Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 14 of 14
  1. #1
    Member
    Join Date
    Mar 2007
    Posts
    7

    Default Hacker within cPanel

    Hi!

    The other day I monitored a hacker while he/she was trying to get access to my networks FTP service. 37376 attempts were made before I decided to permanently block the IP number from which the attack was launched.

    Time of the attack: Around Thu Mar 15 07:15:00 CET 2007
    IP: 208.116.56.10 (cpanelx9.fuitadnet.com)

    I also reported this incident to the ISP, absue@fuitadnet.com.

    Just wanted to let you know.

    Kind regards,
    Ted Lyngmo

  2. #2
    Member
    Join Date
    Mar 2002
    Posts
    248

    Default

    Ted,

    install APF with BFD. This will block him out once he reached 3-5 failed ftp login.

  3. #3
    Member
    Join Date
    Mar 2007
    Posts
    7

    Default

    Thanks, but that won't be necessary. The interesting thing is that the attack was lauched from one of cPanels servers.

  4. #4
    Member
    Join Date
    Mar 2002
    Posts
    248

    Default

    probably some automated script.

  5. #5
    Member
    Join Date
    Jul 2005
    Posts
    23

    Default

    Are You realy sure, as I see it it came from fuitadnet.com with the hostname cpanelx9.fuitadnet.com and that is not the same.

  6. #6
    Member
    Join Date
    Mar 2007
    Posts
    7

    Default

    You might be right.

    It seems like the address (http://208.116.56.10) actually points to an installation of cPanel.

  7. #7
    Member
    Join Date
    Mar 2007
    Posts
    7

    Default

    Quote Originally Posted by gundamz View Post
    probably some automated script.
    No doubt

    It's worrying that scriptkids have access to an ISPs servers.

  8. #8
    Member
    Join Date
    Sep 2003
    Posts
    165

    Default

    That's not cpanel servers, it's a server with cpanel installed. There is a difference.
    search is your friend!
    cPanel Specialist Certification::Technical

  9. #9
    Member
    Join Date
    Mar 2007
    Posts
    7

    Default

    Quote Originally Posted by carluk View Post
    it's a server with cpanel installed.
    That exactly what I wrote Today, 02:33 PM.

  10. #10
    Member
    Join Date
    Sep 2003
    Posts
    165

    Default

    Quote Originally Posted by dev_null View Post
    Thanks, but that won't be necessary. The interesting thing is that the attack was lauched from one of cPanels servers.
    You might have underlined "installation of cpanel" in a post after, but you still said the above. I presume it was simply an English language mistake?
    search is your friend!
    cPanel Specialist Certification::Technical

  11. #11
    Member
    Join Date
    Jul 2002
    Location
    Canada
    Posts
    675

    Default

    Brute force attacks are common on FTP/SSH. Consider CSF because it has a realtime daemon that monitors for invalid logins. BFD is based on a cronjob so an attack can be hiting your server thousands of times before they're blocked.
    Upload Guardian 2.0 - Sign up for our early beta
    ServerProgress - Server security, consulting and assistance

  12. #12
    Member
    Join Date
    Mar 2007
    Posts
    7

    Default

    Quote Originally Posted by carluk View Post
    You might have underlined "installation of cpanel" in a post after
    but you still said the above. I presume it was simply an English language mistake?
    Nope. In the earlier posts I assumed it was one of cPanels servers, but after some contemplation I was prepared to agree with morfargekko that pointed out the same thing as you did.

    In the message after I also expressed my concerns about scriptkids having access to the ISPs [or webhosts], and not cPanels, servers.

    Thanks anyway

  13. #13
    Member
    Join Date
    Mar 2007
    Posts
    7

    Default

    Quote Originally Posted by ramprage View Post
    Brute force attacks are common on FTP/SSH. Consider CSF because it has a realtime daemon that monitors for invalid logins. BFD is based on a cronjob so an attack can be hiting your server thousands of times before they're blocked.
    I dont think APF or CSF will be the solution for me since I've got a standalone firewall/router/switch in which I do all my blocking. So far I've done it manually, but the amount of attacks seems to have increased lately so I might create a realtime daemon that parses the logs and then connects to the F/W and updates the table of blocked IP addresses. Maybe I can reuse some of CSFs parsers though. Thanks for the hint.

  14. #14
    Member
    Join Date
    Sep 2003
    Posts
    658

    Default

    You may want to contact the offending IP's NOC.

    OrgName: FortressITX
    OrgID: FORTR-5
    Address: 100 Delawanna Ave
    City: Clifton
    StateProv: NJ
    PostalCode: 07014
    Country: US

    ReferralServer: rwhois://rwhois.fortressitx.com:4443

    NetRange: 208.116.0.0 - 208.116.63.255
    CIDR: 208.116.0.0/18
    NetName: FORTRESSITX
    NetHandle: NET-208-116-0-0-1
    Parent: NET-208-0-0-0-0
    NetType: Direct Allocation
    NameServer: NS1.PWEBTECH.COM
    NameServer: NS2.PWEBTECH.COM
    Comment:
    RegDate: 2006-04-19
    Updated: 2006-05-17

    OrgAbuseHandle: FIAD-ARIN
    OrgAbuseName: Fortress ITX Abuse Dept
    OrgAbusePhone: +1-973-572-1070
    OrgAbuseEmail: abuse@fortressitx.com

    OrgTechHandle: FIH2-ARIN
    OrgTechName: Fortress ITX Hostmaster
    OrgTechPhone: +1-973-572-1070
    OrgTechEmail: hostmaster@fortressitx.com

    # ARIN WHOIS database, last updated 2007-03-17 19:10
    # Enter ? for additional hints on searching ARIN's WHOIS database.

Similar Threads & Tags
Similar threads

  1. Hacker Safe and cPanel?
    By lostmind in forum Security
    Replies: 3
    Last Post: 07-27-2008, 12:02 PM
  2. Hacker Safe and cPanel?
    By lostmind in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 07-27-2008, 12:02 PM
  3. Help tracking down a hacker .. where to view Cpanel login IP's?
    By listenmirndt in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 08-02-2007, 08:41 AM
  4. Hacker?? Need help
    By ChipW in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 06-12-2007, 02:42 AM
  5. Is this a hacker??
    By hjnet in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 05-31-2002, 06:17 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube