Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 7 of 7
  1. #1
    Member
    Join Date
    Dec 2004
    Posts
    13

    Default Space Theft

    I have had some users(3) show up on WHM as they are using like 400MB(average) but when I du -sh them on SSH it shows up they were actually using 16GB, they hid some files on folders named like "...", ".,/.,", "happy.gif/.,/..." now, WHM wasnt able to read those folders so they were stealing alot of space, how do I fix this?

  2. #2
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    If they're owned by the user they would show up, but I would bet they're owned by nobody:nobody - either way, those are exploit files and those accounts or the scripts running in them have been compromised and you could have hackers daemons running on your server. you need to check the whole server over thoroughly.
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  3. #3
    Member
    Join Date
    Dec 2004
    Posts
    20

    Default

    Whoa, this really sucks. I better start checking my folders. You maybe should disable their accounts or ask them whats going on.

  4. #4
    Member
    Join Date
    Dec 2003
    Posts
    120

    Default

    install rkhunter
    http://downloads.rootkit.nl/rkhunter-1.2.4.tar.gz

    in your linux root shell type
    cd /usr/local
    wget http://downloads.rootkit.nl/rkhunter-1.2.4.tar.gz
    tar xzvf rkhunter-1.2.4.tar.gz
    cd rkhunter-1.2.4
    sh ./install.sh

  5. #5
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Mar 2003
    Location
    NC
    Posts
    725
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    As posted above sounds like your server might be hacked. What files have they uploaded to the server? I bet they will be illegal movies and games which if that is true is probably causing your server to transfer a lot more then is necessary.

    As chirpy said file ownership is how quotas are determined.

  6. #6
    Member
    Join Date
    Dec 2004
    Posts
    11

    Default

    Hi !

    Maybe you have a tip for me? It seems someone is "hiding" 30 Gig of space on our server's HDD somehow. WHM does show 20 Gig being used for the /home directory -- and this on a 80 Gig HDD should not add up to 85%.

    What would be a way to find directories like "...", ".,/.," --- if ownership would be "nobody"?

    Best,
    John

  7. #7
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    It's probably simpler to use du from the top of /home and work your way downwards:

    cd /home
    du --max-depth=1 -h
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

Similar Threads & Tags
Similar threads

  1. Replies: 3
    Last Post: 06-13-2010, 09:08 PM
  2. Replies: 6
    Last Post: 06-20-2008, 01:01 AM
  3. Bandwidth Theft
    By andrewj in forum Security
    Replies: 5
    Last Post: 05-21-2008, 09:01 AM
  4. IP Conflict/Theft in same NOC
    By jeroman8 in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 07-13-2007, 08:17 AM
  5. Bandwidth Theft?????
    By leec in forum cPanel and WHM Discussions
    Replies: 6
    Last Post: 06-13-2003, 04:19 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube