Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Results 1 to 9 of 9
  1. #1
    Member
    Join Date
    Oct 2002
    Posts
    18

    Default server deface

    Last night someone was able to do a mass deface on one of our servers. We run chkrootkit and rkhunter regularly and I don't see any odd processes running so I don't think I have a root kit problem.

    Is there any way to track down a script vulnerability that could have done this?

    All files matching *index* had 4 <iframe> lines added and chown to root.root

    Any help would be appreciated (If there's a better forum for this please let me know).

    Thanks,
    Dean

  2. #2
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    If the index files are chowned to root:root where they weren't previously, then you've had a root compromise somewhere. No-one other than root (or a daemon, process or suid binary) can change file ownerships like that. Are you running the latest STABLE/RELEASE/CURRENT/EDGE of cPanel as there were some exploits found not long ago.
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  3. #3
    Member
    Join Date
    Oct 2002
    Posts
    18

    Default

    I'm running the RELEASE tree and it says it's up to date
    WHM 9.9.7 cPanel 9.9.8-R5

    If I've had a root compromise it's probably beyond my realm to find it. I've noticed a couple of places that do security work on linux/Cpanel systems. How do you know who you can trust?

  4. #4
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    Sadly, with difficulty. One option is to ask for recommendations from others. Another route might be to ask CERT for help:
    http://www.cert.org/tech_tips/incident_reporting.html
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  5. #5
    Member sawbuck's Avatar
    Join Date
    Jan 2004
    Posts
    1,310
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Quote Originally Posted by Crooner
    How do you know who you can trust?
    You can certainly trust Chirpy.

  6. #6
    Member verdon's Avatar
    Join Date
    Nov 2003
    Location
    Northern Ontario, Canada
    Posts
    792

    Default

    Quote Originally Posted by sawbuck
    You can certainly trust Chirpy.
    I'll second that... he knows what he's doing too

  7. #7
    Member
    Join Date
    Feb 2003
    Posts
    311

    Default

    Check your /tmp folder for scripts. It could be as simple as having exec privilages on the /tmp folder that allowed someone to run it. I know there was an old my_egallery exploit that caused issues like this in the past. Might want to scan your server and see if anyone is running my_egallery.

  8. #8
    Member
    Join Date
    Sep 2004
    Posts
    529

    Default

    Look through your httpd logs (if they haven't been wiped) for suspicious activity near the time of the timestamps on the modified files. If the files are indeed owned by root, then you need an OS reload. If not, you should be able to clean up, plug the hole, and make sure that nothing else was touched.

  9. #9
    Member
    Join Date
    Jan 2004
    Posts
    252

    Default

    If it is a root compromise i strongly recommend an os reinstall, rather then trying to clean the box up.
    Rack911.com - Competent Server Administration
    Server Security - Administration - Managed Servers - Optimization - High Traffic Clusters

Similar Threads & Tags
Similar threads

  1. Change master name server from server 1 to server 4
    By Curt in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 10-16-2002, 02:45 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube