My Box hacked from cryptocurrency miner
-
Not "caused" but "can cause". And it's very unlikely that your pfSense box got hacked and a crypto-miner installed. Instead of reading why your CPU might be high, just look at what's using your CPU. Why spend time guessing what temperature it is outside when you can just step outside?
-
@harvy66
i stopped all service and no client connected , the same error .i using 32 CPUs whith HP server Proliant 930 Gen9 -
Where did you search for it? Did you find any process running on your pfSense box indicating an issue?
-
https://doc.pfsense.org/index.php/High_Load_Troubleshooting
As on that page, use 'top' to identify the process or processes that are responsible for the high load. That will give at least some idea of the next step. Also, a miner would be making weird network connections to its pool, which you could examine in pftop, presumably.
-
@gzorn
You said CPU so you want to look in System Activity. -
@a-atef said in My Box hacked from cryptocurrency miner:

-
Hello, I'm from the Global Support team at Netgate, can you open a ticket at https://go.netgate.com/support/login we would like to take a look at your issue.
-
We looked over the config and there were some design issues that allowed the attacker to gain access and install minerd, we have made some suggestions on a redesign.
This was NOT a flaw in our software, but human error.