Results 1 to 6 of 6

Thread: WHM Attack

  1. #1
    Member
    Join Date
    Jan 2012
    Posts
    9
    cPanel/WHM Access Level

    Root Administrator

    Default WHM Attack

    I recently got attacked on my VPS ( which is a hosted VPS with WHM / cPanel on it)

    I have cphulk active on it and locks them out after 3 attempts but somehow my root password got changed and a customers site had nice "you've been hacked" messages on it.

    What can I do to protect WHM / cPanel?

    Help!

  2. #2
    Member Astral God's Avatar
    Join Date
    Sep 2010
    Location
    127.0.0.1
    Posts
    167
    cPanel/WHM Access Level

    Root Administrator

    Default

    Please check /http://www.whmsecurity.com/linux-security/7-how-whm-cpanel-hardening-security-basics-part-1-a.html lots of tips here for overall security.

  3. #3
    Member
    Join Date
    Apr 2011
    Location
    US
    Posts
    209
    cPanel/WHM Access Level

    Root Administrator

    Default Re: WHM Attack

    Use only strong passwords. Also check the logs to see more details.
    www.PlotHost.com - Professional Web Hosting Solutions

  4. #4
    Member GIANT_CRAB's Avatar
    Join Date
    Mar 2012
    Posts
    62
    cPanel/WHM Access Level

    Root Administrator

    Default Re: WHM Attack

    Hello Astral,

    Quote Originally Posted by Astral God View Post
    Please check /http://www.whmsecurity.com/linux-security/7-how-whm-cpanel-hardening-security-basics-part-1-a.html lots of tips here for overall security.
    That website contains very misleading information such as turning on magic quotes, safe mode, disabling shell access for all (other than root), suhosin etc.
    A new user should never have suhosin installed, in-fact, suhosin doesn't really harden WHM but more of PHP.
    All these are terrible mistakes and I suggest not to follow them.

    There are smarter ways of hardening your WHM.

    Firstly, you need to actually find out HOW the attacker actually hacked into your server.
    After finding out how the attack hacked into your server, it will eventually be better rather than just guessing the leak hole and anyhow- patching everything that is useless.

    Yours truly,
    GIANT_CRAB
    Support operator @ LoomHosts

  5. #5
    Registered User
    Join Date
    Jun 2012
    Posts
    1
    cPanel/WHM Access Level

    Root Administrator

    Default Re: WHM Attack

    you will use strong pass ex:minhtikh@23$

  6. #6
    cPanel Staff cPanelTristan's Avatar
    Join Date
    Oct 2010
    Location
    somewhere over the rainbow
    Posts
    7,611
    cPanel/WHM Access Level

    Root Administrator

    Default Re: WHM Attack

    Let's hope that isn't one of your passwords!

    As for password strengthening, you could configure that in WHM > Configure Security Policies > Password Strength and then WHM > Security Center > Password Strength Configuration areas.
    cPResources: Support Options | More Support Options | Forums Search | cPanel.net Site Search | Mailing Lists(Alt) | Docs
    -- Tristan, Technical Analyst III, Forums Specialist, cPanel Tech Support

    Submit a ticket | Check an existing ticket

Similar Threads

  1. I'm under attack
    By mystikzen in forum E-mail Discussions
    Replies: 4
    Last Post: 11-27-2007, 06:22 AM
  2. Attack, help me please.
    By brave in forum cPanel & WHM Discussions
    Replies: 14
    Last Post: 04-01-2005, 05:04 AM
  3. help me attack
    By preleaf in forum cPanel & WHM Discussions
    Replies: 3
    Last Post: 11-28-2004, 03:22 AM
  4. Under attack!?!?
    By (SH)Saeed in forum cPanel & WHM Discussions
    Replies: 18
    Last Post: 08-06-2003, 08:15 AM
  5. HELP! UNDER ATTACK!
    By (SH)Saeed in forum cPanel & WHM Discussions
    Replies: 3
    Last Post: 11-03-2002, 10:48 AM