The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

All Site passwords changed

Discussion in 'Security' started by wstream, Dec 4, 2013.

  1. wstream

    wstream Registered

    Joined:
    Dec 4, 2013
    Messages:
    2
    Likes Received:
    0
    Trophy Points:
    1
    cPanel Access Level:
    Root Administrator
    Hi All

    I need some info and help

    We have a dedicated server witha handfull of joomla sites and 1 wordpress site.

    last night we had the wordpress site hacked.

    As a result all other sites that are joomla had their user table - user passwords chaged and privelages changed to superadmin.

    Whats puzzling me is how they were able to change passwords on other databases in the same server.

    At worst they could have got hold of the DB password for the wordpress database but not the others.

    so how would they have changed the data on the other db's

    In order to protect against this happening again ill need to determin the route taken.

    Any help or pointers greatly appreciated.

    Thanks

    Ash
     
  2. cPanelMichael

    cPanelMichael Forums Analyst
    Staff Member

    Joined:
    Apr 11, 2011
    Messages:
    30,830
    Likes Received:
    672
    Trophy Points:
    113
    cPanel Access Level:
    Root Administrator
  3. quizknows

    quizknows Well-Known Member

    Joined:
    Oct 20, 2009
    Messages:
    942
    Likes Received:
    57
    Trophy Points:
    28
    cPanel Access Level:
    DataCenter Provider
    You got hit with a symlink hack.

    http://forums.cpanel.net/f185/solutions-handling-symlink-attacks-202242.html

    In short, a hacker can use a default cPanel/WHM/Apache setup to get read access to everyones configuration.php files. With that they have all the SQL usernames/passwords to change the admin tables.

    I suggest cloudlinux with securelinks, or at least SuPHP with the EasyApache "Symlink Race Condition" protection.
     
  4. wstream

    wstream Registered

    Joined:
    Dec 4, 2013
    Messages:
    2
    Likes Received:
    0
    Trophy Points:
    1
    cPanel Access Level:
    Root Administrator
    Hi Michael - thanks for the move

    Quizknows - thanks for the reply - yup looks like thats what happened - have applied RUID2 and JailShell

    Thanks again guys

    Ash
     
Loading...

Share This Page