Please whitelist cPanel in your adblocker so that you’re able to see our version release promotions, thanks!

The Community Forums

Interact with an entire community of cPanel & WHM users!

Back connect and root access

Discussion in 'Security' started by fernandomm, Aug 2, 2013.

  1. fernandomm

    fernandomm Active Member

    Joined:
    Nov 25, 2009
    Messages:
    26
    Likes Received:
    0
    Trophy Points:
    51
    Hi,

    Someone was able to access one of our users and installed a back connect. With this back connect script, he was able to not only access the user's account but our entire server and defaced all websites ( root access ).

    Any ideas of how this is possible? Is bruce-force an option or there might be another options?

    We're currently recovering a backup but we need to find out what happened in order to prevent this from happening again.
     
  2. cPanelMichael

    cPanelMichael Technical Support Community Manager
    Staff Member

    Joined:
    Apr 11, 2011
    Messages:
    44,803
    Likes Received:
    1,896
    Trophy Points:
    363
    cPanel Access Level:
    Root Administrator
    Twitter:
    Hello :)

    While it's possible the account password was brute forced, it's difficult to speculate on any specific cause. It's generally recommended to reinstall the Operating System and restore the accounts if your server has been hacked at the root level. I suggest consulting with a qualified system administrator or security specialist for a full investigation on the entry point. Some companies list their services for this in the cPanel application catalog:

    cPanel Application Catalog - System Administration Services

    Thank you.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
Loading...

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice