Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 7 of 7
  1. #1
    Registered User
    Join Date
    Aug 2010
    Posts
    2

    Default Succesful WHM Root login (not me!)

    Hello,

    I've been experiencing the following problems:

    One of the sites I'm hosting had an vulnerability in one of the scripts. The exact script has/can not be found yet but the strange thing is:

    The hackers seem to be able to install a shell on the users account. Then use this shell to gain access to WHM (without knowing the password).
    CSF (cPanel firewall plugin) tells me this through e-mail.

    I personally think there is a private exploit available for this, but I cannot be sure.

    Can anyone tell me anything more? Does he gain full (root) access to WHM or does he just gain authentication access (without being in WHM)

    The strange thing is: nothing has been changed or altered. I'm an experienced adminstrator. My server is pretty secured. And I know I never know for sure my machine is safe after the hacker has gained true access to it.

    The only thing I can't get my finger behind is how they gain root access to WHM with running a webshell on an user account? (who is just a shared hosting user, not reseller or anything, no access to WHM.)

    I can deliver all information if you want.

    Please help me, this has happened twice now (same hacker probably) and I want to give my users a secure feeling (I suspended the vulnerable account until we find the malicious script)

  2. #2
    cPanel Product Evangelist Infopro's Avatar
    Join Date
    May 2003
    Location
    Pennsylvania
    Posts
    7,891
    cPanel/Enkompass Access Level

    Root Administrator

    Lightbulb

    This is not free, but you might find it useful:
    ConfigServer eXploit Scanner (cxs)

    How do you know he's gaining root? What email is CSF sending you?
    Fav cPlinks this week: Blog - cPanel & WHM 11.32 we love it! | cPanel University study for it! | Attracta is coming! we want this!

  3. #3
    Registered User
    Join Date
    Aug 2010
    Posts
    2

    Default

    Thanks for responding! I'm aware of that tool, but I will not look towards solutions for finding any exploits. I will restore the server back to when the user did not

    Like I said, the user has not been in SSH. Only web related services (http and WHM.)

    The e-mail:

    Subject: lfd on <server>.pr0jects.nl: WHM root access alert from 188.123.173.4 (JO/Jordan/-)

    Email body: Time: Thu Aug 19 15:04:14 2010 +0200
    IP: 188.123.173.4 (JO/Jordan/-)

    Bells and alarms started since we don't use root. (can't login to SSH with root from outside. Hacker doesn't try bcuz I see no entry's for his IP trying)

    I stand by my suspicion that there is a 0day cPanel/WHM exploit available somewhere.

    Can the cPanel crew please respond? I saw you looking at my thread....

  4. #4
    cPanel Development cpanelkenneth's Avatar
    Join Date
    Apr 2006
    Posts
    3,782
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Please open a support ticket on the compromised system. If you already have, please PM me the ticket number.

    Thank you.
    Kenneth
    Product Manager
    cPanel, Inc.

  5. #5
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Dec 2003
    Location
    Athens/GREECE
    Posts
    180
    cPanel/Enkompass Access Level

    DataCenter Provider

    Default

    Hello,

    Did you look at WHM access logs to see what he did at the time he gained access?
    Sincerely,

    George Vardikos
    HyperHosting Internet Services

  6. #6
    Member
    Join Date
    Jul 2005
    Location
    Sticky On Internet
    Posts
    555

    Default

    can you check if the user in question has mysql username as root.
    it may also be cpuser_root

    if i am not mistaken some older version of csf reported remote mysql connection with user root as whm access alert.

    I no longer have that OLD box where this happened else i would have tried to dig it for you.

  7. #7
    Member
    Join Date
    May 2010
    Posts
    321

    Default

    Quote Originally Posted by mohit View Post
    can you check if the user in question has mysql
    if i am not mistaken some older version of csf reported remote mysql connection with user root as whm access alert.
    You are correct, The CSF old version did this now blocks any new users with root name.

    To be honest if I got an email where someone logged in as root and I know it wasent me, Id probably have heart attack.

    Either go by what the cPanel pros say or completly disable root via SSH, Make sure its set to JAIL for all accounts. Make a new wheel group with a new user for extra protection.

    Install CHKRootKit and Rootkit Hunter as this will help alot to find and remove the malicious script.

Similar Threads & Tags
Similar threads

  1. WHM with no root login
    By nimrodx in forum Security
    Replies: 10
    Last Post: 09-06-2010, 03:13 AM
  2. Cannot login to WHM with root
    By quangomatt in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 12-24-2009, 11:49 PM
  3. Root Login to WHM
    By bamaster in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 01-14-2008, 11:56 AM
  4. how to change root login user to other for Cpanel WHM login page?
    By onnetsupport in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 06-07-2006, 09:21 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube