Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 4 of 4
  1. #1
    Registered User
    Join Date
    Feb 2006
    Posts
    2

    Default Hack attempts from cPanel

    Hi,

    According to my logs, my server had several hack attempts coming from a cPanel server (63.247.79.189). I would like to know whom I should contact to resolve this situation (and if possible take sanctions against the account owner).

    Regards.

  2. #2
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    May 2005
    Posts
    56

    Default

    I just did a little digging on that IP for you and although there is no PTR reverse map on that IP if you open a manual telnet connection to port 25 it identifies itself as:

    220-cpanel.cihans.com ESMTP Exim 4.52 #1 Thu, 09 Feb 2006 16:14:10 +0200

    the improtant bit there is:

    cpanel.cihans.com

    The whois for cihans.com is as follows:

    Registrant:
    qweqwe (CIHANS-COM-DOM)
    qweqwe
    qweqwe, 123123
    Turkey
    90.123123123
    90.123456
    cihan94@hotmail.com

    Domain Name: CIHANS.COM

    Administrative Contact:
    asdfadsf cihan94@hotmail.com
    adsfdasf
    asdfffdasf, 21312331
    Turkey
    90.12321312
    Fax- 90.123123123

    Technical Contact, Zone Contact:
    adsfdsafds cihan94@hotmail.com
    sdfsdfsdfd
    sdfsdfdsf, 3211234
    Turkey
    90.321432423
    Fax- 90.123456

    Record last updated on 02-Feb-2006.
    Record expires on 17-Jan-2007.
    Record created on 17-Jan-2005.

    Domain servers in listed order:

    Name Server: ns1.cihans.com
    Name Server: ns2.cihans.com

    You should try the email address but I wouldn't hold out too much hope there.

    The other option is to complain to the IP block owner as they can remove connectivity to the server and usuall get a result. The IP is registered to:

    OrgName: Global Net Access, LLC
    OrgID: GNAL-2
    Address: 55 Marietta St, NW
    Address: Suite 1720
    City: Atlanta
    StateProv: GA
    PostalCode: 30303
    Country: US

    ReferralServer: rwhois://rwhois.gnax.net:4321

    NetRange: 63.247.64.0 - 63.247.95.255
    CIDR: 63.247.64.0/19
    NetName: GNAXNET
    NetHandle: NET-63-247-64-0-1
    Parent: NET-63-0-0-0-0
    NetType: Direct Allocation
    NameServer: DNS1.GNAX.NET
    NameServer: DNS2.GNAX.NET
    Comment: Comment: ADDRESSES WITHIN THIS BLOCK ARE NON-PORTABLE
    Comment: Comment: ********************************************
    Comment: Comment: Reassignment information for this block is
    Comment: Comment: available at rwhois.gnax.net port 4321
    Comment: Comment: ********************************************
    RegDate: 2003-04-11
    Updated: 2004-02-06

    OrgAbuseHandle: ABUSE745-ARIN
    OrgAbuseName: Abuse
    OrgAbusePhone: +1-404-230-9150
    OrgAbuseEmail: abuse@gnax.net

    OrgTechHandle: ENGIN7-ARIN
    OrgTechName: Engineering
    OrgTechPhone: +1-404-230-9150
    OrgTechEmail: engineering@gnax.net

    # ARIN WHOIS database, last updated 2006-02-08 19:10
    # Enter ? for additional hints on searching ARIN's WHOIS database.

    They, abuse@gnax.ne,t look like a much better bet to talk to about this and get something done.

  3. #3
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    Nice bit of investigative work
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  4. #4
    Registered User
    Join Date
    Feb 2006
    Posts
    2

    Default

    Thanks for these details. I'm gonna check gnax.net.

Similar Threads & Tags
Similar threads

  1. Preventing annoying/lame hack attempts
    By santrix in forum Security
    Replies: 7
    Last Post: 09-05-2009, 11:52 AM
  2. Preventing annoying/lame hack attempts
    By santrix in forum cPanel and WHM Discussions
    Replies: 7
    Last Post: 09-05-2009, 11:52 AM
  3. Hack attempts to DNS?
    By jols in forum Security
    Replies: 5
    Last Post: 07-18-2008, 02:36 PM
  4. Hack attempts to DNS?
    By jols in forum cPanel and WHM Discussions
    Replies: 5
    Last Post: 07-18-2008, 02:36 PM
  5. cpanel hack attempts through resetpass script
    By dezignguy in forum cPanel and WHM Discussions
    Replies: 7
    Last Post: 03-18-2005, 09:37 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube