Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 6 of 6
  1. #1
    Member
    Join Date
    May 2006
    Location
    Perú
    Posts
    35

    Default Webpage cracked with ftp cracker

    Hi one of the webs of a client on my sever was hacked with this script: /http://www.ghostng.com/images/serte.php
    What can i do in the WHM config to avoid that kind of hacking attempts?

    Ty so much!

  2. #2
    cPanel Quality Assurance Analyst cPanelDon's Avatar
    Join Date
    Nov 2008
    Location
    Houston, Texas, U.S.A.
    Posts
    2,555
    cPanel/Enkompass Access Level

    DataCenter Provider

    Default

    Quote Originally Posted by samuelmf View Post
    Hi one of the webs of a client on my sever was hacked with this script: /http://www.ghostng.com/images/serte.php
    What can i do in the WHM config to avoid that kind of hacking attempts?

    Ty so much!
    Are you saying an FTP user's password was "cracked" (such as by a brute-force attempt to guess the FTP user's password)?

    I would consider ensuring that cPHulk is enabled and or adjust its configuration via the Security Center in WebHost Manager; you may also use WHM to increase the default required password strength that is enforced both for new FTP accounts and when cPanel users modify their existing account password(s).

    Reference menu paths and documentation:

  3. #3
    Member
    Join Date
    May 2006
    Location
    Perú
    Posts
    35

    Default I had the Cphulk disabled

    Hi, thanks for reply, when i enable cphulk this message appears on the screen:

    Warning: VerifyReverseMapping was detected as being enabled for SSHD which causes problems with whitelisting IPs for cPHulkd. VerifyReverseMapping has been set to "no" to prevent issues.

    For this change to take effect, please Restart SSHD at your nearest convenience.



    I have installed on my server the Configserver Firewall Script

  4. #4
    cPanel Quality Assurance Analyst cPanelDon's Avatar
    Join Date
    Nov 2008
    Location
    Houston, Texas, U.S.A.
    Posts
    2,555
    cPanel/Enkompass Access Level

    DataCenter Provider

    Default

    Quote Originally Posted by samuelmf View Post
    Hi, thanks for reply, when i enable cphulk this message appears on the screen:

    Warning: VerifyReverseMapping was detected as being enabled for SSHD which causes problems with whitelisting IPs for cPHulkd. VerifyReverseMapping has been set to "no" to prevent issues.

    For this change to take effect, please Restart SSHD at your nearest convenience.
    It is normal for cPHulk to first check for SSHd configuration directives that might conflict. To restart SSHd, please try the following area in WebHost Manager: WHM: Main >> Restart Services

    Quote Originally Posted by samuelmf View Post
    I have installed on my server the Configserver Firewall Script
    I believe it may be OK to run both cPHulk and CSF.

  5. #5
    Member
    Join Date
    May 2006
    Location
    Perú
    Posts
    35

    Default Service restarted

    Thx, the service was restarted and cphulk, csf and sshd are running well!

  6. #6
    Member
    Join Date
    May 2006
    Location
    Perú
    Posts
    35

    Default Files that the hacker have used

    I will upload the files that the hacker have left on the hacked page.
    -removed by Infopro-

    There are the files the hacker left on my site, if someone have knowings about programing and linux at expert level could analyse to help other prevent that kind of hackings.

    If the files are risky please let me know, to delete them!

    Ty
    Last edited by Infopro; 08-28-2010 at 08:03 PM. Reason: removed files from post

Similar Threads & Tags
Similar threads
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube