Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Page 2 of 2 FirstFirst 1 2
Results 16 to 21 of 21
  1. #16
    Registered User
    Join Date
    Jan 2008
    Posts
    4

    Default

    if its the same issue to why servage and others has been hacked..
    /slap on you..
    the spam that has happened past 3 weeks has been due to kernels not beeing updated (for one..).
    Start making sure you updated the kernel and all other scripts that is running.
    Especially all those "one click install" scripts that come with things such as fantastico.

    make the propper updates, install mod_security, thighten your apache+php install.

    install firewall and other kinds of protection while your at it if you havent already.
    Good luck.

  2. #17
    Member
    Join Date
    Jan 2008
    Location
    Buenos Aires, Argentina
    Posts
    942
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    I wonder if host2host have been able to solve this problem

  3. #18
    Member
    Join Date
    May 2007
    Posts
    78

    Default

    Quote Originally Posted by DennisTG View Post
    the spam that has happened past 3 weeks has been due to kernels not beeing updated (for one..).
    How often are Kernels released (on average)?
    And where do you see if you have the latest version? I know what version I have, but whereabouts on the CentOs site are they located to see if your version matches the latest one?

  4. #19
    Member markfrompf's Avatar
    Join Date
    Mar 2006
    Location
    Los Angeles, CA
    Posts
    179

    Default

    You should probably also firewall out the IP range since you found it in your logs - Then when you're all secured, unfirewall it and see if he gets back in.

    Also, this one hit us a month or so ago: C99MadShell
    -----------------------------------------------------------
    | Mark A. Mutti: PhireFast Website Hosting
    | E: Mark.mutti@phirefast.com - P: (866) 350-4456 Ext. 100
    | 24/7 Support, 15 Minute Average Response Time
    | cPanel, Fantastico, Webmail & More!
    -----------------------------------------------------------

  5. #20
    Registered User
    Join Date
    Jun 2008
    Posts
    1

    Default

    Register_Globals = OFF

    This will thwart a heap of attacks, and make sure you have a .htaccess file in place to prevent some malicious types of URL calls.

  6. #21
    cPanel Partner NOC cPanel Partner NOC Badge AndyReed's Avatar
    Join Date
    May 2004
    Location
    Minneapolis, MN
    Posts
    2,223

    Default

    Quote Originally Posted by markfrompf View Post
    Also, this one hit us a month or so ago: C99MadShell
    c99Shell and r57shell scripts have been around for more than two years. There are many phishing scripts out there, C99shell.php, for example, is one of'em which provides a shell-like prompt to let you execute commands interactively.

    The Php Shell is a Php based script. With this script a hacker can execute arbitrary shell commands or browse the file system on a remote web server. Hackers can also use such a script for transferring a malicious site as a compressed file, unpack and then run it on a Web server. Unless you have a script to scan the content of files hosted on your Web server otherwise hackers can disguise the r57shell or c99shell as an image or html file. We've seen and cleaned up these shellscripts on many servers.
    Andy Reed
    RHCE and CCNA
    ServerTune.com

Similar Threads & Tags
Similar threads

  1. Website Hacked.
    By ManojB in forum Security
    Replies: 13
    Last Post: 11-11-2008, 04:05 PM
  2. Website Hacked.
    By ManojB in forum cPanel and WHM Discussions
    Replies: 13
    Last Post: 11-11-2008, 04:05 PM
  3. HELP !!!! Website hacked by Viagara and medicine links
    By host2host in forum New User Questions
    Replies: 20
    Last Post: 06-17-2008, 11:59 PM
  4. Website Hacked
    By KenCo in forum Data Protection
    Replies: 23
    Last Post: 07-16-2007, 05:40 PM
  5. a website has been hacked
    By Bert W in forum cPanel and WHM Discussions
    Replies: 5
    Last Post: 06-24-2003, 07:52 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube