Results 1 to 6 of 6

Thread: phpnuke exploit protection

  1. #1
    Member mahdionline's Avatar
    Join Date
    Oct 2003
    Posts
    127

    Unhappy phpnuke exploit protection

    Hi

    I have a DREADFUL problem with some of phpnuke that hosted on my server. Ev1 abuse team send me a mail about " PHP-Nuke Exploit " . they notice me that a spammer use of a phpnuke site to do his work. and send many spam in every month.

    now I have 3 question :

    1- how can i discover that which account on server use phpnuke ?
    ( I see in mysql database list that we have about 200 phpnuke on our server)

    2- how can I find out that which of account is victim of that spammer ?

    3- how can I filter all phpnuke ?( can I do this with mod_security) ?

    Regard
    Mahdionline

  2. #2
    Member
    Join Date
    Aug 2003
    Location
    United Kingdom
    Posts
    186

    Default

    Under WHM in Addon Modules, you can install the addonupdates module - this adds another option in WHM called 'Addon Script Manager'. This can be used to find PHPNuke installs, but I am not sure if it only finds versions of PHPNUke that have been installed via cPanel.

  3. #3
    Member PPNSteve's Avatar
    Join Date
    Mar 2003
    Location
    Somewhere in Ilex Forest
    Posts
    333
    cPanel/WHM Access Level

    Root Administrator

    Default

    we are currently NOT reccomending to use PHPNuke to our clients.. also if you can, have them shut off the email function in nuke.

    i'm sure there are other solutions as well..
    Steve H.
    --------------
    1-GB.NET
    Domain Names

  4. #4
    Member mahdionline's Avatar
    Join Date
    Oct 2003
    Posts
    127

    Default

    Quote Originally Posted by PPNSteve
    we are currently NOT reccomending to use PHPNuke to our clients.. also if you can, have them shut off the email function in nuke.

    i'm sure there are other solutions as well..
    thanks but how can I filter or shut off outgoing mail of phpnuke sites ?
    a note : we have near to 200 phpnuke on our server. and I donot know , which account is the victim of spammer .! !

    please help me !
    Mahdionline

  5. #5
    cPanel Partner NOC cPanel Partner NOC Badge gorilla's Avatar
    Join Date
    Feb 2004
    Location
    Sydney / Australia
    Posts
    738

    Default

    have u installed PHP suEXEC ? find it in WHM/software/update apache
    u can trace the spammer with that :

    Have u enabled SMTP Tweak ? in Tweak Security
    This SMTP tweak will prevent users from bypassing the mail server to send mail (This is a common practice used by spammers). It will only allow the MTA (mail transport agent), mailman, and root to connect to remote SMTP servers.

    And i guess you could Prevent the user 'nobody' from sending out mail to remote addresses (php and cgi scripts generally run as nobody if you are not using phpsuexec and suexec respectively.) u find that in WHM/Tweak Settings

    and i guess u could tell all ur customers to protect their nuke install with Sentinel
    Last edited by gorilla; 01-20-2005 at 10:32 AM.

  6. #6
    Member mahdionline's Avatar
    Join Date
    Oct 2003
    Posts
    127

    Default

    Thanks ! I do that and now I should wait for the future and . . .
    Mahdionline

Similar Threads

  1. mod_userdir Protection - Exclude Protection Not Working
    By PDM in forum cPanel & WHM Discussions
    Replies: 2
    Last Post: 07-05-2008, 07:10 PM
  2. PHPNuke
    By 2tone in forum cPanel Developers
    Replies: 7
    Last Post: 06-02-2006, 07:00 AM
  3. PHPNuke
    By Arvand in forum cPanel & WHM Discussions
    Replies: 2
    Last Post: 08-24-2003, 06:15 PM
  4. phpNuke
    By gilharvey in forum cPanel & WHM Discussions
    Replies: 1
    Last Post: 07-01-2003, 11:22 AM