Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Results 1 to 9 of 9
  1. #1
    Member
    Join Date
    Jul 2003
    Posts
    33

    Default Is my server hacked?

    Every time I visit all sites of a server.. I'm redirected to this unknown russian site..
    http://www.nnovauto.ru

    and so as other sites that are being hosted...

    anyone here who experiencd the same??

  2. #2
    Member rhenderson's Avatar
    Join Date
    Apr 2005
    Location
    Oklahoma
    Posts
    742

    Default

    Do a search on here for a javascript hack, there have been several posts about this exact same thing around 4 to 6 months ago but I cannot remember exactly what they were. If I remember correctly there was some script or test you could do.
    Regards,
    Randy
    Affordable Web Hosting
    _________________________

  3. #3
    Member
    Join Date
    Jul 2003
    Posts
    33

    Default I can't find any scripts.

    The server has 100 sites.

    When I search sites og the server in google, google show me the link.

    If i click it, it redirect to another site.

    But if I copied th link, it work find.

  4. #4
    Member
    Join Date
    Apr 2007
    Location
    Bakersfield, California
    Posts
    270

    Default

    Does this thread shed any light? http://forums.cpanel.net/showthread.php?t=62821

    I know there are some threads over at WHT about Javascript injection in pages. Have you tried scanning your server with a rootkit hunter?

  5. #5
    Member
    Join Date
    Mar 2002
    Posts
    295

    Default

    Assuming the pages have been modified by inserting iframes

    if you look you will find some scripts that will clean the iframes from all the files

    add a firewall and rootkit hunter

  6. #6
    Member rhenderson's Avatar
    Join Date
    Apr 2005
    Location
    Oklahoma
    Posts
    742

    Default

    Quote Originally Posted by Silver_2000 View Post
    Assuming the pages have been modified by inserting iframes

    if you look you will find some scripts that will clean the iframes from all the files

    add a firewall and rootkit hunter
    Thanks SIlver Iframes was what I was thinking about when I posted above, just could not remember the terminaology. Gave you a rep for that one.
    Regards,
    Randy
    Affordable Web Hosting
    _________________________

  7. #7
    Member brianoz's Avatar
    Join Date
    Mar 2004
    Location
    Melbourne, Australia
    Posts
    1,093
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    You also need to be concerned about how the iframe code got there in the first place. If you remove the code without fixing the security problem, the code will likely get put back again.

    At the least you should:
    • change your root and/or reseller passwords
    • check logs to see whether ftp was used, if so, change the user passwords
    • if the server is yours, check for up to date kernel
    • add CSF firewall from www.configserver.com

    From hearing about this happen before, the ways they get in to do this seem to be (choose one, usually):
    • user PHP scripts with weaknesses, leading to system compromise
    • sniffing the root/reseller password over wifi
    • a trojan keylogger installed on your PC/desktop/laptop
    • an old kernel with a known weakness
    • stealing passwords on a server not running suphp and using them to escalate privilege

  8. #8
    Member
    Join Date
    Jul 2003
    Posts
    33

    Default No iframe injection..

    Here try test..

    orinonga.com

    Search it at google.

    And copy the link from google, visit...
    Last edited by Infopro; 05-14-2009 at 06:44 PM.

  9. #9
    Member
    Join Date
    Aug 2006
    Posts
    47

    Default

    I had the IFRAME problem but I'm now having one other problem, similar to this one.

    The websites files (several websites, on my server), are ok, and not changed but, when entering it from the browser, a javascript is there.

    Restarting apache solves the issue (temporarily)

    Somebody told me about code injection to the shared memory or something.

    Maybe suPHP will help. Will try this weekend.

    Do you have suPHP installed?

    best regards

Similar Threads & Tags
Similar threads

  1. my server is hacked
    By jcaldera in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 05-02-2009, 04:23 PM
  2. server has been hacked
    By aracrew in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 01-21-2008, 06:55 PM
  3. Server get hacked
    By vishwas in forum cPanel and WHM Discussions
    Replies: 5
    Last Post: 12-02-2005, 04:49 AM
  4. my server got hacked?
    By goodgbb in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 08-25-2005, 10:18 AM
  5. new server got hacked
    By brumie in forum cPanel and WHM Discussions
    Replies: 24
    Last Post: 04-29-2004, 01:00 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube