Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Page 13 of 13 FirstFirst ... 3 11 12 13
Results 181 to 189 of 189
  1. #181
    Member
    Join Date
    Sep 2006
    Posts
    9

    Default

    Quote Originally Posted by dragon2611 View Post
    UPCP also runs the Operating systems package management utility to check for updates (well i think it actually depends on the settings) so it wouldnt surpise me if all that happened is those files were replaced with a newer version.

    Afaik LFD uses checksums to see if the files have changed and throws that up if they have when it's quite possible it was just an OS update that's caused them to change.
    Thanks for the reply. That's very possible and eases my mind a bit.

    I'm still being cautious.

  2. #182
    Member
    Join Date
    Nov 2003
    Posts
    119

    Default

    Quote Originally Posted by sweetsteve View Post
    Thanks for the reply. That's very possible and eases my mind a bit.

    I'm still being cautious.
    I've had false warnings from it before..

    I've also had the Random JS rootkit before, Not seen it around lately though either the creators are laying low or someone found out how it was getting onto all these servers and patched the hole.

  3. #183
    Member
    Join Date
    Sep 2006
    Posts
    9

    Default

    I found some discussion about false alarms here:
    http://forum.configserver.com/showthread.php?t=1052

    I'm thinking the only real test is to restart the servers and then check for signs that the exploit is installed.

  4. #184
    Member
    Join Date
    Sep 2006
    Posts
    9

    Default

    Quote Originally Posted by cpaneldave View Post
    Steve,
    Don't take this warning lightly. It has all the signs of a rootkit we've been seeing that affects those specific files. Try the following tests on your system to see what happens:

    Code:
    [root\@cpanel ~]# mkdir 1
    mkdir: cannot create directory `1': No such file or directory
    [root\@cpanel ~]# touch 2
    touch: cannot touch `2': No such file or directory
    If you see the above results, it's almost certain your server has been compromised

    If you believe your server has been compromised, then you should contact your datacenter or NOC to have
    them properly clean the server. You will also need to change all account passwords on the system to
    prevent your server from being re-compromised.
    I did those test and also the tcpdump test and everything seems ok, but I'm wondering if the server needs to restart before the thing becomes live.

  5. #185
    Member
    Join Date
    Dec 2001
    Posts
    746

    Default

    Steve,
    Don't take this warning lightly. It has all the signs of a rootkit we've been seeing that affects those specific files. Try the following tests on your system to see what happens:

    Code:
    [root\@cpanel ~]# mkdir 1
    mkdir: cannot create directory `1': No such file or directory
    [root\@cpanel ~]# touch 2
    touch: cannot touch `2': No such file or directory
    If you see the above results, it's almost certain your server has been compromised

    If you believe your server has been compromised, then you should contact your datacenter or NOC to have
    them properly clean the server. You will also need to change all account passwords on the system to
    prevent your server from being re-compromised.

  6. #186
    Member
    Join Date
    Dec 2001
    Posts
    746

    Default

    Quote Originally Posted by sweetsteve View Post
    I did those test and also the tcpdump test and everything seems ok, but I'm wondering if the server needs to restart before the thing becomes live.
    You can always look at the MD5 sums for those files from your distributions download mirror or open up the files in a test editor to make sure they haven't been replaced with a perl script.

    I'd grep through the index files in your home partition to see if any have been injected with iframes as well.

    Side note:
    If you think you may be compromised, definitely do not restart the box. A lot of compromises will alter binaries and such on restart.

  7. #187
    Member
    Join Date
    May 2003
    Posts
    118

    Default

    I had the same warnings. They are false positives from LFD due to last night's cpanel update. I also did cpaneldave's test on the server and it came back fine. In other words I was able to create the directories.
    Brian

  8. #188
    Member
    Join Date
    Dec 2001
    Posts
    746

    Default

    Quote Originally Posted by brianc View Post
    I had the same warnings. They are false positives from LFD due to last night's cpanel update. I also did cpaneldave's test on the server and it came back fine. In other words I was able to create the directories.
    It's likely that the rootkit publishers have seen our test and modified the rootkit to report success. I'd still inspect the files just to make sure. Here's a good presentation from our June conference about how in-depth and organized these types of threats are:

    http://www.cpanel.net/conference/08/...zedThreats.pdf

  9. #189
    Member
    Join Date
    Sep 2004
    Posts
    8

    Default

    A lot of the false positives on CentOS are related to the fact that CentOS 4.7 was released, therefore a huge amount of rpms were replaced.

Similar Threads & Tags
Similar threads

  1. Virus on the server?
    By scooby_london in forum cPanel and WHM Discussions
    Replies: 7
    Last Post: 09-28-2009, 04:52 PM
  2. Strange Virus On cPanel server
    By MurdochNZ in forum cPanel and WHM Discussions
    Replies: 188
    Last Post: 09-14-2008, 05:39 AM
  3. Replies: 6
    Last Post: 08-04-2007, 08:11 PM
  4. Replies: 28
    Last Post: 06-24-2005, 10:03 PM
  5. strange mailserver problem on a cpanel server
    By apogee in forum cPanel and WHM Discussions
    Replies: 13
    Last Post: 12-10-2004, 01:25 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube