Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 2 of 2
  1. #1
    Member
    Join Date
    May 2004
    Location
    Croatia
    Posts
    36

    Default hijacked server?

    Today I've received two emails from lfd stating:

    Subject: lfd on xxxxxx.xxxxxx.tld: Account modification alert
    =====================================================
    Time: Mon Feb 23 04:02:20 2009 +0100

    Reported Modifications:

    Account [root] password has changed
    =====================================================

    Subject:lfd on xxxxxx.xxxxxx.tld: SSH login alert for user root from 94.75.224.3 (EU/-/hosted-by.leaseweb.com)
    =====================================================
    Time: Mon Feb 23 04:02:29 2009 +0100
    IP: 94.75.224.3 (EU/-/hosted-by.leaseweb.com)
    Account: root
    Method: password authentication
    =====================================================

    I'm quite happy that I left screen running on the server, so that I could change back the root password, delete the new account (Reported by lfd - New account [plesk-root] has been created with uid:[0] gid:[0] login:[/root] shell:[/bin/sh]) and take a look at the damage:

    - syslog was stopped
    - nothing in /var/log
    - exim not running


    Any one else had this? a friend of mine had 3 servers with this same issue...
    Last edited by valkira; 02-23-2009 at 05:11 PM.

  2. #2
    Member rhenderson's Avatar
    Join Date
    Apr 2005
    Location
    Oklahoma
    Posts
    742

    Default

    So how did they get in, in the first place to be able to change the root password?
    Regards,
    Randy
    Affordable Web Hosting
    _________________________

Similar Threads & Tags
Similar threads

  1. Help! Mail Hijacked!
    By Hines in forum Security
    Replies: 3
    Last Post: 12-05-2010, 08:25 PM
  2. Domain root was "hijacked" by rails
    By Gerto in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 10-31-2008, 03:36 AM
  3. Contact Us form hijacked?
    By ramjet666 in forum New User Questions
    Replies: 6
    Last Post: 09-18-2005, 05:41 PM
  4. HELP! Somebody has hijacked my email system
    By sexy_guy in forum cPanel and WHM Discussions
    Replies: 13
    Last Post: 04-15-2003, 05:30 AM
  5. Change master name server from server 1 to server 4
    By Curt in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 10-16-2002, 01:45 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube