Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 3 of 3
  1. #1
    Registered User
    Join Date
    Aug 2005
    Posts
    1

    Default restoring server from backup

    hello all, a client of the company i work for, had his server compromised (r00ted), the bakcup that was done only has the following

    root@www1 [/old]# ls
    ./ ../ home/ home2/ httpd/ lost+found/ var/ root/.my.cnf
    root@www1 [/old]# ls var
    ./ ../ cpanel/ lib/ log/ named/ spool/
    root@www1 [/old]#
    root@www1 [/old/var]# ls cpanel
    ./ addonwhmversions/ deleteddomains futex-test* mmpass proftpdconvert updatelogs/
    ../ adminsessions/ dnsrequests hordepass mysqlup quotawarned usecpphp
    accounting.log bandwidth/ eximstatspass iclevels.conf neomail/ repquota.cache users/
    accts.db buildapache.config.pl eximup ipchangeinprogress newaccts/ root.accts useup2date
    activate/ bwlimited/ features/ jailshell2 noanonftp sessions/ version/
    addoncpanelversions/ clevels.conf fileprotect lang.cache/ notifications/ smtpgidonlytweak whmtheme
    addonmodules Counters/ fixedsqlstatment lastrun/ objcache/ suexecpatch zonetemplates/
    addonmoduleversions/ cp76maillists fpconvert13 logs/ packages/ suspended/
    addonscripts cpanel.config frontpagepassthrough4.2 mailman2 perl/ suspendinfo/
    addonscriptsversions/ CPDNSLib.dat ftpup mailman2converted phpopendomains upcpcheck


    is there any way to restore this data without risks of missing information?

    the httpd configuration files and named zones are on the backups.

  2. #2
    cPanel Partner NOC cPanel Partner NOC Badge AndyReed's Avatar
    Join Date
    May 2004
    Location
    Minneapolis, MN
    Posts
    2,223

    Default

    Quote Originally Posted by Aerethorn
    hello all, a client of the company i work for, had his server compromised (r00ted), the bakcup that was done only has the following

    root@www1 [/old]# ls
    ./ ../ home/ home2/ httpd/ lost+found/ var/ root/.my.cnf

    is there any way to restore this data without risks of missing information?
    Are you sure these files are not blank? Does he have *.tar.gz or incremental backup for his sites and DBs? Or all of that is gone?
    Andy Reed
    RHCE and CCNA
    ServerTune.com

  3. #3
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    Without the files from /etc you might be in for a bit of a struggle. Obviously the /home data is fine for the user files. The important files in /var/cpanel are users/ features/ packages/ if you restore those plus the home files, plus /var/lib/mysql/ and /var/named and the httpd.conf files.

    The next major hurdle will be recreating /etc/passwd which can be done using:

    /scripts/rebuildetcpasswd

    However, you have to be very careful with that script and be sure to backup /etc/passwd /etc/shadow /etc/gshadow and etc/group before playing with it.

    After that's been run all none of the cPanel accounts will have passwords set. Next step would be to try running through the following:

    /scripts/rebuildnamedconf
    /scripts/updateuserdomains
    /scripts/fullhordereset
    /scripts/fixeverything
    /scripts/upcp --force


    Hopefully that will recreate most of what you need, but there are likely to be big holes and you'll have to set each and every cPanel account password.

    Ultimately, it might be simpler to recreate each account through WHM individually and then restore the /home data for the account and then correct the files ownerships.
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

Similar Threads & Tags
Similar threads

  1. restoring a backup with username already in the server
    By sharmaine001 in forum cPanel and WHM Discussions
    Replies: 5
    Last Post: 12-16-2009, 08:38 PM
  2. Problems restoring cP 10 backup on cP 11 server
    By Xenon101 in forum cPanel and WHM Discussions
    Replies: 13
    Last Post: 09-23-2009, 04:33 PM
  3. Restoring a server without backup
    By Horta in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 02-15-2005, 04:35 PM
  4. Restoring a backup already on the server??
    By iHost.net.nz in forum cPanel and WHM Discussions
    Replies: 7
    Last Post: 09-01-2004, 07:09 AM
  5. Restoring a full server backup
    By gvard in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 07-16-2004, 04:12 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube