What is happening?
A droplet is the name some providers use for a small cloud server. It is like a VPS. If it is compromised, someone else has broken in and controls it.
An outgoing flood is a huge amount of junk traffic sent from your server to another one. A DDoS attack is when many computers send so much traffic that a site cannot cope. Your server may be one of the helpers without you knowing.
Signs of trouble:
- The server is very slow.
- Your provider sends a warning about attacks from your server.
- Network use is very high with no reason.
- You see programs you do not know.
Steps to stop it
- Tell Hostvento support about the problem by opening a ticket at https://secure.hostvento.com/submitticket.php.
- Log in over SSH. If you cannot, ask support whether a rescue method is available.
- Look at what uses the network and the CPU:
top ss -tunptoplists busy programs.ss -tunplists network connections and the program behind each. - Find the strange program and stop it. Replace 1234 with its process number:
kill -9 1234 - Check for unknown users and tasks:
A cron job is a task that runs on a timer. Attackers often hide one there.cat /etc/passwd crontab -l ls -la /etc/cron.d - Change every password at once: root, users, databases and control panels.
- Look at the file
~/.ssh/authorized_keysand remove keys you do not know. - Update all software:
On AlmaLinux or Rocky usesudo apt update && sudo apt upgrade -ydnf update -y. - Close ports you do not need with a firewall, and turn on SSH key login.
The safest cure
Once a server is hacked, you cannot be sure every hidden door is closed. The safest way is a fresh install.
- Copy only your data, such as site files and databases, to a safe place. Scan them first.
- Reinstall the operating system.
- Restore your data.
- Set strong passwords and update everything before you go live.
Tip: Most break-ins start from weak passwords or old software such as an outdated WordPress plugin. Keep both fresh and strong.
Quick recap
- A hacked server can send attack traffic without you knowing.
- Tell support, find the bad program and stop it.
- Change all passwords and remove unknown keys and cron jobs.
- A fresh install is the safest cleanup.
- Keep software updated and passwords strong.