Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 4 of 4
  1. #1
    Member
    Join Date
    Feb 2008
    Posts
    26

    Angry My server has been hacked again. Please Help me!

    Hi there,
    I had my server hacked , I found this script that was run as root:

    [snipped]


    How can i defender my server from this script (Back Connect Backdoor) ?
    Last edited by Infopro; 11-21-2009 at 10:37 PM. Reason: removed code from posts

  2. #2
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Mar 2003
    Location
    NC
    Posts
    725
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Are you literally running RH9? That is an incredibly old release that is open to who knows how many exploits.

    If the attacker gains root it is hard to block them from doing much. A properly configured firewall can help block a backdoor like that from working but if they have root wiping the iptables rule would allow it to work.

    What kernel were you running when you got exploited? You probably need to update it or get an entirely new OS.

  3. #3
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Jul 2005
    Posts
    609

    Default

    Quote Originally Posted by hackboys View Post
    Hi there,
    I had my server hacked , I found this script that was run as root:

    [snipped]

    How can i defender my server from this script (Back Connect Backdoor) ?
    Thanks for posting this, now even more hackers will have that backdoor and exploits.

    Seriously dude, you still have a RH 9 install disk? That belongs in a museum.

    RH9 was released like 5 years ago, and even at that time it wasn't that good. The RH series was totally discontinued after that, and is now RHE. RHE 5 is out, or if you want a free OS go with CentOS 5.
    Last edited by Infopro; 11-21-2009 at 10:36 PM.

  4. #4
    Member
    Join Date
    Jan 2005
    Location
    Earth
    Posts
    1,050

    Default

    Your server is definitely rooted and cannot be cleaned up. The best way it to re-install the machine and apply some security tweaks.

    The most important is your kernel which need to be kept updated as such rootkits are uploaded using a security hole in the kernel. You can then enable Apache suexec, PHP suexec, enable open_basedir, disable some php functions using which server side commands can be executed, install CSF firewall, mount /tmp and /dev/shm with noexec,nosuid mode and a few other important changes.

Similar Threads & Tags
Similar threads

  1. My server has been hacked again. Please Help me!
    By hackboys in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 11-21-2009, 02:02 PM
  2. server has been hacked
    By aracrew in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 01-21-2008, 05:55 PM
  3. my server got hacked?
    By goodgbb in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 08-25-2005, 09:18 AM
  4. Server being hacked?
    By ThaMATRiX in forum cPanel and WHM Discussions
    Replies: 35
    Last Post: 10-18-2004, 08:05 PM
  5. Server hacked.
    By Schaap in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 08-19-2004, 11:47 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube