10-11-2018, 11:07 AM
(10-11-2018, 07:56 AM)perryoo11 Wrote: vestacp is a magnet to badly configured servers.
I use vestacp and I have not been affected by the latest flaws they had.
I simply changed my ssh port + regular ssh password changes. and root disabled by default.
helps significantly.
It looks as though the latest flaw was about the hackers could log in as the user 'admin' through SSH.
So, just disabling SSH access by root is not good enough.
Should at least disable SSH access by 'admin' in sshd config.