Results 1 to 6 of 6

Thread: Getting screwed over, need urgent help.

  1. #1
    Member
    Join Date
    May 2012
    Posts
    33
    cPanel/WHM Access Level

    Root Administrator

    Default Getting screwed over, need urgent help.

    Hi,
    Since about a week we have been getting LOT of complaints from our datacenter about a few of our webs holding phishing pages, shells, deface pages etc etc. I have tried clamav, maldet but they don't seem to help a lot.

    I just got another complaint. The site is not EXACTLY defaced, but it has a "hacked" page uploaded inside
    Code:
    wp-content/themes/twentyten/x.php
    Not to mention the site is using wordpress. My question is, how can I check when and how this file was uploaded?

    And what can I do to prevent these things?

  2. #2
    Member
    Join Date
    Nov 2006
    Posts
    89

    Default Re: Getting screwed over, need urgent help.

    Quote Originally Posted by Nishant80 View Post
    Hi,
    Not to mention the site is using wordpress. My question is, how can I check when and how this file was uploaded?

    And what can I do to prevent these things?
    you could try looking at the timestamp of the file, though it's conceivable that has been altered.

    Most likely, the WP sites are running old versions of WP or plugins that are vulnerable to attack. Keeping them updated is probably the most effective way to prevent this, but that will likely be challenging. Mass updating of wordpress is pretty simple - there are a lot of scripts out there to do that. There aren't many for updating plugins, though. php-cli is one that looks promising, though I haven't played with it.

    Other than that, compiling apache with suhosin will help some. Be sure you're not running mod_php or have something in place (like mod_ruid2) to keep one site compromise from allowing an attacker to drop exploit code on all sites you host.

    There's no 100% solution.

  3. #3
    Member
    Join Date
    Jul 2012
    Posts
    36
    cPanel/WHM Access Level

    Root Administrator

    Default Re: Getting screwed over, need urgent help.

    Also check your FTP logs, a lot of malware gets uploaded because of compromised user accounts.

  4. #4
    Member
    Join Date
    Apr 2011
    Location
    Chicago, IL
    Posts
    171
    cPanel/WHM Access Level

    Root Administrator

    Default Re: Getting screwed over, need urgent help.

    What about this. ConfigServer eXploit Scanner (cxs)

    That might help. But that best thing to do, is to restore the site to a time, when it was not infected. And change the passwords to a more secure password.

  5. #5
    Member
    Join Date
    Jul 2012
    Posts
    36
    cPanel/WHM Access Level

    Root Administrator

    Default Re: Getting screwed over, need urgent help.

    Quote Originally Posted by tank View Post
    But that best thing to do, is to restore the site to a time, when it was not infected. And change the passwords to a more secure password.
    Thats definitely the best advice. Usually its a stolen password that lets them in.

  6. #6
    cPanel Staff cPanelTristan's Avatar
    Join Date
    Oct 2010
    Location
    somewhere over the rainbow
    Posts
    7,611
    cPanel/WHM Access Level

    Root Administrator

    Default Re: Getting screwed over, need urgent help.

    With WordPress, it's usually an old version actually. They don't need to steal passwords when WordPress has easily exploitable old versions that haven't been updated. Scanning frequently for out-of-date WordPress installs and informing the customer they need to update is the best course of action. If they don't update and get hacked, charging them to restore from a backup would work out well, since they were already informed and now you have to do the work they didn't do.
    cPResources: Support Options | More Support Options | Forums Search | cPanel.net Site Search | Mailing Lists(Alt) | Docs
    -- Tristan, Technical Analyst III, Forums Specialist, cPanel Tech Support

    Submit a ticket | Check an existing ticket

Similar Threads

  1. I am screwed...
    By Piggers in forum cPanel & WHM Discussions
    Replies: 6
    Last Post: 10-10-2004, 11:06 PM
  2. I Screwed up SSL???
    By SBS2003 in forum cPanel & WHM Discussions
    Replies: 9
    Last Post: 10-07-2004, 07:30 PM
  3. Now I really screwed it up!
    By DuckieN in forum New User Questions
    Replies: 3
    Last Post: 09-01-2004, 11:49 PM
  4. UPCP is all screwed up
    By markie in forum cPanel & WHM Discussions
    Replies: 0
    Last Post: 01-03-2004, 08:00 AM
  5. Somebody please ... its screwed up
    By sanjaypande in forum cPanel & WHM Discussions
    Replies: 16
    Last Post: 06-10-2003, 03:52 PM