Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 4 of 4
  1. #1
    Member
    Join Date
    Mar 2007
    Posts
    43

    Default Just got hit by iframe hack on 5 boxes

    Not sure how since we have iframe rules in mod_security but this just happened to us on 5 boxes hosting in 3 different DC's. Every index file on every box replaced.

    What going on with this? Is there a v11 exploit? Must be. What a co incidence that all 5 boxes are hit in 3 different DC's. I understand 1 but 5?

    Unbelievable.

  2. #2
    Technical Product Specialist cPanelDavidG's Avatar
    Join Date
    Nov 2006
    Location
    Houston, TX
    Posts
    11,189
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Quote Originally Posted by gotroot View Post
    Not sure how since we have iframe rules in mod_security but this just happened to us on 5 boxes hosting in 3 different DC's. Every index file on every box replaced.

    What going on with this? Is there a v11 exploit? Must be. What a co incidence that all 5 boxes are hit in 3 different DC's. I understand 1 but 5?

    Unbelievable.
    There is a very long discussion about this at: http://forums.cpanel.net/showthread.php?p=333644

    We're unsure as to what precisely could be causing this and if it's even a cPanel-specific exploit (as there have been reports of this occurring on non-cPanel servers). If you or anyone else finds any evidence that it could be a cPanel security issue, please send relevant logs and commentary to security@cpanel.net

  3. #3
    Member
    Join Date
    Apr 2004
    Location
    Pakistan
    Posts
    9

    Default

    Hi

    one of my clients had a similar issue with iframe injection. I tried alot of different rules etc but of no vain. In the end, i just asked my client to remove a javascript from his index page and that solved the issue.

    I am not sure but it seems its related to java scripts or something.
    Salman Habib
    Kamyana Web Inc.
    http://www.kamyana.com

  4. #4
    Member rpmws's Avatar
    Join Date
    Aug 2001
    Location
    back woods of NC, USA
    Posts
    1,858

    Default

    Quote Originally Posted by gotroot View Post
    Not sure how since we have iframe rules in mod_security but this just happened to us on 5 boxes hosting in 3 different DC's. Every index file on every box replaced.

    What going on with this? Is there a v11 exploit? Must be. What a co incidence that all 5 boxes are hit in 3 different DC's. I understand 1 but 5?

    Unbelievable.

    is it possible that one of your resellers may be scattered with atleast one account on each of those boxes that are affected? do any of them have anything in common client wise?
    Just keeping my "eye" on things....
    R. Paul Mathews
    RPMWS - diehard cPanel Nutcase

Similar Threads & Tags
Similar threads

  1. Effective iframe/gumblar hack prevention?
    By Wallaby in forum Security
    Replies: 5
    Last Post: 04-30-2010, 11:36 AM
  2. How can you remove the iframe hack server wide?
    By DWHS.net in forum Security
    Replies: 8
    Last Post: 02-17-2010, 12:43 PM
  3. IFrame Hack - Cpanel Forced Update = Fixed?
    By contemptx in forum Security
    Replies: 4
    Last Post: 10-19-2009, 04:58 PM
  4. IFrame Hack - Cpanel Forced Update = Fixed?
    By contemptx in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 10-19-2009, 04:58 PM
  5. Solution For Iframe Java Script Hack
    By apscinsspl in forum Security
    Replies: 16
    Last Post: 08-14-2009, 06:58 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube