upload in Magento and Adobe Commerce | Sansec

Some are successfull (200) :confused: And later, with webshell maybe someone used some privilege escalations vulnerabilities lately discovered…

This happen very often when you use cms plugin file managers… happened to wordpress on a lot of fms and many versions after a patch after some versions again…Now you have a start, check plugins versioning and you will see when the problem caused. It will be hard to clear all sites… If you have previous backups, after a clean hestiacp installation restore the backups and run updates to everything. This is the best solution i think in your case…

Yes, @Blats. I managed to restore server, Hestia, configs etc from the backups. I have upgraded the system and will try to block anything related to PolyShell on nginx.

And I’d like to thank you all for the responses and support, even if the subject seems to be not really related to Hestia and its upgrade. Thanks again!