Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 7 of 7
  1. #1
    Member
    Join Date
    Jan 2011
    Posts
    14

    Default Access logs, file manager logs etc

    Hi

    Client had a breach to their website, got the access logs and fount the culprit and their IP. FTP logs show no access. Access logs show once inside cpanel then went into file manager. This where they deleted public_html folder.

    Where do i find a log that tells me they deleted this folder?

  2. #2
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Jun 2004
    Posts
    313
    cPanel/Enkompass Access Level

    DataCenter Provider

    Default Re: Access logs, file manager logs etc

    Try searching through:

    Code:
    /usr/local/cpanel/logs/access_log
    This file contains access_log data for the cPanel/WHM interface, and you can search through the GET strings for 'frontend/x3/filemanager' (or whatever skin is used).
    NDCHost (ProVPS): Xen VPS / Dedicated / Co-Location
    Contact us for your cPanel Licensing needs! We price match, provide better support, and take care of our customers!

  3. #3
    Member
    Join Date
    Jan 2011
    Posts
    14

    Default Re: Access logs, file manager logs etc

    Hi

    I've had a look through them and indeed got results from the criminals IP which shows GET requests. But what am i looking for that shows a request "delete public_html" ?

  4. #4
    cPanel Product Evangelist Infopro's Avatar
    Join Date
    May 2003
    Location
    Pennsylvania
    Posts
    7,894
    cPanel/Enkompass Access Level

    Root Administrator

    Default Re: Access logs, file manager logs etc

    I'm not sure that there are log files for the File Manager itself, hopefully I'll be corrected here by someone. I've just created and then deleted a directory via FM and can find no traces of those actions in my logs.

  5. #5
    Member
    Join Date
    Jan 2011
    Posts
    14

    Default Re: Access logs, file manager logs etc

    There is logs of said person accessing file manager.

    Thing is my client wants to process legal action and needs said logs... bit lacking if logs are provided for GET accesses to FM but not rm -rf requests?

  6. #6
    cPanel Product Evangelist Infopro's Avatar
    Join Date
    May 2003
    Location
    Pennsylvania
    Posts
    7,894
    cPanel/Enkompass Access Level

    Root Administrator

    Default Re: Access logs, file manager logs etc

    There is logs of said person accessing file manager.
    Correct.

    bit lacking if logs are provided for GET accesses to FM but not rm -rf requests?
    I agree. If there are tracks left for actual actions in File Manager I'm not sure where they'd be.

    That said, how did they get into the account? If the user did not have a hard-to-guess password this type of damage should be expected. Restoring the account from backup and setting a much harder password, and, scanning this users home computer for any sort of problems is suggested.

    Good luck!

  7. #7
    Member
    Join Date
    Jan 2011
    Posts
    14

    Default Re: Access logs, file manager logs etc

    Yeah I store back ups for clients, so I resorted this for them within 20mins of it going down. Reset passwords and provided it via phone (too risky to provide by email at that point) The breach was from an ex-friend of theirs, they guessed my clients google mail security questions and gained access to confidential emails and credentials.

    The access logs are enough for a small claims court here in the UK. Just one of those things ain't it.... although logs of what people do in file manager would of been handy at this point.

    Thanks for your help.

Similar Threads & Tags
Similar threads

  1. Replies: 4
    Last Post: 03-03-2011, 12:10 PM
  2. What logs are "Backup Access Logs" in the back up option.
    By DWHS.net in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 03-08-2010, 04:03 PM
  3. API & File manager logs
    By Sergiu Tot in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 08-03-2009, 07:32 AM
  4. Logs for File Manager Uploads
    By zack.a in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 05-14-2007, 01:21 PM
  5. File Manager Logs and tmp directory
    By demomen in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 02-04-2006, 06:57 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube