Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Results 1 to 5 of 5
  1. #1
    Member linuxprovider's Avatar
    Join Date
    Mar 2004
    Location
    egypt
    Posts
    28

    Default my Server Hacked

    Dear all

    Today while i run some commands like ls this error appeared

    segmentation falt

    any way the reason is my server's hacked

    now i reinstall it but my question

    How could my server hack while i have disabled Compilers for unprivileged users

    i admited that i have found cgi-telnet scripts but how could he used it to install rootkit

    plz help me to not falldown again

    Thanks
    Shafei Gad
    Linux System Administrator
    002 0123802231


  2. #2
    cPanel Partner NOC cPanel Partner NOC Badge AndyReed's Avatar
    Join Date
    May 2004
    Location
    Minneapolis, MN
    Posts
    2,223

    Default

    Quote Originally Posted by linuxprovider View Post
    How could my server hack while i have disabled Compilers for unprivileged users

    i admited that i have found cgi-telnet scripts but how could he used it to install rootkit
    Servers get hacked, at least in part, because they are running old, outdated, unpatched software with exploitable vulnerabilities.

    How to keep your web servers and web sites from being hacked?

    Keep your software updated — run the latest versions of Apache and Php. The same goes for MySQL and any other server side scripts. Php forums have been heavily targeted by hackers, not so much for running phishing sites, but it seems like the script kiddies like to deface them.

    Apache.org has Security Tips for Server Configuration at: http://www.w3.org/Security/Faq/

    W3.org has WWWSecurity FAQ at: http://www.w3.org/Security/Faq/

    I’ve seen a number of compromised sites being used to run exploits, both the WMF exploit and the createTextRange() exploits. Those sites were dropping trojan downloaders that contacted other servers to download malware including backdoors, key loggers, spam bots, password stealing trojans — the really nasty spyware, and in some cases, adware as well. It’s frustrating and sad, especially since it’s largely preventable. Please search these forums; there are many threads discussing HowTo secure your server. Or you can seek professional help to secure your server.
    Andy Reed
    RHCE and CCNA
    ServerTune.com

  3. #3
    Member linuxprovider's Avatar
    Join Date
    Mar 2004
    Location
    egypt
    Posts
    28

    Unhappy

    Many Thanks For Clearing that

    i have a question

    i have disable php ( shell scripts )

    but i am still can not disable perl ( cgi-telnet scripts )
    i have installed mod_security
    but still no hope plz give my help coz as you know if i am not fixing this problem my
    server will still facing dangers


    Thanks
    Shafei Gad
    Linux System Administrator
    002 0123802231


  4. #4
    Member
    Join Date
    Nov 2006
    Location
    Lithuania
    Posts
    122

    Default

    Quote Originally Posted by AndyReed View Post
    I’ve seen a number of compromised sites being used to run exploits, both the WMF exploit and the createTextRange() exploits.
    Can you please tell a little bit more about these? Would be great.
    Gytis Repecka aka Kelmas
    NFS Tuning / AutoNews.lt webmaster, IT journalist

  5. #5
    cPanel Partner NOC cPanel Partner NOC Badge AndyReed's Avatar
    Join Date
    May 2004
    Location
    Minneapolis, MN
    Posts
    2,223

    Default

    Quote Originally Posted by Kelmas View Post
    Can you please tell a little bit more about these? Would be great.
    WMF
    FAQ
    http://isc.sans.org/diary.php?storyid=994

    Linux/BSD still exposed to WMF exploit through WINE!
    http://blogs.zdnet.com/Ou/index.php?p=146

    TextRange() exploits
    http://www.computerworld.com/printth...110122,00.html

    You need a very good set of Mod Security rules to minimize and/or stop attacks on your server. In addition, install APF and BFD. I think every body should read WWWSecurity FAQ at: http://www.w3.org/Security/Faq/
    Andy Reed
    RHCE and CCNA
    ServerTune.com

Similar Threads & Tags
Similar threads

  1. my server is hacked
    By jcaldera in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 05-02-2009, 04:23 PM
  2. server has been hacked
    By aracrew in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 01-21-2008, 06:55 PM
  3. Server get hacked
    By vishwas in forum cPanel and WHM Discussions
    Replies: 5
    Last Post: 12-02-2005, 04:49 AM
  4. my server got hacked?
    By goodgbb in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 08-25-2005, 10:18 AM
  5. new server got hacked
    By brumie in forum cPanel and WHM Discussions
    Replies: 24
    Last Post: 04-29-2004, 01:00 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube