Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Page 1 of 2 1 2 LastLast
Results 1 to 15 of 19
  1. #1
    Member
    Join Date
    Feb 2003
    Posts
    291

    Angry server hacked....

    Hello All,

    From last few days the server load is continuously running between 25% - 75%. Someone has hacked into the server sending mail. Is there some way we can tract this and shut them out.

    6166 root 0 3.2 0.5 sendmail
    6173 root 0 3.2 0.5 sendmail
    6175 root 0 3.0 0.5 sendmail
    6180 root 0 3.0 0.5 sendmail
    6187 root 0 3.0 0.5 sendmail
    6163 root 0 2.9 0.5 /usr/sbin/exim-MCS-MCP-MCremote_smtpmx2.mail.yahoo.com219R55Q-0003AL-00
    6182 root 0 2.9 0.5 sendmail
    6190 root 0 2.9 0.5 /usr/sbin/exim-MCS-MCP-MCremote_smtpmx2.mail.yahoo.com219R55R-0003AU-00
    6194 root 0 2.7 0.5 /usr/sbin/exim-MCS-MCP-MCremote_smtpmx2.mail.yahoo.com219R55P-0003AE-00
    5595 nobody 0 2.5 3.8 httpd
    6155 root 0 2.5 0.5 sendmail
    6186 root 0 2.5 0.5 /usr/sbin/exim-MCS-MCP-MCremote_smtpmx2.mail.yahoo.com219R55T-0003Al-00
    6158 root 0 2.3 1.0 /usr/sbin/exim-MCS-MCP-MCremote_smtpmx2.mail.yahoo.com219R55S-0003AZ-00
    6160 root 0 2.3 0.5 sendmail
    6165 root 0 2.3 0.5 /usr/sbin/exim-MCS-MCP-MCremote_smtpmx1.mail.yahoo.com219R55V-0003At-00


    Thank you,

    cPanel.net Support Ticket Number:
    Mitul

  2. #2
    Member
    Join Date
    Jun 2002
    Posts
    100

    Default

    Did you upgrade your kernel to latest version?

    cPanel.net Support Ticket Number:

  3. #3
    Member
    Join Date
    Feb 2003
    Posts
    291

    Default

    I am using 2.4.18-27.7.x version of kernel.

    cPanel.net Support Ticket Number:
    Mitul

  4. #4
    Member
    Join Date
    Feb 2003
    Posts
    291

    Default

    This was upgraded long time back...

    cPanel.net Support Ticket Number:
    Mitul

  5. #5
    Member
    Join Date
    Jun 2002
    Posts
    100

    Default

    You have lost your root pass posible.

    You must upgrade to latest kenel, becouse you have not latest kernel version.Your kernel version has a vulnerable.

    cPanel.net Support Ticket Number:

  6. #6
    Member
    Join Date
    Jun 2002
    Posts
    100

    Default

    Yýu can use this comand;
    up2date --nox -f kernel

    cPanel.net Support Ticket Number:

  7. #7
    Member
    Join Date
    Jun 2002
    Posts
    100

    Default Server Security Guide - Basic steps to server security

    http://www.admin0.net/security/introduction.htm

    cPanel.net Support Ticket Number:

  8. #8
    Member
    Join Date
    Feb 2003
    Posts
    291

    Default

    Does this mean my server is been hacked.

    Is there any way to track who is sending mails from my server?

    Thank you,

    cPanel.net Support Ticket Number:
    Mitul

  9. #9
    Member
    Join Date
    Apr 2003
    Posts
    22

    Default Re: Server Security Guide - Basic steps to server security

    Originally posted by tekdns
    http://www.admin0.net/security/introduction.htm

    cPanel.net Support Ticket Number:
    nice link...I will put this in my list of links to give to new admins....

    cPanel.net Support Ticket Number:
    NightHawk
    We Make Server Management Easy!
    http://www.easyservermanagement.com

  10. #10
    Member
    Join Date
    Apr 2003
    Posts
    22

    Default

    Originally posted by mitul
    Does this mean my server is been hacked.

    Is there any way to track who is sending mails from my server?

    Thank you,

    cPanel.net Support Ticket Number:
    the information you have provided is not enough to show for certain that your server has been hacked, certainly if your server was hacked...they could then send that email...but, there are other options:
    1) insecure formmail.pl (or clones)
    2) compromised customer smtp password
    3) compromised customer webmail account
    4) open relay (I am guessing you have checked this already).
    5) there are others...but those are the ones I would check first).

    cPanel.net Support Ticket Number:
    NightHawk
    We Make Server Management Easy!
    http://www.easyservermanagement.com

  11. #11
    Member
    Join Date
    Feb 2003
    Posts
    291

    Default

    The server is been tested for open relay.

    The formmail.cgi bug was fixed few days ago by cpanel.

    If is about clients smtp or webmail password been compromised how do I trace that out.

    Please help me fast....

    Thank you,

    cPanel.net Support Ticket Number:
    Mitul

  12. #12
    Member
    Join Date
    Feb 2003
    Posts
    291

    Default

    I got my server tested from ORDB.org for open relay and got confirmation from ORDB.org that my server does not permit open relay.

    How do I trace if its the local client on the server who is sending mails through script or using any other form?

    Please help I am loosing my server....

    Thank you,

    cPanel.net Support Ticket Number:
    Mitul

  13. #13
    Member
    Join Date
    Sep 2002
    Posts
    580

    Default

    Originally posted by tekdns

    You must upgrade to latest kenel, becouse you have not latest kernel version.Your kernel version has a vulnerable.
    What vulnerabilities does 2.4.18-27.7.x have?

    cPanel.net Support Ticket Number:

  14. #14
    Registered User
    Join Date
    May 2003
    Posts
    1

    Default 2.4.18+ vuln

    IIRC anything <2.4.21 has a ptrace root whole open.

    cPanel.net Support Ticket Number:

  15. #15
    Member
    Join Date
    Mar 2003
    Posts
    863

    Default

    2.4.18-27.7.x is not vuln at all. Show me where it says that this kernel is vuln? So many people have had problems with the next kernel release that many have chosen to stay at 2.4.18-27.7.x. If he was hacked he should be looking at his other security admin abilities.

    cPanel.net Support Ticket Number:

Similar Threads & Tags
Similar threads

  1. my server is hacked
    By jcaldera in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 05-02-2009, 03:23 PM
  2. server has been hacked
    By aracrew in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 01-21-2008, 05:55 PM
  3. Server get hacked
    By vishwas in forum cPanel and WHM Discussions
    Replies: 5
    Last Post: 12-02-2005, 03:49 AM
  4. my server got hacked?
    By goodgbb in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 08-25-2005, 09:18 AM
  5. new server got hacked
    By brumie in forum cPanel and WHM Discussions
    Replies: 24
    Last Post: 04-29-2004, 12:00 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube