Hostdzire新公告

id 2026-09-08 23:38 1

尊敬的客户:


我们特此致函,向您通报近期多位VPS客户报告的一起安全问题,并建议您立即采取预防措施。


近期,有数位客户报告称其VPS实例遭到未经授权的访问。在某些案例中,客户发现系统中未经授权安装了与Xboard相关的节点/软件;还有客户报告称,其VPS上被添加了一个未知且长期存在的root SSH公钥。


在与受影响的客户沟通并审查现有信息后,我们发现这些报告案例中存在以下共同因素:



  • 该 VPS 仍在使用由我们的客户专区面板生成并显示的默认密码。

  • SSH 处于公开可访问状态。

  • 启用了基于密码的 SSH 认证。

  • 未配置 SSH 密钥认证。

  • 未安装 Fail2Ban 等暴力破解防护措施。

  • 该 VPS 曾遭受大量 SSH 暴力破解/登录尝试。


由于我们收到了多起具有相似特征的报告,我们启动了更广泛的调查,以了解这些事件可能如何发生,以及是否涉及任何活跃的漏洞。


VPS 节点与基础设施审查


我们审查了托管受影响 VPS 实例的物理和虚拟化节点。


目前,我们未发现任何迹象表明托管节点本身遭到入侵。


继此前发生的 VMware 安全事件后,我们已将节点的管理接口迁移至私有网络,这意味着无法从公共互联网直接访问这些接口。


尽管已实施了上述隔离措施,我们仍对相关节点进行了额外检查,根据目前的调查结果,这些节点似乎是安全可靠的。


WHMCS 安全审查


我们还对当前的 WHMCS 安装环境进行了安全审查。


目前,我们未发现 WHMCS 安装环境内存在活跃入侵的证据。


不过,WHMCS 近期发布了多个更新,以修复未公开的安全问题,包括以下时间点发布的更新:



  • 2026 年 8 月 25 日

  • 2026 年 9 月 3 日


这些更新发布后,我们已立即进行了部署。


由于 WHMCS 尚未公开披露这些安全修复程序的完整技术细节,我们无法独立确定这些更新所解决的漏洞的确切性质、影响范围或被利用情况。


此外,需要明确的是,安全补丁的发布日期并不一定意味着底层漏洞是在同一天首次被发现的。漏洞可能早已被识别,经过私下调查后才在稍后发布补丁。


我们注意到,部分受影响的 VPS 实例的部署时间与这些 WHMCS 安全更新的发布时间大致相同,包括 2026 年 8 月 25 日左右。


鉴于这一时间上的巧合,我们正在调查二者之间是否存在关联。然而,目前我们无法确认 WHMCS 是导致这些 VPS 遭入侵的原因,也不希望将未经证实的可能性作为已确认的安全事件来呈现。


我们观察到的常见模式


到目前为止,我们审查的报告主要涉及仍在使用控制面板生成的默认密码以及标准基于密码的 SSH 访问的 VPS 实例。


对于已实施更强VPS安全措施的客户,我们未观察到相同的模式,例如:



  • 安装后更改默认密码

  • 使用SSH密钥认证

  • 禁用基于密码的SSH认证

  • 使用Fail2Ban等暴力破解防护措施

  • 实施额外的 SSH 安全加固措施


鉴于多份报告显示出相似特征,我们强烈建议使用我们印度和荷兰基础设施 VPS 服务的客户采取预防措施,即使您尚未察觉任何可疑活动。


建议立即采取的措施


在进行任何更改之前,请备份您需要保留的重要数据。


随后,我们强烈建议您采取以下措施:




  1. 通过客户中心面板重新安装您的 VPS。




  2. 安装完成后立即更改 VPS 密码。


    请勿继续使用控制面板生成的或显示的密码。


    自动生成的初始化密码应始终被视为临时密码。我们强烈建议您在安装完成后立即将其替换为自己设置的强密码和唯一密码。




  3. 更改默认 SSH 端口,并启用暴力破解防护措施,例如 Fail2Ban 或其他合适的安全解决方案。




  4. 尽可能使用 SSH 密钥认证。


    在确认 SSH 密钥认证正常工作后,我们还建议禁用基于明文密码的 SSH 登录。




调查仍在进行中


我们正在继续审查已报告的案例、日志、VPS 配置流程、密码生成流程、WHMCS 环境以及其他可能的攻击途径。


目前情况如下:



  • 目前收到的报告仅涉及我们在印度和荷兰的自有基础设施型VPS服务。

  • 尚未收到关于Leaseweb VPS、专用服务器或其他服务的类似报告。

  • 目前未发现任何迹象表明我们的VPS托管节点遭到入侵。

  • 目前未发现任何证据表明我们的WHMCS系统正在遭受活跃攻击。

  • 我们发现了一种常见模式:部分 VPS 实例仍在使用控制面板生成的原始密码,且其基于密码的 SSH 访问权限被公开暴露。

  • 我们仍在调查近期已修复的第三方漏洞是否可能导致了这些事件。


在调查完全结束之前,我们强烈建议受影响的 VPS 客户将之前生成的任何 VPS 密码视为临时密码,并将其替换为自己设置的新密码。


请尽快完成建议的安全措施。




我们还想澄清这些报告的范围。


目前报告的事件仅涉及在我们位于印度和荷兰的自有基础设施上运行的 VPS 服务。


截至目前,我们尚未收到任何关于以下服务受到类似问题影响的报告:



  • Leaseweb VPS 服务

  • 专用服务器

  • HostDZire 的任何其他服务


到目前为止,相关报告仅限于在我们位于印度和荷兰的自有基础设施上托管的 VPS 实例。


此致,

HostDZire 团队

最新回复 (18)
  • id 楼主 09-08 23:38
    1

    Dear Customer,


    We are writing to inform you about a recent security concern reported by multiple VPS customers and to recommend immediate precautionary steps.


    Several customers recently reported unauthorized access to their VPS instances. In some cases, customers found Xboard-related nodes/software installed without authorization, while others reported that an unknown long-term root SSH public key had been added to their VPS.


    After speaking with affected customers and reviewing the information available to us, we identified several common factors among the reported cases:



    • The VPS was still using the default password generated and displayed by our client-area panel.

    • SSH was publicly accessible.

    • Password-based SSH authentication was enabled.

    • No SSH key authentication was configured.

    • No brute-force protection such as Fail2Ban was installed.

    • The VPS had received a large number of SSH brute-force/login attempts.


    Because we received multiple reports with similar characteristics, we started a broader investigation to understand how these incidents may have occurred and whether any active vulnerability could be involved.


    VPS Node and Infrastructure Review


    We reviewed the physical and virtualization nodes hosting the affected VPS instances.


    At this time, we have found no indication that the hosting nodes themselves were compromised.


    Following our previous VMware incident, we moved the management interfaces of our nodes to a private network, meaning they are not directly accessible from the public internet.


    Even with this isolation in place, we performed additional checks across the relevant nodes and, based on our current findings, they appear to be safe and secure.


    WHMCS Security Review


    We also performed a security review of our current WHMCS installation.


    At this time, we have found no evidence of an active compromise within our WHMCS installation.


    However, WHMCS recently released multiple updates addressing undisclosed security issues, including updates released around:



    • 25 August 2026

    • 3 September 2026


    We applied these updates promptly after they were made available.


    Because WHMCS has not publicly disclosed the full technical details of these security fixes, we cannot independently determine the exact nature, impact, or exploitation status of the vulnerabilities addressed by those updates.


    It is also important to understand that the date a security patch is released does not necessarily mean that the underlying vulnerability was first discovered on that same date. A vulnerability may have been identified earlier, investigated privately, and patched later.


    We noticed that several of the affected VPS instances were provisioned around the same general period as these WHMCS security updates, including around 25 August 2026.


    Because of this timing, we are investigating whether there could be any connection. However, we cannot currently confirm that WHMCS was the cause of these VPS compromises, and we do not want to present an unconfirmed possibility as a confirmed security incident.


    Common Pattern We Have Observed


    So far, the reports we have reviewed have primarily involved VPS instances that were still using the default panel-generated password and standard password-based SSH access.


    We have not observed the same pattern among customers who had already implemented stronger VPS security measures such as:



    • Changing the default password after installation

    • Using SSH key authentication

    • Disabling password-based SSH authentication

    • Using brute-force protection such as Fail2Ban

    • Applying additional SSH hardening


    Because multiple reports show similar characteristics, we strongly recommend that customers using our India and Netherlands infrastructure-based VPS services take preventive action, even if they have not noticed any suspicious activity.


    Immediate Action Recommended


    Before making changes, please take a backup of any important data you need to preserve.


    We then strongly recommend the following:




    1. Reinstall your VPS from the client-area panel.




    2. Change the VPS password immediately after installation.


      Do not continue using the password generated or displayed by the panel.


      Automatically generated provisioning passwords should always be treated as temporary passwords. We strongly recommend replacing them with your own strong and unique password immediately after installation.




    3. Change the default SSH port and enable brute-force protection such as Fail2Ban or another appropriate security solution.




    4. Use SSH key authentication wherever possible.


      After confirming that SSH key authentication is working correctly, we also recommend disabling plain password-based SSH login.




    Our Investigation Is Continuing


    We are continuing to review the reported cases, logs, VPS provisioning process, password-generation process, WHMCS environment, and other possible attack vectors.


    At this stage:



    • The reports are currently limited to our own infrastructure-based VPS services in India and the Netherlands.

    • We have received no similar reports for Leaseweb VPS, dedicated servers, or other services.

    • We have found no indication that our VPS hosting nodes were compromised.

    • We have found no evidence of an active compromise in our current WHMCS installation.

    • We have identified a common pattern involving VPS instances that continued using their original panel-generated password with publicly exposed password-based SSH access.

    • We are still investigating whether any recently patched third-party vulnerability may have contributed to the incidents.


    Until the investigation is fully concluded, we strongly recommend that affected VPS customers treat any previously generated VPS password as temporary and replace it with a new password of their own.


    Please complete the recommended security steps as soon as possible.




    We would like to also clarify the scope of these reports.


    The reported incidents currently apply only to VPS services running on our own infrastructure in India and the Netherlands.


    At this time, we have received no reports of similar issues affecting:



    • Leaseweb VPS services

    • Dedicated servers

    • Any other HostDZire services


    So far, the reports are limited to VPS instances hosted on our own infrastructure in India and the Netherlands.


    Kind regards,

    HostDZire Team

  • id 楼主 09-08 23:40
    2

    省流:不要用面板密码和默认端口,密钥登录换了端口的一般没事

  • webcloud2 09-08 23:45
    3

    一般改端口+设置只允许几个常用ip登录

  • 杏山和纱 09-08 23:47
    4

    又是印度和荷兰

  • id 楼主 09-08 23:50
    5

    @webcloud2 #3 主要还是应该拿到了面板上的密码

  • id 楼主 09-08 23:50
    6

    @杏山和纱 #4 都是自营,托管的和代销的就没事

  • nodeisle 09-08 23:51
    7

    密码我觉得好麻烦, 公钥不舒服吗?

  • id 楼主 09-08 23:52
    8

    @nodeisle #7 三哥说不默认密钥登录就是因为会让更多的人来咨询怎么使用

  • mexun 09-08 23:54
    9

    @nodeisle #7

    是舒服啊,不会用啊。

  • Yandex 09-09 00:06
    10

    密钥舒服的很

  • id 楼主 09-09 00:33
    11

    @Yandex #10 是

  • xpro 09-09 07:31
    12

    总有怎么提示也不换的

  • Na 09-09 07:33
    13

    果然又被黑了 ^-^

  • IwasakiYouko 09-09 07:37
    14

    没有推卸责任,同时也公布了调查进度


    很负责且清晰的公告


    好感+1

  • id 楼主 09-09 12:31
    15

    @xpro #12 是,像大妈直接默认密钥

  • id 楼主 09-09 12:32
    16

    @Na #13 看见别人说 25 号就添加了个密钥

  • id 楼主 09-09 12:32
    17

    @IwasakiYouko #14 不过还没处理上个月被黑后刷流量的事(

  • IwasakiYouko 09-09 12:35
    18

    @id #17 发布于2026/9/9 12:32:54

    @IwasakiYouko #14 不过还没处理上个月被黑后刷流量的事(


    喷了。。

* 帖子来源NodeSeek
返回