|
|||
|
Server Hacked, please help
I got a strange email this morning from CPanel and running a search on here yields no results. The email states
Quote:
top - 07:53:40 up 4 days, 22:03, 2 users, load average: 2.23, 2.24, 2.19 Tasks: 149 total, 3 running, 146 sleeping, 0 stopped, 0 zombie Cpu(s): 99.3% us, 0.3% sy, 0.0% ni, 0.0% id, 0.0% wa, 0.2% hi, 0.2% si Mem: 2073820k total, 1963448k used, 110372k free, 118008k buffers Swap: 2096472k total, 648k used, 2095824k free, 1279696k cached Quote:
|
|
||||
|
http://www.cyberciti.biz/faq/unix-li...hn-the-ripper/
This is all I could find. Kill off the process imho. |
|
|||
|
I got to the bottom of it, this guy installed a rootkit "shv5_rootkit" and is sending spam (the Bank of America Hack I imagine) I was able to get a list of commands executed and saw exactly where he got in from and what he has done.
One of my clients seems to have installed an email list program and he gained access through the "temp" file on that program. |
|
|||
|
Quote:
One of the commands he ran was root@tk [~]# cd /lib/ld-lsb.so.3/john-1.7.0.2/run but I cant even file that so.3 file at that location. |
|
|||
|
Thanks for that, what would be the best way to migrate all the accounts from the server is SSH has been disabled and WHM from the new server is unable to establish a connection to the compromised server.
How exactly would I setup backup to remote FTP ? |
|
|||
|
You should have all of your clients change their passwords, John the ripper is typically used to decrypt user passwords. depending on length / complexity / Salted or unsalted he could have cracked the passwords live or downloaded a copy of the shadow file to offline processing. Once the passwords are uncovered he can use them to re-gain access to your server unless you change all of your users passwords.
|
|
|||
|
The most important thing to do is have cpanel update itself automatically, enable the hardened password thing cpanel provides. I have been admining servers for a long time and I have never paid much attention to uptime nor do I go with servers which have 400 day uptimes as I don't trust them. I rather have a low uptime server with all security updates than one which has good uptime. make sure all users use strong passwords. setting the password hardener to 75 or higher is recomended pisses users off but it's for there own good as much as your servers. as it isn't good for your bussiness if you've been hacked.
|
|
|||
|
Not entirely sure, the techs at the datacenter state he may have exploited a recently discovered hole in FC4 kernel but when I check the bash_history, he suddenly appears in the system and starts executing commands referencing a clients mailer program folder. I think that folder is how he gained access to the system but its unclear to me how
Last edited by encryption; 02-19-2008 at 11:46 AM. |
|
|||
|
so I recompiled Apache 2.2 with the latest version of PHP and enabled Mod Security but now none of the sites are working.... I get the following error. Any clues ?
Quote:
Last edited by encryption; 02-19-2008 at 02:32 PM. |
|
||||
|
Sounds like you don't have usrdir enabled on your system.
Try the following. Log into WHM -> Security Center -> mod_userdir -> Ensure that it's enabled on the default host - if you want to allow your customers to access their sites via their username (lots of discussion about that). |
|
|||
|
cheers darren, you've been mighty helpful all along, mod_security didnt have any rules configured so I chose the default configuration, is there anyplace you recommend I obtain a relatively well configured ruleset for use in WHM?
also the default config breaks the use of .htaccess, how would I change that ? (I've searched on the forums a bit but not finding anything constructive) |
![]() |
| Thread Tools | |
| Display Modes | |
|
|