Hello,
I've been noticing a great deal of internet traffic that has been partially due to OVH dedicated servers being compromised. It seems that over a period of a week of sending the information to the abuse department, they have done nothing in regard of removing the infections and securing these boxes. I am not an OVH customer, but I do believe with the pricing and bandwidth being better than anywhere else, I still wonder.. if I was a customer, how do I feel about security not being a top priority?
Here are some details of some compromised servers.. maybe they can be helpful.
91.121.204.61 port: 2001 host: rps2949.ovh.net
rootkit: iroffer-dinoex 3.9
91.121.88.139 port: 3512 host: ns27787.ovh.net
rootkit: kvirc v3.1b
91.121.5.88 port: 3650 host: ns22539.ovh.net
rootkit: kvirc v3.1b
91.121.24.155 port: 3624 host: ns39659.ovh.net
rootkit: kvirc v3.1b
91.121.17.174 port: 2277 host: ns38862.ovh.net
rootkit: kvirc v3.1b
91.121.2.160 port: 53875 host: ns37060.ovh.net
rootkit: iroffer v1.3.b11
91.121.110.99 port: 4561 host: ns354601.ovh.net
rootkit: kvirc v3.1b
91.121.118.159 port: 50292 host: ns201328.ovh.net
rootkit: iroffer v1.3.b11 [20051213023024],
http://iroffer.org/ - Linux 2.6.24.2-xxxx-std-ipv4-32
87.98.132.23 port: 60501 host: 87-98-132-23.ovh.net
rootkit: iroffer v1.3.b11 [20051213023024],
http://iroffer.org/ - Linux 2.6.24.5-grsec-xxxx-grs-ipv4-32
91.121.78.22 port: 3184 host: ks26461.kimsufi.com
rootkit: kvirc v3.1b
(France Based, maybe you can help your buddies)
host: s15326865.domainepardefaut.fr
87.106.146.18 port: 2311
rootkit: kvirc v3.1b
87.106.96.95 port: 1353
host: s15235642.domainepardefaut.fr
rootkit: kvirc v3.1b
This is just a handful, there's more. I'm watching them stay compromised going into week #2. Instead of anybody from OVH telling me anything, don't feel it's necessary. I'll tell the forum when they are secured because I can see them while OVH cannot.