Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 5 of 5
  1. #1
    Member
    Join Date
    Jan 2005
    Location
    London, UK
    Posts
    187

    Default How to track down hacker IP

    Hi,
    One of my VPS servers was hacked.
    This person was able to:
    access my main cPanel account
    change my contact email to a Yahoo email
    change my server contact email to same Yahoo email
    create a new account owned by root user with another Yahoo email address

    I'm running WHM 10.8.0 cPanel 10.9.0-S80
    Fedora i686 - WHM X v3.1.0

    Have since changed my root password and the email addresses back, and deleted the new account.

    Asked my VPS provider if they could have a look around, and also track down the IP so we can block it.

    Amazingly, they said they cannot find the IP this person used.

    I am no expert in such matters, but find this a little difficult to swallow.
    Can anyone here help or know how?

    Lastly, any cPanel exploit know that let's this happen?
    Only thing I can think of is my password was 10 characters, and seem to remember cPanel had a problem with anything over 8?

    Appreciate any help.

    - Vince

  2. #2
    cPanel Product Evangelist Infopro's Avatar
    Join Date
    May 2003
    Location
    Pennsylvania
    Posts
    7,894
    cPanel/Enkompass Access Level

    Root Administrator

    Lightbulb

    Username 8, passwords can be much longer. Have you dug thru the log files or were they removed?
    Fav cPlinks this week: Blog - cPanel & WHM 11.32 we love it! | cPanel University study for it! | Attracta is coming! we want this!

  3. #3
    Member
    Join Date
    Jan 2005
    Location
    London, UK
    Posts
    187

    Default

    I am not capable to dig and identify which IP created the hacker account, that's why I asked my VPS provider.

    Thanks for reply,

    - Vince

  4. #4
    Member
    Join Date
    Mar 2006
    Posts
    1,215

    Default

    I would suggest asking them to reload a fresh template for you and get the vps
    secured.

    Provided someone obviously had access to the entire vps, you still may be
    compromised and a firewall against proxy or easily changeable addresses
    will stop no one.

    Its not surprising that address traces may not be found as they do have
    access to all your logs and the ability to edit at will.

    If your provider will not or refuses to reload your template to a fresh
    install, then seek another provider.

  5. #5
    Member
    Join Date
    Jan 2005
    Location
    London, UK
    Posts
    187

    Default

    jayh38,
    Thanks for your reply.
    Just to help me understand what you are suggesting, will the loading of a 'fresh template' affect existing data/accounts, so a bfull vps backup should be done beforehand?

    If you don't mind explaining, what exactly does this do?

    I was once told that a full backup was needed, and VPS rebuilt, then restore all the accounts. But surely, if the hacker has compromised and left scripts within any of the accounts, they would get in again and all was to no avail.

    Am I missing something?

    Many thanks,

    - Vince

    P.S. I forgot to mention that during the compromise the VPS was still using version 2.4.x kernel, but coincidently I was migrated to a VPS with 2.6.9-023stab033.9-enterprise just a few hours after. I believe this is a more secure kernel, and maybe due to migration I already have a 'fresh template' now anyway?
    Last edited by mambovince; 12-21-2006 at 12:59 PM. Reason: Added more info

Similar Threads & Tags
Similar threads

  1. Hacker?? Need help
    By ChipW in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 06-12-2007, 02:42 AM
  2. is this a hacker ?
    By gordypordy in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 02-01-2006, 12:07 PM
  3. Crazy hacker.......
    By amal in forum cPanel and WHM Discussions
    Replies: 14
    Last Post: 05-09-2005, 10:58 PM
  4. how to track hacker?
    By 10101 in forum cPanel and WHM Discussions
    Replies: 7
    Last Post: 06-15-2004, 08:27 AM
  5. Is this a hacker??
    By hjnet in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 05-31-2002, 06:17 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube