Back connect and root access

fernandomm

Active Member
Nov 25, 2009
26
0
51
Hi,

Someone was able to access one of our users and installed a back connect. With this back connect script, he was able to not only access the user's account but our entire server and defaced all websites ( root access ).

Any ideas of how this is possible? Is bruce-force an option or there might be another options?

We're currently recovering a backup but we need to find out what happened in order to prevent this from happening again.
 

cPanelMichael

Administrator
Staff member
Apr 11, 2011
47,913
2,202
363
Hello :)

While it's possible the account password was brute forced, it's difficult to speculate on any specific cause. It's generally recommended to reinstall the Operating System and restore the accounts if your server has been hacked at the root level. I suggest consulting with a qualified system administrator or security specialist for a full investigation on the entry point. Some companies list their services for this in the cPanel application catalog:

cPanel Application Catalog - System Administration Services

Thank you.