proxmox
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| proxmox [2024/09/01 11:00] – protocol | proxmox [2026/08/31 23:49] (current) – protocol | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| + | ===== Limpar backdoor ===== | ||
| + | < | ||
| + | |||
| + | # remover backdoor e minerador de cripto (XMrig/ | ||
| + | # encontrei eles nas librarias para mexer nos comandos comuns, classico.. | ||
| + | unset LD_PRELOAD | ||
| + | export LD_PRELOAD="" | ||
| + | |||
| + | chattr -ia / | ||
| + | echo "" | ||
| + | rm -f / | ||
| + | |||
| + | # matar os processos de mineraçao e persistencia | ||
| + | pkill -9 -f PVE-1 | ||
| + | pkill -f PVE-1-maintain | ||
| + | pkill -f PVE-1-update | ||
| + | pkill -f ld-svc | ||
| + | |||
| + | # boa tentativa deles, mais classico tambem.. | ||
| + | chattr -ia / | ||
| + | chattr -ia / | ||
| + | chattr -ia / | ||
| + | chattr -ia / | ||
| + | chattr -ia / | ||
| + | chattr -ia / | ||
| + | chattr -ia / | ||
| + | chattr -ia / | ||
| + | |||
| + | systemctl stop PVE-1-update.timer 2>/ | ||
| + | systemctl disable PVE-1-update.timer 2>/ | ||
| + | systemctl stop ld-svc.timer 2>/ | ||
| + | systemctl disable ld-svc.timer 2>/ | ||
| + | |||
| + | chattr -ia / | ||
| + | rm -f / | ||
| + | |||
| + | chattr -ia / | ||
| + | rm -f / | ||
| + | rm -f / | ||
| + | rm -f / | ||
| + | rm -f / | ||
| + | rm -f / | ||
| + | rm -rf / | ||
| + | rm -rf / | ||
| + | rm -f / | ||
| + | rm / | ||
| + | rm -f / | ||
| + | rm -f / | ||
| + | rm -f / | ||
| + | rm -f / | ||
| + | |||
| + | systemctl daemon-reload | ||
| + | systemctl reset-failed | ||
| + | |||
| + | |||
| + | # listar as VM e disk ID | ||
| + | cat / | ||
| + | |||
| + | # extrair as VM (preferencia em disco externo ou remoto) | ||
| + | dd if=/ | ||
| + | |||
| + | Usar testdisk para restaurar, nao esqueçe selecionar MBR or GPT, se for XFS use kpartx ou forçando offset em loop device.. | ||
| + | |||
| + | uma chave ssh deles em / | ||
| + | ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQCltvjARi/ | ||
| + | CVt0aNVoUYc71EQhNA4Q1XbqrzCwzjB/ | ||
| + | Eezua0I2YLm9KizbgE11FxEB+9NQW3fkdRuYtZZGMzd2DHB+V5jwfCxPKl0SpyWmQNL+cpn9Lpt0EP/ | ||
| + | IP deles: | ||
| + | 103.117.145.130 C&C | ||
| + | 45.185.15.129 C&C | ||
| + | 45.148.10.152 C&C | ||
| + | 62.60.130.193 (entry proxy, most probably some botnet zombie) | ||
| + | 205.172.58.170 (monero) | ||
| + | |||
| + | grep -a -b -o " | ||
| + | dd if=/ | ||
| + | dd if=server2-mkauth.raw of=staged_padded.maz bs=1 skip=62236491651 count=150000000 status=progress | ||
| + | |||
| + | # Extrai as linhas financeiras brutas do arquivo de imagem do disco | ||
| + | strings server2-mkauth.raw | grep -E " | ||
| + | grep " | ||
| + | |||
| + | # Extrai as linhas financeiras brutas do arquivo de imagem do disco | ||
| + | strings server2-mkauth.raw | grep -E " | ||
| + | grep " | ||
| + | |||
| + | strings server2-mkauth.raw | grep -E " | ||
| + | grep " | ||
| + | |||
| + | strings server2-mkauth.raw | grep -E " | ||
| + | grep " | ||
| + | |||
| + | strings server2-mkauth.raw | grep -E " | ||
| + | grep " | ||
| + | |||
| + | strings server2-mkauth.raw | grep -E " | ||
| + | grep " | ||
| + | |||
| + | strings server2-mkauth.raw | grep -E " | ||
| + | grep " | ||
| + | |||
| + | mysql -u root -p mkradius < / | ||
| + | mysql -u root -p mkradius < / | ||
| + | mysql -u root -p mkradius < / | ||
| + | mysql -u root -p mkradius < / | ||
| + | mysql -u root -p mkradius < / | ||
| + | mysql -u root -p mkradius < / | ||
| + | mysql -u root -p mkradius < / | ||
| + | |||
| + | |||
| + | </ | ||
| + | |||
| + | |||
| ===== mount proxmox virtual disk ===== | ===== mount proxmox virtual disk ===== | ||
| <code C [enable_keyword_links=" | <code C [enable_keyword_links=" | ||
| mount -t vfat -o loop, | mount -t vfat -o loop, | ||
| + | </ | ||
| + | |||
| + | ===== Add user from CLI ===== | ||
| + | < | ||
| + | |||
| + | pveum useradd manuel@pam | ||
| + | |||
| + | |||
| + | pveum acl modify / --roles PVEAdmin --users manuel@pam | ||
| + | |||
| </ | </ | ||
| Line 26: | Line 149: | ||
| - | === repositories === | + | ===== repositories |
| old <8 | old <8 | ||
| Line 48: | Line 171: | ||
| </ | </ | ||
| - | === remove nag screen === | + | ===== remove nag screen ===== |
| < | < | ||
| sed -Ezi.bak " | sed -Ezi.bak " | ||
| </ | </ | ||
| + | |||
| ===== links to sort ===== | ===== links to sort ===== | ||
| + | Deactivate the volume group: | ||
| + | |||
| + | # vgchange -a n my_volume_group | ||
| + | | ||
| + | |||
| + | Now you actually remove the volume group: | ||
| + | |||
| + | # vgremove my_volume_group | ||
| + | | ||
| + | |||
| + | https:// | ||
| https:// | https:// | ||
proxmox.1725199215.txt.gz · Last modified: by protocol
