[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

[tor-relays] Re: Tor Node infected with ransomware



Hi,

Thank you for the replies. At the time of writing I was in total panic mode and rotated all my keys. Only after that I saw all these posts from users across different hosters facing the same issue.
It was a good practice to just re-evaluate my OPSEC, though.


I opened a support ticket with my hoster (HostSlick) and got a reply about 12 hours later. I didn't want to re-deploy until they gave confirmation they are clean again.

Luckily, with the awesome relayor playbook I recovered the relay, I just lost the Guard flags, but I think thats fine for now, they'll come back :)


However, I decided to turn my back on that hoster and cancelled my VPS, will be up for a few more months. We already had a few disagreements when the problem with spoofed IP abuse reports arose last year. My relay was suspended (without any notice) at the time for multiple days and it took some time to explain to the hoster that the packets did not came from me.

PS: Thanks Marco, I will look into a centralized solution for collecting logs, just to make any future incidents easier to understand.



Best,

skankhunt42

Attachment: OpenPGP_0x3CC105E07F16F851.asc
Description: OpenPGP public key

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

_______________________________________________
tor-relays mailing list -- tor-relays@xxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to tor-relays-leave@xxxxxxxxxxxxxxxxxxxx