The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Back connect and root access

Discussion in 'Security' started by fernandomm, Aug 2, 2013.

  1. fernandomm

    fernandomm Active Member

    Nov 25, 2009
    Likes Received:
    Trophy Points:

    Someone was able to access one of our users and installed a back connect. With this back connect script, he was able to not only access the user's account but our entire server and defaced all websites ( root access ).

    Any ideas of how this is possible? Is bruce-force an option or there might be another options?

    We're currently recovering a backup but we need to find out what happened in order to prevent this from happening again.
  2. cPanelMichael

    cPanelMichael Forums Analyst
    Staff Member

    Apr 11, 2011
    Likes Received:
    Trophy Points:
    cPanel Access Level:
    Root Administrator
    Hello :)

    While it's possible the account password was brute forced, it's difficult to speculate on any specific cause. It's generally recommended to reinstall the Operating System and restore the accounts if your server has been hacked at the root level. I suggest consulting with a qualified system administrator or security specialist for a full investigation on the entry point. Some companies list their services for this in the cPanel application catalog:

    cPanel Application Catalog - System Administration Services

    Thank you.

Share This Page