zlacker

[return to "I got hacked: My Hetzner server started mining Monero"]
1. iLoveO+g7[view] [source] 2025-12-17 21:50:08
>>jakels+(OP)
> ls -la /tmp/.XIN-unix/javae

Unless ran as root this could return file not found because of missing permissions, and not just because the file doesn't actually exist, right?

> “I don’t use X” doesn’t mean your dependencies don’t use X

That is beyond obvious, and I don't understand how anyone would feel safe from reading about a CVE on a widely used technology when they run dozens of containers on their server. I have docker containers and as soon as I read the article I went and checked because I have no idea what technology most are built with.

> No more Umami. I’m salty. The CVE was disclosed, they patched it, but I’m not running Next.js-based analytics anymore.

Nonsensical reaction.

◧◩
2. Hackbr+si[view] [source] 2025-12-17 22:55:24
>>iLoveO+g7
> No more Umami. I’m salty.

But kudos for the word play!

[go to top]