Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 3 of 3
  1. #1
    Member
    Join Date
    Sep 2005
    Posts
    42

    Default URGENT:my server hacked by a hacker! plz help me

    Hello,
    Some one hacked my server and inserted a file in one of the hosts . this file called "fantic.php" that hacker can view entire hosts`s files and can edit writable files on server and can view files`s contents...
    i tried to enable "open_basedir protection" and this action, disabled the "fantic.php" file operation on other hosts, but i saw this hacker activate on my server again, when i traced , i saw that she/he is using http://serversharedip/~hostuser/ link to public access "fantic.php" file and at this way, open_basedir dosn`t work and so this hacker can have access to other hosts.
    i tried to enable "mod_userdir Protection" , and anything was ok, but after restarting apache, automatrically "mod_userdir Protection" disabled and didn`t work. i tried to enable it again, but , it didn`t enable ....
    now i don`t know what to do, please, help me!

    I do apologize because of my bad english

    Thanks
    Abolfazl

  2. #2
    cPanel Partner NOC cPanel Partner NOC Badge AndyReed's Avatar
    Join Date
    May 2004
    Location
    Minneapolis, MN
    Posts
    2,223

    Default

    Quote Originally Posted by 4402734
    Some one hacked my server and inserted a file in one of the hosts . this file called "fantic.php" that hacker can view entire hosts`s files and can edit writable files on server and can view files`s contents...
    The first thing you need to do is cleaning up your server. Remove all the scripts the hacker downloaded and installed on your server. Second, secure your server. Search these forums as there are many threads discussing server security. If you don't know, hire a sys admin to take care of this problem for you.
    Andy Reed
    RHCE and CCNA
    ServerTune.com

  3. #3
    Member
    Join Date
    Mar 2002
    Posts
    175

    Default

    Looks like that one is a renamed php shell script, and is uploaded to a few abandoned photo galleries.

Similar Threads & Tags
Similar threads

  1. Email option in Cpanel..urgent plz
    By jack001 in forum E-mail Discussions
    Replies: 1
    Last Post: 03-05-2008, 05:18 AM
  2. emergency , plz :((( my site has been hacked
    By 7msh in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 12-03-2005, 09:25 PM
  3. plz help urgent
    By DhruvPatel2005 in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 09-03-2005, 04:14 PM
  4. core dump uploads and cracked/hacker - urgent help needs
    By claudio in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 09-27-2004, 10:01 AM
  5. DirectAdmin to Cpanel? Urgent plz
    By NetMan10 in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 09-24-2004, 12:40 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube