Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Page 1 of 2 1 2 LastLast
Results 1 to 15 of 16
  1. #1
    Member
    Join Date
    May 2006
    Posts
    11

    Exclamation Someone hacked server, need to track this

    Today someone hacked our server. Reseller password and root where changed and all accounts where suspened. Is there any way to see who (IP) and when changed root password? are there any cpanel/ehm logs? There are logs for apache, but they are useless...

    Please help

    PS: I got root password back.

  2. #2
    Registered User
    Join Date
    Apr 2006
    Posts
    1

    Default

    ssh in
    more /var/log/secure

  3. #3
    Member
    Join Date
    May 2006
    Posts
    11

    Default

    Quote Originally Posted by adamd84
    ssh in
    more /var/log/secure
    I see A lot of "Failed password for root" <- someone was trying to brute force. But there is no "Accepted password" logs. These are only ssh logs ( I think) and I think someone hacked server using WHM.

  4. #4
    Member @home's Avatar
    Join Date
    Nov 2003
    Posts
    114

    Default

    Quote Originally Posted by qrees
    I see A lot of "Failed password for root" <- someone was trying to brute force. But there is no "Accepted password" logs. These are only ssh logs ( I think) and I think someone hacked server using WHM.
    Maby a good idea to install BFD

  5. #5
    Member
    Join Date
    May 2006
    Posts
    11

    Default

    Quote Originally Posted by @home
    Maby a good idea to install BFD
    Yeah, probably, but as i already said, i don't think that that was the problem. Problem is in WHM, how can I track who did what?

  6. #6
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    The only logs you'll have for cPanel/WHM are in /usr/local/cpanel/logs/*

    If your root password was changed, it suggests a root compromise on the server. IF that's the case you should have the server OS wiped out and reinstalled and restore from backup as you cannot trust the server anymore as it could have backdoors installed - then have it secured against root compromise attacks.
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  7. #7
    Member
    Join Date
    Jul 2003
    Posts
    275

    Default

    Keeping on topic and catching Chirpy at the same time... your firewall and Login Failure Daemon modules... do they work against invalid WHM and Cpanel logins as well, or just standard httpd authentication, SSH, FTP and mail?
    Basically... if someone were trying to brute force a cpanel or WHM login on my server, would the LFD block them?

  8. #8
    Member
    Join Date
    Jul 2002
    Location
    Canada
    Posts
    675

    Default

    hire an experienced administrator to review and lock down your server. if you're not sure how they got in or where to check you need to hire a professional to consult and correct the issue
    Upload Guardian 2.0 - Sign up for our early beta
    ServerProgress - Server security, consulting and assistance

  9. #9
    Member
    Join Date
    May 2006
    Posts
    11

    Default

    Quote Originally Posted by ramprage
    hire an experienced administrator to review and lock down your server. if you're not sure how they got in or where to check you need to hire a professional to consult and correct the issue
    I think i have found what was the problem and how did they change password (it's stupid, do i'm not going to post explanation here :P ).

    And about this brute force attack. APF doean't seem to work:
    Code:
    Unable to load iptables module (ip_tables), aborting.
    How can i solve this?

    -- EDIT:
    modprobe ip_tables results:
    Code:
    FATAL: Could not load /lib/modules/2.6..../modules.dep: No such file or directory
    Last edited by qrees; 06-21-2006 at 03:41 PM.

  10. #10
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    Quote Originally Posted by NightStorm
    Keeping on topic and catching Chirpy at the same time... your firewall and Login Failure Daemon modules... do they work against invalid WHM and Cpanel logins as well, or just standard httpd authentication, SSH, FTP and mail?
    Basically... if someone were trying to brute force a cpanel or WHM login on my server, would the LFD block them?
    No - ATM I haven't found a way to track them through SSL connections.
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  11. #11
    Member
    Join Date
    Jul 2002
    Location
    Canada
    Posts
    675

    Default

    Seems like your installation of APF/BFD is broken. What version are you using? Have you tried reinstalling?
    Upload Guardian 2.0 - Sign up for our early beta
    ServerProgress - Server security, consulting and assistance

  12. #12
    Member
    Join Date
    May 2006
    Posts
    11

    Default

    Quote Originally Posted by ramprage
    Seems like your installation of APF/BFD is broken. What version are you using? Have you tried reinstalling?
    The problem is iptables which doesn't work.

    modprobe ip_tables:
    Code:
    FATAL: Could not load /lib/modules/2.6.9-11.EL/modules.dep: No such file or directory

  13. #13
    Member
    Join Date
    Mar 2006
    Location
    Brno, Czech Republic
    Posts
    510

    Default

    reinstall iptables/upgrade kernel. should do it
    Not everything that is counted counts and not everything that counts can be counted

  14. #14
    Member
    Join Date
    May 2006
    Posts
    11

    Default

    Quote Originally Posted by katmai
    reinstall iptables/upgrade kernel. should do it
    Ok, rebooting the server helped. And that's why it's impossible to have 100% uptime
    Hiya host - Shared hosting

  15. #15
    Member
    Join Date
    Jan 2004
    Posts
    252

    Default

    2.6.9-11.EL

    That kernel is vulnerable to exploits.
    Rack911.com - Competent Server Administration
    Server Security - Administration - Managed Servers - Optimization - High Traffic Clusters

Similar Threads & Tags
Similar threads

  1. My server has been hacked again. Please Help me!
    By hackboys in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 11-21-2009, 02:02 PM
  2. Server Hacked ..!
    By Nelesh in forum New User Questions
    Replies: 6
    Last Post: 07-11-2009, 05:35 PM
  3. Is there any way to properly track server bandwidth?
    By damainman in forum cPanel and WHM Discussions
    Replies: 11
    Last Post: 01-30-2004, 09:27 PM
  4. How do i track spam sent from my server?
    By hostultra in forum cPanel and WHM Discussions
    Replies: 12
    Last Post: 09-08-2003, 05:09 PM
  5. spam mail being sent out of server, how to track?
    By XPerties in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 06-12-2003, 08:37 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube