#16 (permalink)  
Old 07-09-2009, 08:24 PM
Registered User
 
Join Date: Jan 2004
Posts: 59
sphost
Quote:
Originally Posted by Spiral View Post
Now regarding your mentioning "you did all", I would like to sit down
with you and discuss exactly everything you can remember you did
originally as that will give me some insight as to your original configuration,
the areas you may have missed, and where you more likely got hacked,
and also would tell me what areas I may need to bring you more up to
speed on and get you to strengthen your understanding.

this was basically what i did http://forums.cpanel.net/f7/beginner...ver-30159.html
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #17 (permalink)  
Old 07-11-2009, 06:44 PM
Registered User
 
Join Date: Jul 2009
Posts: 3
ddmd is on a distinguished road
Maybe they did not found your root password, but another user pass and exploited some local vulnerability to get root?

Did you check your logs to see if they brute forced it? As far as monitoring, this is what I just posted on another thread:

I had a similar problem a while ago and used the ossec tool (open source) to find all offending packages. It has a nice rootkit/worm/exploits detection tool in there....

After that, I kept that running with Snort and modsecurity (all open source) to monitor my systems. I lately also found sucuri to remotely check if my sites have been defaced, blacklisted, etc.

links:
Welcome to the Home of OSSEC
ModSecurity: Open Source Web Application Firewall
Snort :: Home Page
Sucuri information security (BETA)
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #18 (permalink)  
Old 07-11-2009, 09:52 PM
Spiral's Avatar
Registered User
 
Join Date: Jun 2005
Location: Area 51
Posts: 1,501
Spiral is on a distinguished road
Quote:
Originally Posted by ddmd View Post
Maybe they did not found your root password, but another user pass and exploited some local vulnerability to get root?
Sphost was (and still - unfortunately) using an obsolete almost EOL version
of Fedora and the BIND server had originally not been patched or secured
in the original server configuration and the hackers had used an old exploit
to gain a root shell via a DNS attack. It would not have worked on most
servers today so they were actually lucky finding his server.

His server has now been fully secured and the vulnerable areas have
been manually patched and reconfigured so the previous vulnerabilities
no longer exist, the server fully hardened, and an extensive list of
defensive technologies have been put in place to help protect him
from future exploit and hacking attempts.

He's in a lot better shape now and has also been upgraded in the process
to Apache 2.2.11 along with SuHosin hardened SuPHP and other goodies
including well configured firewall and port scan monitors, root kit detectors,
intelligent traffic monitoring, self updating protection, and other fun stuff.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Server Hacked, please help encryption cPanel and WHM Discussions 15 02-20-2008 10:02 AM
server has been hacked aracrew cPanel and WHM Discussions 2 01-21-2008 06:55 PM
my Server Hacked linuxprovider cPanel and WHM Discussions 4 01-02-2007 05:09 PM
Server being hacked? ThaMATRiX cPanel and WHM Discussions 35 10-18-2004 09:05 PM
new server got hacked brumie cPanel and WHM Discussions 24 04-29-2004 01:00 PM


All times are GMT -5. The time now is 10:23 AM.


Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
© cPanel Inc