#1 (permalink)  
Old 06-08-2007, 09:36 AM
Registered User
 
Join Date: Mar 2006
Posts: 3
ChipW is on a distinguished road
Hacker?? Need help

I have an issue with one customer that claims that he was hacked.... Entire site deleted... This is a game clan using PHPNuke....

The problem now is that the MYSQL server is continually going down which is causing server wide problems.... The owner of this site found a chat log of someone saying they are using mysql exploits....

My question is, how do I find out if this is what is bringing me down.... What do I look for in the logs and what logs do I even look in?

I am a total n00b to this kind of thing...

Any help would be great.... I took this customer's site down for the moment to see if the problem stops and have changed my server and mysql root passwords..

WHM 10.8.0 cPanel 10.9.0-S13517
RedHat Enterprise 3 i686 - WHM X v3.1.0

ConfigServer Security & Firewall - csf v2.51
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 06-08-2007, 11:39 AM
Infopro's Avatar
Forum Moderator
 
Join Date: May 2003
Location: Pennsylvania
Posts: 3,498
Infopro is on a distinguished road
Post

Quote:
Originally Posted by ChipW View Post

Any help would be great.... I took this customer's site down for the moment to see if the problem stops and have changed my server and mysql root passwords..

WHM 10.8.0 cPanel 10.9.0-S13517
RedHat Enterprise 3 i686 - WHM X v3.1.0

ConfigServer Security & Firewall - csf v2.51

That's a good start of course. Another step might be to not allow them on your server to begin with. You wouldn't be the first server to ban the nukes.

This is a great tool to have installed. http://www.logview.org/
Giving you access to lots of logs to poke thru real easy.

Keep the site suspended till you figure it out.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 06-08-2007, 12:30 PM
brianoz's Avatar
Registered User
 
Join Date: Mar 2004
Location: Melbourne, Australia
Posts: 984
brianoz is on a distinguished road
Have you got remote access to mysql allowed? If so, I'd disable it. Also recommend upgrading csf to be the latest with shell command "csf -u" or from the WHM interface.

phpnuke has a lousy security reputation, from what I hear ...
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 06-12-2007, 03:42 AM
nilesh_kolte's Avatar
Registered User
 
Join Date: Apr 2006
Posts: 41
nilesh_kolte is on a distinguished road
Hello,

Check the following URL..

cpwrap root exploit

This will fix.
__________________
~~~ Cool Buddy ~~~
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 04:02 PM.


Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
© cPanel Inc