#Panel breached
1 messages · Page 1 of 1 (latest)
They have full machine access
So anything you do should have that in mind
How would they have that? When I logged into Termius the last login date and ip was mine. No one else was in that
Dont need ssh
The exploit gave them full access to the entire machine
It let them run any code
So by doing this update to 1.11.11 won’t fix this issue and what they done/have?
updating doesnt magically revert changes they made. There isnt really a way to know for certain what they did outside of the panel.
Gotcha okay thank you. I reverted and deleted everything I saw that was different and added by them. Do you recommend changing any tokens or keys backend that may help
The exploit is able to get shell thru php lfi => it wont be added into last log
If they had shell id wipe whole os and restore user data from backup