Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Page 1 of 2 1 2 LastLast
Results 1 to 15 of 22
  1. #1
    Member
    Join Date
    Nov 2002
    Location
    Delaware
    Posts
    67

    Default **** Possible Major Cpanel Security Flaw - All Cpanel Servers Open To Be Hacked ****

    Somehow, Hackers have defaced every home pge for our clients on all of our cpanel servers. Our dataceter secured all of the servers and they have a high rate of success at this so there may possibly be a vulnerability within Cpanel that can allow hackers to change every main web page..

    Here is a client domain which has been hacked.

    http://all-about-pregnancy.com/

    regards,
    Chris

  2. #2
    Member
    Join Date
    Mar 2003
    Posts
    863

    Default

    You running Kernel 2.4.18-14? I can see why you were rooted. You should be up to Kernel 2.4.18-27.7.x and anything less then this is very VULN to root exploits. Not necessarily a cPanel exploit. You should look into upgrading your Kernel first then clean up your box. Hopefully its fixable but unlikely.
    Last edited by sexy_guy; 05-07-2003 at 02:18 PM.

  3. #3
    Member
    Join Date
    Oct 2002
    Posts
    751

    Default

    How do you know this is a CPanel security issue though?
    Were you running secure kernels on all your servers, was all other software up to date?

    How did the datacenter 'secure' your servers?

  4. #4
    Member
    Join Date
    Mar 2003
    Posts
    863

    Default

    Originally posted by jamesbond
    How do you know this is a CPanel security issue though?
    Were you running secure kernels on all your servers, was all other software up to date?

    How did the datacenter 'secure' your servers?
    If you go to this site you will see the version of the Kernel his running, Kernel 2.4.18-14. Its displayed very prominently on the site for all to see. HINT HINT! Why do you think they displayed it? Insecure kernel exploit is what this is. And if you have questions howabout emailing the guy.

  5. #5
    Member
    Join Date
    Oct 2002
    Posts
    751

    Default

    Originally posted by sexy_guy
    If you go to this site you will see the version of the Kernel his running, Kernel 2.4.18-14. Its displayed very prominently on the site for all to see. HINT HINT! Why do you think they displayed it? Insecure kernel exploit is what this is. And if you have questions howabout emailing the guy.
    Calm down sexy_guy, you get worked up so easily in almost every thread I see you posting.
    I didn't see your post until I submitted mine, if I had then I wouldn't have posted in this thread, since you already looked into it.

    And why would I have to e-mail him if I have questions.
    Is this a new policy on this forum :
    Got any questions? Don't post , e-mail instead!

  6. #6
    Member
    Join Date
    Nov 2002
    Location
    Delaware
    Posts
    67

    Default

    The post was only to make people aware of the issue.

    Spammers were getting email through formmail but the hackers or whomever replaced every home page didn't get into the server to do this.

    This server just did go online so it's just luck I guess that they found a way get to the server.

    Regards,
    Chris

  7. #7
    Member
    Join Date
    Mar 2003
    Posts
    863

    Default

    Originally posted by jamesbond
    And why would I have to e-mail him if I have questions.
    Is this a new policy on this forum :
    Got any questions? Don't post , e-mail instead!
    Im not worked up at all, i was stating what i saw. I didnt ask you to email anyone. I said if the site owner, the one who got hacked emailed the hacker at the email listed on the hacked site then usually he will tell you how he got root.

  8. #8
    Member
    Join Date
    Mar 2003
    Posts
    863

    Default

    Originally posted by sitehostz
    The post was only to make people aware of the issue.

    Spammers were getting email through formmail but the hackers or whomever replaced every home page didn't get into the server to do this.

    This server just did go online so it's just luck I guess that they found a way get to the server.

    Regards,
    Chris
    What dont you email him? He will tell you exactly how he got in.

    You should probably consider installing tripwire as well, on a clean box that is.
    Last edited by sexy_guy; 05-07-2003 at 02:44 PM.

  9. #9
    Member
    Join Date
    Oct 2002
    Posts
    751

    Default

    Originally posted by sexy_guy
    Im not worked up at all, i was stating what i saw. I didnt ask you to email anyone. I said if the site owner, the one who got hacked emailed the hacker at the email listed on the hacked site then usually he will tell you how he got root.
    Well since you quoted my post I assumed you were talking to me. My apologies

  10. #10
    Member
    Join Date
    Mar 2003
    Posts
    863

    Default

    Originally posted by jamesbond
    Well since you quoted my post I assumed you were talking to me. My apologies
    I quoted you by accident, im sorry too.

  11. #11
    Member
    Join Date
    Sep 2001
    Posts
    189

    Default

    Originally posted by sitehostz
    The post was only to make people aware of the issue.

    Spammers were getting email through formmail but the hackers or whomever replaced every home page didn't get into the server to do this.

    This server just did go online so it's just luck I guess that they found a way get to the server.

    Regards,
    Chris
    If your kernel <2.4.20 with ptrace patch, your server can be hacked as 1-2-3 It is easy to do!
    Alex Andreyev,
    http://www.WHost.INFO - NEW web hosting directory.

  12. #12
    Member
    Join Date
    Nov 2002
    Location
    Delaware
    Posts
    67

    Default

    Well, I hope they had fun advertising... I guess the joke was on us this time...

    http://www.zone-h.org/en/defacements/view/id=260770/

    http://www.zone-h.org/en/defacements

    The images used on our defaced clients web sites came from there.
    http://www.zone-h.org/defaced/2003/0...co.uk/w00t.jpg
    Last edited by sitehostz; 05-08-2003 at 01:10 AM.

  13. #13
    Member
    Join Date
    Sep 2001
    Posts
    189

    Default

    If they defaced you, they have backdoor to your server under ROOT ! Check it out twice!
    Alex Andreyev,
    http://www.WHost.INFO - NEW web hosting directory.

  14. #14
    Member WeMasterz5's Avatar
    Join Date
    Feb 2003
    Location
    Miami
    Posts
    361

    Default

    quick question here

    (sorry for your problems)


    question...is there a way from shell to see the kernal ver running on the server?

  15. #15
    Member
    Join Date
    Oct 2002
    Posts
    751

    Default

    uname -a

Similar Threads & Tags
Similar threads

  1. Replies: 4
    Last Post: 07-06-2011, 09:51 AM
  2. Security Flaw with email in cpanel?
    By Secmas in forum Security
    Replies: 6
    Last Post: 04-14-2010, 03:05 PM
  3. Major Security Issue In Cpanel
    By ukhost4u in forum cPanel and WHM Discussions
    Replies: 22
    Last Post: 10-22-2006, 11:28 AM
  4. ALL CPANEL servers = limited open relays
    By H2Hosting.com in forum cPanel and WHM Discussions
    Replies: 9
    Last Post: 09-04-2003, 01:00 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube