Hi,
Three of my WHM servers were compromised on Thu-Fri by Sarbot511.
I believe they get in through an application which are open to SQL Inject attack. My question is how did they gain root password of the server through SQL Inject?
I have SuPhp, mod_security, and CSF firewall installed. All clients are running through their own username, if a client's website say is open to SQL inject attack, how is it possible for them to gain root access and compromised the whole server?
Any inputs would be appreciated. I am currently clueless on how to patch the hole. I tried reloading the server and restored client data back to the server, within a few hours the same server is compromised again, the same way.
Thank you.



LinkBack URL
About LinkBacks
Reply With Quote











