Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 8 of 8
  1. #1
    Member
    Join Date
    Oct 2007
    Posts
    5

    Default urgent help wanted

    hello
    i keep finding this page all of my clients especially those who have vBulletin forums

    a picture attached to this thread please check and inform me how to prevent these files from being uploaded to my server
    the picture is in arabic but i think it is clear
    it has most on SSH commands
    Attached Thumbnails Attached Thumbnails urgent help wanted-fixed.jpg  

  2. #2
    Member
    Join Date
    Jul 2008
    Posts
    121

    Default

    Quote Originally Posted by ghaidaa View Post
    hello
    i keep finding this page all of my clients especially those who have vBulletin forums

    a picture attached to this thread please check and inform me how to prevent these files from being uploaded to my server
    the picture is in arabic but i think it is clear
    it has most on SSH commands
    Hello,

    You what?

    This is nothing to do with CPanel..

  3. #3
    cPanel Product Evangelist Infopro's Avatar
    Join Date
    May 2003
    Location
    Pennsylvania
    Posts
    7,891
    cPanel/Enkompass Access Level

    Root Administrator

    Exclamation

    Quote Originally Posted by ghaidaa View Post
    hello
    i keep finding this page all of my clients especially those who have vBulletin forums

    a picture attached to this thread please check and inform me how to prevent these files from being uploaded to my server
    the picture is in arabic but i think it is clear
    it has most on SSH commands
    This does not look good. Especially if you're finding it all over.

    Personally I'd lock down any account I found that on and then start worrying that my entire server was compromised. At the very least you have some sort of script that has been compromised, surely.

    Moving to apache2.x with suphp and mod_security would help some, making sure every single script (vbulletin, Joomla, *.nuke and so on) are up to date or locked down, would help as well.

    Don't ignore this.

  4. #4
    Member
    Join Date
    Jul 2008
    Posts
    121

    Default

    It still isn't a CPanel issue, talk to Vbulletin about it..

    Also, it is _probably_ a vbulletin module, if you ask Vbulletin they will tell you.

    I don't see how this is a "security risk", seen as it is indeed in the Admin Panel..

    Are you out just to cause worry?
    Last edited by sirotex; 07-11-2008 at 07:20 PM.

  5. #5
    cPanel Product Evangelist Infopro's Avatar
    Join Date
    May 2003
    Location
    Pennsylvania
    Posts
    7,891
    cPanel/Enkompass Access Level

    Root Administrator

    Lightbulb

    If you don't recognize it, you'll just have to trust me that that image posted above is not a vbulletin module and is not safe to have on your server.

  6. #6
    Member
    Join Date
    Sep 2006
    Posts
    7

    Default

    I've seen that hack in English and it's usually used on php sites like nuke. They normally use it to upload scripts to the hacked account. It's not a server hack. But I cant remember the name of it. I would also check all of the folders on that account for any unusual files and folders and remove them. Then tell the client to update any software they are using.

  7. #7
    cPanel Partner NOC cPanel Partner NOC Badge AndyReed's Avatar
    Join Date
    May 2004
    Location
    Minneapolis, MN
    Posts
    2,223

    Default

    Quote Originally Posted by ghaidaa View Post
    i keep finding this page all of my clients especially those who have vBulletin forums

    a picture attached to this thread please check and inform me how to prevent these files from being uploaded to my server
    From the image attached to your posting, it looks like a phpshell script such as c99 or r57. Make sure your server is not compromised.

    HowTo secure vBulletin from being hacked: http://servertune.com/kbase/entry/339/
    Andy Reed
    RHCE and CCNA
    ServerTune.com

  8. #8
    Member
    Join Date
    Oct 2007
    Posts
    5

    Default

    thank you verymuch for your help
    i know its not a Cpanel issue or a VBulletin script but i thoghut i could find help in a trusted place and I did
    yes its true the picture shows a shell called C99 and it is the same as C75

    i found somthing today that can prevent uploading that kind of shell to the VB
    its called "CrackerTracker" you can download it from here
    www.traidnt.net/vb/attachment.php?attachmentid=108055&d=1171067073
    and more info at
    CrackerTracker - A Protection System from http://www.cback.de
    i sent an email to all my clients to update their forums and scripts and asked them to use the hack
    i will try it and inform you later
    i accept more assistance
    Last edited by Infopro; 07-13-2008 at 12:35 AM.

Similar Threads & Tags
Similar threads

  1. urgent help wanted
    By ghaidaa in forum cPanel and WHM Discussions
    Replies: 7
    Last Post: 07-12-2008, 07:57 PM
  2. Help wanted
    By merlinpa1969 in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 08-07-2007, 08:23 PM
  3. URGENT! URGENT! WHM restore questions. Reward waiting for you!
    By Ganga in forum cPanel and WHM Discussions
    Replies: 6
    Last Post: 10-01-2004, 07:16 PM
  4. help wanted :S
    By qbert1987 in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 12-30-2003, 12:50 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube