outroll / vesta

VESTA Control Panel
http://vestacp.com
GNU General Public License v3.0
2.94k stars 1.03k forks source link

CRITICAL - Vesta is no longer supported - Suggested easy migration #2254

Closed industrial64 closed 2 years ago

industrial64 commented 2 years ago

To any users of VestaCP. It is with sadness that I state a no well-known fact: Vesta is no longer receiving security support, and several massive vulnerabilities have been exposed and well documented.

HestiaCP is a properly-supported evolution of VestaCP. Migrating from Vesta to Hestia is super easy, just backup your user, and restore your user on HestiaCP. (One important change from Vesta is that the Admin user should not be user/package that has domains/DB's/mail/etc.

Feel free to conduct your own investigation, and see why moving away from VestaCP is now CRITICAL.

HestiaCP is a shoe-fit for most because of the simplistic migration: 1) VestaCP: v-backup-users 2) SCP the .tar files to your new HestiaCP server 3) HestiaCP: v-restore-user $USER $BACKUPFILE.tar

ninjao commented 2 years ago

Is it best to install on a fresh system and restore thr backup?

Or ok to install on current system? (Hestia i mean(

industrial64 commented 2 years ago

Fresh install STRONGLY and urgently recommended :) Did a few Vesta>Hestia migrations, always do things clean. Leave behind outstanding vulnerabilities and anything which security holes left exposed for prolonged time on the open net. There could always be an attack laying in wait on an old Vesta system.

jaapmarcus commented 2 years ago

Is it best to install on a fresh system and restore thr backup?

Or ok to install on current system? (Hestia i mean(

Update from VestaCP to Hesita without reinstalling OS is not supported.

If you have Debain 9 installed you can consider switching to MyVesta as they still support updating.

Also Debian Strech is EOL end of next month

Devoleksiy commented 2 years ago

@industrial64 Why are you making such a big statement here, are you a development participant? @serghey-rodin Can you confirm this statement?

jaapmarcus commented 2 years ago

Last commit was 6 months ago...

New security vulnerabilities: https://github.com/serghey-rodin/vesta/issues/2246 https://github.com/serghey-rodin/vesta/issues/2252

Forum is dead: https://forum.vestacp.com

It is up to you what you want to decide but I would move on...

macedd commented 2 years ago

Sorry, I have my doubts too. This project clearly has a maintenance issue, but it is well known. Now how is the new project different? Who are the maintainers and why they didn’t help here? Can you link some discussion around the project creation?

On Sat, 2 Jul 2022 at 03:59 Jaap Marcus @.***> wrote:

Last commit was 6 months ago...

New security vulnerabilities:

2246 https://github.com/serghey-rodin/vesta/issues/2246

2252 https://github.com/serghey-rodin/vesta/issues/2252

Forum is dead: https://forum.vestacp.com

It is up to you what you want to decide but I would move on...

— Reply to this email directly, view it on GitHub https://github.com/serghey-rodin/vesta/issues/2254#issuecomment-1172864461, or unsubscribe https://github.com/notifications/unsubscribe-auth/AABTSANEGC66PDHE3DBZWOLVSAAHZANCNFSM5ZVAWHXQ . You are receiving this because you are subscribed to this thread.Message ID: @.***>

-- Thiago Macedo Software +55 34 99176-4055 | @.***

https://internetbudi.com.br/

jaapmarcus commented 2 years ago

Hestia started after a group of developers have felt being ignored and a lot of good pull request where not merged with VestaCP. That why they have started HestiaCP.

What is different between VestaCP and HestiaCP

See also

https://github.com/serghey-rodin/vesta/issues/2006

ScIT-Raphael commented 2 years ago

Who are the maintainers and why they didn’t help here?

Because we can't. The only one who can publish new builds to the vesta repository is @serghey-rodin. We could have send PRs to the fix the issues, @jaapmarcus also did, for myself, I gave that up.

But I think the issue #2006 describes the situation properly.

jaapmarcus commented 2 years ago

Also: https://huntr.dev/repos/hestiacp/hestiacp vs https://huntr.dev/repos/serghey-rodin/vesta/