Ok,
Long story short..ish
So up until this morning my server & websites were running fine,
however woke up today to see that my sites looked like they were currupted, well the forums anyway,
So looking through the FTP, all files seemed intact,
I looked through my non forum sites and noticed they were serving out malware via an embeded IFrame.
However checking the FTP all files were intact & not altered.
I decided I would go through and start securing the server to see if I could find the rootkit or whatever was causing the issues so first off I done a:
Forced Cpanel Update
Once this had completed my websites were fine?
I had to run out after that, a few hours later and my sites were again hacked.
Another Cpanel Update later & my sites were ok again?
After hours of searching I came accross many threads saying that this hack is caused via hackers gaining access to FTP accounts.
However, i dont use easy passwords 20+ letters, numbers, symbols
reading further it was said that they also gain them by infecting the source PC and store them when you connect to the site for maintance etc..
But after a virus / malware scan = nothing, (I also have these running 24/7 due to certain data i deal)
So anyway, I have updated all passwords, disabled all shell access on accounts.
But i still dont get as to how this hack is happening, when files are not being edited and that its currently solved by forcing cpanel to update?
I haved checked just about everything & I cannot find anything out of place?



LinkBack URL
About LinkBacks
Reply With Quote





