5 ms·
Well OVH do install backdoors on all the servers, its a surprise how many people dont know about it, here is how to remove it echo "" > /root/.ssh/authorized_k
by dcc1 13y ago
Well OVH do install backdoors on all the servers, its a surprise how many people dont know about it, here is how to remove it
echo "" > /root/.ssh/authorized_keys2
rm -rf /usr/local/rtm
echo "" > /etc/crontab
killall -9 rtm
more here > https://news.ycombinator.com/item?id=4839414 https://news.ycombinator.com/item?id=4839414
- shin_lao 13y agoLink to official documentation: http://help.ovh.co.uk/InstallOvhKey http://help.ovh.co.uk/InstallOvhKey
- lucb1e 13y agoRegardless of whether the backdoor-building of theirs is documented, someone obtained unauthorized access to the machines, be it an employee or not. This means OVH really is compromised, even if they documented the installation of this backdoor.
- nwh 13y agoI'm not entirely sure why they bothered with the root SSH key. If they really wanted they'd just pop open a serial console on the virtual machine wouldn't they?
- _Lemon_ 13y agoThis won't protect against OVH being compromised. In the manager you can select the netboot / PXE option and "boot from rescue mode". From there you get e-mailed the logins from the server booted onto a Debian rescue image. You have full access to the OS / hard drives.
- X-Istence 13y agoPlease don't go blowing away your entire /etc/crontab! In most cases it isn't even necessary. As for their keys, they are locked down to a single IP address, so unless the attackers gained control over that IP the attackers wouldn't be able to access your machine using those keys even if they were compromised.