Results 1 to 5 of 5

Thread: My server is compromised?

  1. #1
    Member
    Join Date
    May 2003
    Posts
    5

    Default My server is compromised?

    In the list of processes of the server, I have seen these processes:
    ------------------
    root 27596 0.0 0.0 2072 920 ? S 16:27 0:00 xinetd -stayalive -pidfile /var/run/xinetd.pid
    nobody 28563 0.0 0.0 1380 376 ? S 16:32 0:00 ./tty
    nobody 28564 0.0 0.0 2100 1080 ttyp0 S 16:32 0:00 \_ sh -i
    -------------------

    In my terminal program (SSH) I have received the message of such kind:

    ==============
    Broadcast.............................. (i remember only it)

    If you see this message, write to me to this address: "email"
    ===============

    I have written to him. He has answered, that my server is hacked and also he can remove vulnerability, if I shall open to him an account.



    What you can to me advise?

    cPanel.net Support Ticket Number:

  2. #2
    Member casey's Avatar
    Join Date
    Jan 2003
    Location
    If there is trouble, it will find me
    Posts
    2,336

    Default

    Well don't give him an account, whatever you do!

    cPanel.net Support Ticket Number:

  3. #3
    cPanel Partner NOC cPanel Partner NOC Badge DWHS.net's Avatar
    Join Date
    Jul 2002
    Location
    LA, Costa RIca
    Posts
    1,385

    Default

    I would ask him how he hacked it and let us know

    Maybe offer a small price $20 for him to show you what he did. Then you can get his information from the payment method.

    He's not too bad to contact you, usually they just look for cc's and delete everything. So I have been told .

    Sorry about your mis-fortune and hope all turns out well.

    I would back up the server and move everything to a new server ASAP.

    cPanel.net Support Ticket Number:

  4. #4
    Member
    Join Date
    May 2003
    Posts
    5

    Default

    Yes, I shall not open for him an account.

    I nevertheless think there is a vulnerability.
    The remote user can run commands with the rights nobody.

    cPanel.net Support Ticket Number:

  5. #5
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Feb 2003
    Location
    Norman, OK
    Posts
    81

    Default

    Make sure noone on your server is running an outdated version of the PHP version of YaBB. (YaBBSE)

    There's a bug that allows users to upload scripts & compile & execute them as user nobody...

    Regards,
    Matt

    cPanel.net Support Ticket Number:

Similar Threads

  1. Server Compromised?
    By keykurt in forum New User Questions
    Replies: 2
    Last Post: 01-02-2007, 04:57 PM
  2. Server Compromised
    By iisnet in forum cPanel & WHM Discussions
    Replies: 4
    Last Post: 12-27-2004, 10:17 AM
  3. Server compromised or what?
    By mike_r in forum cPanel & WHM Discussions
    Replies: 18
    Last Post: 12-27-2004, 12:33 AM
  4. Compromised Server
    By mygregory in forum cPanel & WHM Discussions
    Replies: 9
    Last Post: 05-31-2004, 05:39 AM
  5. Our server was compromised
    By simonlee in forum cPanel & WHM Discussions
    Replies: 4
    Last Post: 10-23-2003, 06:20 PM