Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 4 of 4
  1. #1
    Member
    Join Date
    Jan 2005
    Posts
    12

    Default CGI - Hacking?

    Hey guys!

    I have a quick question.
    A customer of mine has claimed that he been hacked via CGI scrtipts (namely entropymail.cgi IIRC). Anyhow, this user claims that someone has gone in, run a command which tarred up their whole home dir and then then moved it to a place that someone could download it (ie into the public_html folder)

    First of all, is this plausible?
    heres what the hacker allegedly used:
    Code:
    entropymail.cgi?|tar -cf user.tar /home/user/|
    Now, i am sceptical that it would be so easy to hack soemthign which is built into cpanel (i know for a fact this user hadnt installed/used anything) but theres also the possibility that they have signed up for an account themselves (the hacker that is) and they have then use the aforementioned cgi thing to exploit this users site.

    What i want to know is is this possible and if so, how would i go about fixing this massive security hole?

    - MARK

  2. #2
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    I cannot find a script called entropymail.cgi on my servers, is this a script that the user installed themselves, or have you got the wrong script name?
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  3. #3
    Member
    Join Date
    Jan 2005
    Posts
    12

    Default

    hey chirpy,

    I have loked also, and i cant see anything called entropymail but i beleive he used one of the entropy scripts on the servers. Although, this is a dude who got hacked asking the hacker how he did it. It turns out the hacker did sign up to our company and it looks as though as he has installing phpmyadmin and somehow obtained all the files in the persons home directory.

    Not only am i worried about the security of the server, i dont like peoples source files getting leaked. Hence why i came here for advise.

    This user signed up for a small plan, which DIDNT have CGI enabled. So i can only say that it was a inbuilt script.
    Since then i have disabled all of cpanels inbuilt CGI stuff via the featurte manager thing. For some reason i cant get rid of cgiemail though.

  4. #4
    cPanel Partner NOC cPanel Partner NOC Badge AndyReed's Avatar
    Join Date
    May 2004
    Location
    Minneapolis, MN
    Posts
    2,223

    Default

    I suggest you run rkhunter and chkrootkit to make sure that your server is not vunerable. Data forensic is real time consuming and exahusting. If you think that your server is unsecure, OS reload is your best option.
    Andy Reed
    RHCE and CCNA
    ServerTune.com

Similar Threads & Tags
Similar threads

  1. Replies: 0
    Last Post: 02-14-2005, 09:49 PM
  2. Hacking
    By mahdionline in forum cPanel and WHM Discussions
    Replies: 13
    Last Post: 10-12-2004, 12:11 PM
  3. Hacking
    By sujai in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 02-09-2004, 06:44 AM
  4. Hacking? Not Sure!!!
    By sunnycom in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 10-21-2003, 08:00 AM
  5. hacking help
    By shann in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 11-30-2002, 04:46 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube