Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 7 of 7
  1. #1
    Member Roy@ENHOST's Avatar
    Join Date
    Mar 2002
    Location
    Los Angeles California
    Posts
    495

    Default hackers visits every 2 days. How to trap him?

    Hi guys,

    One of my server's security was compromised.
    And the hacker visits every 2 days.
    What can I install to trap and track him?
    = = = = = = = = = = = = = = = = = =
    Cpanel XP Evolution (Add DOZENS of functions to your Cpanel NOW!!!) - 21 Languages, User Friendly Interface, Feature Enabled, Highly Customizable, Create Popup Once window, Language Aware, Flash Tutorials, Theme Changer,Integration with Modernbill,WHM AutoPilot,ClientExec,LPanel&WHOISCart

  2. #2
    Member sawbuck's Avatar
    Join Date
    Jan 2004
    Posts
    1,313
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Logcheck might be something to take a look at.
    http://linux.maruhn.com/sec/logcheck.html

  3. #3
    Member Roy@ENHOST's Avatar
    Join Date
    Mar 2002
    Location
    Los Angeles California
    Posts
    495

    Default

    Hi guys,

    I went to FTP section and downloaded the raw FTP log.
    I nabbed that fella.

    212.174.89.155 - - [25/Jun/2004:06:51:20 -0400] "GET / HTTP/1.1" 200 660 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; 118K501TUR)"

    Went to http://www.ip2location.com/free.asp to check out the IP:212.174.89.155

    "212.174.89.155 TR TURKEY"
    Got him!

    Then I used IP tables to block the whole class C IP.
    iptables -I INPUT -s 212.174.89.0/24 -j DROP

    Am I safe to say he can't break in? Can he use proxy to get in?
    = = = = = = = = = = = = = = = = = =
    Cpanel XP Evolution (Add DOZENS of functions to your Cpanel NOW!!!) - 21 Languages, User Friendly Interface, Feature Enabled, Highly Customizable, Create Popup Once window, Language Aware, Flash Tutorials, Theme Changer,Integration with Modernbill,WHM AutoPilot,ClientExec,LPanel&WHOISCart

  4. #4
    Member
    Join Date
    Oct 2003
    Posts
    1,020

    Default

    Originally posted by Roy@ENHOST
    Am I safe to say he can't break in? Can he use proxy to get in?
    If all you did was ban his IP (or the class C range of it) using iptables, then I would say yes.

  5. #5
    Member Roy@ENHOST's Avatar
    Join Date
    Mar 2002
    Location
    Los Angeles California
    Posts
    495

    Default

    Through Proxy?

    Originally posted by SarcNBit
    If all you did was ban his IP (or the class C range of it) using iptables, then I would say yes.
    = = = = = = = = = = = = = = = = = =
    Cpanel XP Evolution (Add DOZENS of functions to your Cpanel NOW!!!) - 21 Languages, User Friendly Interface, Feature Enabled, Highly Customizable, Create Popup Once window, Language Aware, Flash Tutorials, Theme Changer,Integration with Modernbill,WHM AutoPilot,ClientExec,LPanel&WHOISCart

  6. #6
    Member
    Join Date
    Oct 2003
    Posts
    1,020

    Default

    Sure. It also is not that difficult to obtain an IP on a different class C subnet. Most ISPs I have dealt with switch customers between two or three different subnets regularly. Keep in mind, that you could ban all Turkish IPs, but that would not eliminate the possibility of the person using a shell account and simply using an account originating in another country.

    What was this person doing on your box? How was your server compromised? Banning the hackers IP is OK, but eliminating the source of the vulnerability is better.

  7. #7
    Member
    Join Date
    May 2004
    Posts
    15

    Default

    if i was a hacker , i will never see it a problem for a victim to block my ip

    Hackers can log in to your server from another another server for example

    In my opinion eliminating the source of the vulnerability is not just better .... it is a must !!!!

Similar Threads & Tags
Similar threads

  1. Using the Universal Password Trap
    By fusephase in forum cPanel Developers
    Replies: 10
    Last Post: 08-24-2011, 11:14 AM
  2. cPanel Universal Password Trap Problem
    By mtbwacko in forum cPanel Developers
    Replies: 0
    Last Post: 11-10-2009, 06:11 PM
  3. Ignore My Own Visits
    By lbarber in forum New User Questions
    Replies: 0
    Last Post: 09-22-2007, 10:07 AM
  4. stop logs of boxtrapper spam trap feature
    By lawrence.dcosta in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 02-01-2007, 12:38 AM
  5. 4000 visits
    By Wicked in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 08-18-2006, 03:05 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube