Go Back   cPanel Forums > cPanel® and WHM® (for Linux® and FreeBSD® Servers) > cPanel and WHM Discussions

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 07-17-2007, 09:23 AM
Registered User
 
Join Date: Jul 2003
Location: India
Posts: 12
fastdns
"Remote Data Services Data Control" warning on all my websites ?

Hi

All my websites are trying to run a malicious code, and AV detects that as Bloodhound or its variant XML_HACK.AO .

The pop up is similar to the one described at :

http://msmvps.com/blogs/spywaresucks...06/548681.aspx

I have been frantically searcihng for a clue, but in vain.

Does anyone have an idea what this is and how it is spreading to all the sites ?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 10-02-2007, 10:47 AM
Registered User
 
Join Date: May 2004
Location: Eindhoven
Posts: 42
Parcye
I have the same, anybody got any idea how to solve this?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 10-02-2007, 04:09 PM
Registered User
 
Join Date: Oct 2007
Posts: 144
sarhosting is an unknown quantity at this point
Have you checked all of your logs?

Is annoymous FTP turned? Have you got a demo account

Do you have anything insure like sql commands, that could cause SQL inject?

As these websites, PHP, Java or have any of these in it?

You could install rkhunter via command like works well for me
__________________
Kind Regards
Bionic Internet Ltd
http://www.bionic-hosting.co.uk

UK Web Hosting| UK Reseller Hosting |
UK Dedicated Servers
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 10-02-2007, 04:25 PM
Registered User
 
Join Date: May 2004
Location: Eindhoven
Posts: 42
Parcye
What is rkhunter?

I have no demo account.

It looks like it is caused by an old joomla installed by a user.

Managed to fix the effected sites with a perl script that checks all files in home...
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 10-02-2007, 04:47 PM
Registered User
 
Join Date: Oct 2007
Posts: 144
sarhosting is an unknown quantity at this point
RK Hunter:-

Rootkit scanner

Project information

Rootkit scanner is scanning tool to ensure you for about 99.9%* you're clean of nasty tools. This tool scans for rootkits, backdoors and local exploits by running tests like:

- MD5 hash compare
- Look for default files used by rootkits
- Wrong file permissions for binaries
- Look for suspected strings in LKM and KLD modules
- Look for hidden files
- Optional scan within plaintext and binary files

Rootkit Hunter is released as GPL licensed project and free for everyone to use.

* No, not really 99.9%.. It's just another security layer

http://www.rootkit.nl/projects/rootkit_hunter.html
__________________
Kind Regards
Bionic Internet Ltd
http://www.bionic-hosting.co.uk

UK Web Hosting| UK Reseller Hosting |
UK Dedicated Servers
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 04:23 AM.


Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
© cPanel Inc