Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Results 1 to 8 of 8
  1. #1
    Member
    Join Date
    Jul 2002
    Posts
    367

    Default security issue

    Our server was hacked adn we did upgrade the kernel. Also upgrade teh security pathches.

    When we scan we got folliwng info.

    Whence Possible Trojan

    /usr/lib/libexpat.so.0.1.0
    .

    Possible Trojan - /usr/bin/GET
    .

    Possible Trojan - /usr/bin/HEAD
    .

    Possible Trojan - /usr/bin/POST
    .

    Possible Trojan - /usr/bin/lwp-download
    .

    Possible Trojan - /usr/bin/lwp-mirror
    .

    Possible Trojan - /usr/bin/lwp-request
    .

    Possible Trojan - /usr/bin/lwp-rget
    .
    .

    Possible Trojan - /usr/bin/curl
    .

    Possible Trojan - /usr/lib/libcurl.so.2.0.2
    .


    Would it cause any problem???? Any I deal???

    Thanks
    Shan

    cPanel.net Support Ticket Number:

  2. #2
    Member
    Join Date
    May 2002
    Posts
    429

    Default

    which Kernel did you have when you got hacked?

    cPanel.net Support Ticket Number:

  3. #3
    Member
    Join Date
    Jul 2002
    Posts
    367

    Default

    i had 2.4.19.

    ARe this trojon acceptable??

    cPanel.net Support Ticket Number:

  4. #4
    Member
    Join Date
    Feb 2002
    Location
    UK
    Posts
    461

    Default

    The trojan scanner in WHM isnt accurate, install and use chkrootkit

    cPanel.net Support Ticket Number:
    Apache to die or not to die, that is the question...

  5. #5
    Member
    Join Date
    Mar 2003
    Posts
    863

    Default

    Originally posted by shann
    i had 2.4.19.

    ARe this trojon acceptable??

    cPanel.net Support Ticket Number:
    How do you know it was the kernel? I mean OpenSSH is vuln enough and we are upgraded to 3.5. You guys should really be updating your OpenSSH instead of using the vuln version currently installed on Cpanel. Anything below 3.3 is absolutely vulnarable.

    cPanel.net Support Ticket Number:

  6. #6
    Member
    Join Date
    Feb 2003
    Posts
    251

    Default

    Is the only reason you think you were hacked because of the cpanel trojan scanner?

    Have you tried running chkrootkit on the server?

    Mike

    cPanel.net Support Ticket Number:

  7. #7
    Member
    Join Date
    Jul 2002
    Posts
    367

    Default

    No,

    we had ptrace.c file on our tmp dir. thats how we found . We updated the kernel to 2.4.20 and updated security patches.

    when we scan we are getting above info.

    cPanel.net Support Ticket Number:

  8. #8
    Member
    Join Date
    Feb 2002
    Location
    UK
    Posts
    461

    Default

    I have never seen the scanner in WHM never throw back at least one possible trojan, install and use chkrootkit, like i suggested

    cPanel.net Support Ticket Number:
    Apache to die or not to die, that is the question...

Similar Threads & Tags
Similar threads

  1. Security issue?
    By BianchiDude in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 04-21-2008, 08:12 AM
  2. Is this a security issue?
    By BianchiDude in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 07-18-2006, 04:04 PM
  3. Security issue
    By prof in forum Security
    Replies: 3
    Last Post: 02-21-2006, 12:31 PM
  4. Possible security issue
    By GordonH in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 01-27-2004, 05:38 AM
  5. security issue
    By NNNils in forum cPanel and WHM Discussions
    Replies: 16
    Last Post: 04-28-2003, 03:55 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube