Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Results 1 to 4 of 4
  1. #1
    Registered User
    Join Date
    Mar 2006
    Posts
    3

    Default Hacker?? Need help

    I have an issue with one customer that claims that he was hacked.... Entire site deleted... This is a game clan using PHPNuke....

    The problem now is that the MYSQL server is continually going down which is causing server wide problems.... The owner of this site found a chat log of someone saying they are using mysql exploits....

    My question is, how do I find out if this is what is bringing me down.... What do I look for in the logs and what logs do I even look in?

    I am a total n00b to this kind of thing...

    Any help would be great.... I took this customer's site down for the moment to see if the problem stops and have changed my server and mysql root passwords..

    WHM 10.8.0 cPanel 10.9.0-S13517
    RedHat Enterprise 3 i686 - WHM X v3.1.0

    ConfigServer Security & Firewall - csf v2.51

  2. #2
    cPanel Product Evangelist Infopro's Avatar
    Join Date
    May 2003
    Location
    Pennsylvania
    Posts
    7,165
    cPanel/Enkompass Access Level

    Root Administrator

    Post

    Quote Originally Posted by ChipW View Post

    Any help would be great.... I took this customer's site down for the moment to see if the problem stops and have changed my server and mysql root passwords..

    WHM 10.8.0 cPanel 10.9.0-S13517
    RedHat Enterprise 3 i686 - WHM X v3.1.0

    ConfigServer Security & Firewall - csf v2.51

    That's a good start of course. Another step might be to not allow them on your server to begin with. You wouldn't be the first server to ban the nukes.

    This is a great tool to have installed. http://www.logview.org/
    Giving you access to lots of logs to poke thru real easy.

    Keep the site suspended till you figure it out.

  3. #3
    Member brianoz's Avatar
    Join Date
    Mar 2004
    Location
    Melbourne, Australia
    Posts
    1,093
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Have you got remote access to mysql allowed? If so, I'd disable it. Also recommend upgrading csf to be the latest with shell command "csf -u" or from the WHM interface.

    phpnuke has a lousy security reputation, from what I hear ...

  4. #4
    Member nilesh_kolte's Avatar
    Join Date
    Apr 2006
    Posts
    66

    Default

    Hello,

    Check the following URL..

    http://forums.cpanel.net/showthread....ghlight=cpwrap

    This will fix.
    ~~~ Cool Buddy ~~~

Similar Threads & Tags
Similar threads

  1. I have been hacker attack
    By caykoylu in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 12-01-2006, 08:47 PM
  2. is this a hacker ?
    By gordypordy in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 02-01-2006, 01:07 PM
  3. Crazy hacker.......
    By amal in forum cPanel and WHM Discussions
    Replies: 14
    Last Post: 05-09-2005, 11:58 PM
  4. hacker report
    By mahdionline in forum cPanel and WHM Discussions
    Replies: 5
    Last Post: 10-17-2004, 05:18 PM
  5. Is this a hacker??
    By hjnet in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 05-31-2002, 07:17 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube