Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Results 1 to 10 of 10
  1. #1
    Member
    Join Date
    May 2004
    Posts
    32

    Default Compromised Server

    First ever Cpanel dedicated server, after reselling for a long time.

    Less than a month into things, my server is compromised and doing rogue tcp traffic. Got a WHM red message: exim security prob.

    Upgraded to

    WHM 9.2.0 cPanel 9.3.0-R5
    Fedora - WHM X v3.1.0


    System still compromised, server provider has limited the port.

    What next? How could I have avoided this.
    Any help much appreciated.


    G.
    Fedora - WHM X v3.1.0

  2. #2
    Member
    Join Date
    Aug 2001
    Posts
    132

    Default

    Steve at sales@rack911.com is a very good guy on security issues ("thelinuxguy" is his username on various fora).

  3. #3
    Member
    Join Date
    May 2004
    Posts
    32

    Default Interpreting Bandmin

    It would appear that the update to the next newest release did the trick, though whm reports same versions as before

    Exim is now the latest 4.34

    BUT HOW CAN I BE SURE? It has stopped.

    If you keep refreshing bandmin and the numbers don't change much, does that mean that the rogue tcp traffic has been halted?

  4. #4
    Member bamasbest's Avatar
    Join Date
    Jan 2004
    Posts
    531

    Default

    Have you installed a firewall?

    Very well worth the time/effort/resources!

  5. #5
    Member
    Join Date
    May 2004
    Posts
    32

    Default Firewall and Security progs.

    No, and if you mean physical box it cannot be done. The server, though managed by me, is not under my physical control but with a provider. If you mean firewall software then I'd be interested to know about the possible solutions, that are compatible with cpanel.

    What I have found most difficult about the current situation is that cpanel gives you the impression that you can actually pretty much run a server with very little command line knowledge and their updates will keep you protected, when in fact all it takes is for one of the many scripts, modules, services (here exim) to have a security flaw in an update and you will be left with a mess.

    Cpanel did not even report anything but allowed the compromised port/s to do 40Gig of traffic in 6-10 hours. It was only the providers phone call that allerted me.

    As far as I know, there is no way to actually trace/close-off or limit a port except from the command line and it is beyond my capabilities. Of course I could learn, but it means entirely reworking my business expectations. It's hard enough in such an environment just to gain customers. But then if you spend an entire day, like the one just spent it eats away at any profitability.

    I would love some pointers to some good programs that work well with cpanel and would allow real control tracking of ports and limiting bandwidth on them, and also tracking down bad traffic etc. Also: does anybody know where one can find the full logs that report details on this unknown TCP traffic? You certainly can't access any of this from cpanel.


    Any pointers would be much appreciated

  6. #6
    Member
    Join Date
    Feb 2004
    Posts
    469

    Default

    Maybe you could benefit from some one who could do all the security fixes for you then your time could be better spent tending your business.
    I spotted this thread the other day that might be of interest and it looks like there are more offers like this in the same forum. Could be useful in your situation.
    HTH.

  7. #7
    Member bamasbest's Avatar
    Join Date
    Jan 2004
    Posts
    531

    Default

    mygregory,

    apf firewall is very popular amongst cpanel users (software firewall) and is very easy to install.

    Here's a link to some simple instructions for installation:
    http://www.webhostgear.com/61.html

    you should also checkout that site's other tutorials for improving security.

  8. #8
    Member
    Join Date
    May 2004
    Posts
    32

    Thumbs up Looks interesting

    Thank you for your kind help,

    Useful resource. Will probably install APF, though not sure if I need to take any other action beforehand to stop the current use of the ports.

  9. #9
    Member bamasbest's Avatar
    Join Date
    Jan 2004
    Posts
    531

    Default

    Before I installed APF, I thought that my server was fairly secure. Amazing how after I installed it, my logwatch email showed me how many packets were dropped by the firewall.

    I still get some errant attempts by hackers (to no avail), but as soon as I discover the problem, I simply deny access to their IP/IP range and the hackers "Go Away!!!"

    Well worth 20-30 minutes of your time to install this!

    My advice, be proactive as opposed to retroactive

  10. #10
    Member DrGreen's Avatar
    Join Date
    May 2004
    Posts
    44

    Default

    how can you find out there ip`s?
    and then lbock it

Similar Threads & Tags
Similar threads

  1. Server Compromised?
    By keykurt in forum New User Questions
    Replies: 2
    Last Post: 01-02-2007, 05:57 PM
  2. Server Compromised
    By iisnet in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 12-27-2004, 11:17 AM
  3. Server compromised or what?
    By mike_r in forum cPanel and WHM Discussions
    Replies: 18
    Last Post: 12-27-2004, 01:33 AM
  4. Our server was compromised
    By simonlee in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 10-23-2003, 07:20 PM
  5. My server is compromised?
    By avik in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 06-09-2003, 11:24 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube