Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 5 of 5
  1. #1
    Member
    Join Date
    Sep 2005
    Posts
    50

    Default I think my server is hacking other servers...

    Hey, my cPanel server keeps making FTP connections to other servers and brute forcing passwords... I've gotten a few complaints. Right now un netstat it shows several ftp data streams going to other servers. how can I check to see where these originate from? I dont see anyone logged in doing it, and I'm not falling victim to a rootkit (according to rkhunter). Any suggestions?

    Thanks!

    Nick

  2. #2
    Registered User
    Join Date
    Jan 2008
    Posts
    3

    Default

    PHP could be script doing it.

    2 ways i can think of tracing it.

    1.) turn off remote FTP connection in php.ini and check error logs see who spamming.

    2.) check top and see what domains are using the most CPU Time and then check them accounts and there code.

  3. #3
    Member
    Join Date
    Sep 2005
    Posts
    50

    Default

    I will take a look, thanks!

  4. #4
    Member
    Join Date
    Sep 2004
    Location
    inside a catfish
    Posts
    963
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    If you have a firewall running on that server, block OUTBOUND TCP 21 so that your server can't contact other FTP servers on their default port. That will stop the reports.

    But that is in no way a fix to your problem. You've obviously got a script on there somewhere that is doing this - It could be a localized exploit of a user account or it could be a full root server compromise. But you have to stop the activity from affecting others first.

    If you have console access to the server, you should take it off the network and start looking into logs, running processes, etc - and don't reboot it before you get a chance to look, because any useful evidence of a hack that may be useful could disappear after a reboot and other things.

    As root: lsof -n|grep TCP|grep ftp

    You should be able to see what process is running that is connecting to remote FTP servers.

    Mike

  5. #5
    Member
    Join Date
    Sep 2005
    Posts
    50

    Default

    Stopping php from being able to send ftp commands stopped it, so now I just have to track down the offender.

Similar Threads & Tags
Similar threads

  1. How does Hacking take place on Cpanel server?
    By whwrobert in forum Security
    Replies: 31
    Last Post: 11-26-2011, 11:28 PM
  2. Hacking
    By mahdionline in forum cPanel and WHM Discussions
    Replies: 13
    Last Post: 10-12-2004, 12:11 PM
  3. Hacking
    By sujai in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 02-09-2004, 06:44 AM
  4. hacking help
    By shann in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 11-30-2002, 04:46 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube