Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 6 of 6
  1. #1
    Member
    Join Date
    Apr 2009
    Posts
    21

    Default CPanel hacked

    I thought CPanel was secure, but I guess I was wrong.

    Suddenly, I find out that several of the user accounts have been hacked into where index.php has either been over written, or index.html has been placed, along with other malicious scripts...

    Currently, load avg is sky high due to lots of exim procs. God knows what's running them all.

    How do I go about finding out how it happened and securing the server?

  2. #2
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Jul 2005
    Location
    New Jersey, USA
    Posts
    397

    Default

    The problem is not with cpanel. Hacks can occur from many different angles (insecure scripts, weak passwords, etc). You have to check how it occurred by reviewing the logs and then implement security features on your server (modsecurity, firewall, etc)

  3. #3
    Member
    Join Date
    Dec 2008
    Posts
    153

    Default

    maybeee.. they got root access or something, I doubt it was a cpanel hack

  4. #4
    Member
    Join Date
    Apr 2009
    Posts
    21

    Default

    The problem is, I am trying to block certain IP addresses by adding them to host access block but it doesn't seem to be working either

  5. #5
    Support Manager cPanelEric's Avatar
    Join Date
    Nov 2007
    Location
    Texas
    Posts
    488
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Just some friendly advise. Stop the mailserver(exim) and start purging the queue. Whom ever hacked it likely stocked it full of junk. You'll likely get blacklisted for sending all that garbage to boot.

    As soon as you get the system under control put a stock exim configuration in place and start doing some security forensics. Determine the depth of the compromise, aka did they get root? Determine the state of your backups and act accordingly.

  6. #6
    Member SB-Nick's Avatar
    Join Date
    Aug 2008
    Posts
    110

    Default

    You should change all your account's FTP passwords and cPanel account passwords and/or contact a Security Advisor to perform a Security Audit.
    :: Server Buddies ::

    Server Management & Monitoring

    .Dedicated Server Solutions At Affordable Rates.

Similar Threads & Tags
Similar threads

  1. My CPanel was hacked
    By billwide in forum cPanel and WHM Discussions
    Replies: 5
    Last Post: 09-13-2007, 12:06 PM
  2. PLEASE HELP - cPanel Was Hacked!!
    By mhollibush in forum New User Questions
    Replies: 6
    Last Post: 02-26-2007, 05:37 PM
  3. cpanel hacked
    By helmers99 in forum cPanel and WHM Discussions
    Replies: 14
    Last Post: 11-19-2006, 12:35 PM
  4. Replies: 21
    Last Post: 05-08-2003, 02:31 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube