Please whitelist cPanel in your adblocker so that you’re able to see our version release promotions, thanks!

The Community Forums

Interact with an entire community of cPanel & WHM users!

Backdoor?

Discussion in 'General Discussion' started by flumpadink, Mar 25, 2003.

  1. LS_Drew

    LS_Drew Well-Known Member

    Joined:
    Feb 20, 2003
    Messages:
    187
    Likes Received:
    0
    Trophy Points:
    166
    My sysup doesn't work either. :(
     
  2. jamesbond

    jamesbond Well-Known Member

    Joined:
    Oct 9, 2002
    Messages:
    738
    Likes Received:
    1
    Trophy Points:
    168
    Doesn't work on mine either (Linux RH 7.3 - S109) , still on 3.23.54

    root@host [/scripts]# /scripts/sysup
    openssl is up to date (Wed Feb 19 21:45:54 2003)
    openssl-devel is up to date (Wed Feb 19 21:45:54 2003)
    exim is up to date (Wed Feb 19 21:45:54 2003)
    proftpd is up to date (Wed Feb 19 21:45:54 2003)
    bandmin is up to date (Wed Feb 19 21:45:54 2003)
    chkservd is up to date (Wed Feb 19 21:45:54 2003)
    openssh is up to date (Wed Jun 26 19:56:22 2002)
    openssh-server is up to date (Wed Jun 26 19:56:22 2002)
    openssh-clients is up to date (Wed Jun 26 19:56:22 2002)
    MySQL is up to date (Wed Dec 31 23:59:59 1969)
    MySQL-client is up to date (Wed Dec 31 23:59:59 1969)
    MySQL-devel is up to date (Wed Dec 31 23:59:59 1969)
    MySQL-bench is up to date (Wed Dec 31 23:59:59 1969)
    MySQL-shared is up to date (Wed Dec 31 23:59:59 1969)
    ....
     
  3. Curious Too

    Curious Too Well-Known Member

    Joined:
    Aug 31, 2001
    Messages:
    428
    Likes Received:
    1
    Trophy Points:
    318
    cPanel Access Level:
    Root Administrator
    I had the same problem on about 1/2 my servers. You can download the rpms here: http://updates.cpanel.net/pub/sysup and manually install them.
     
  4. demine0

    demine0 Well-Known Member

    Joined:
    Mar 25, 2003
    Messages:
    57
    Likes Received:
    0
    Trophy Points:
    156
    Are you sure hes not just on the same server as you and is including one of your config files that has your mysql info in it?

    or maybe you have <? include $page; ?> in a file, so when you goto index.php?page=main.php it loads main.

    Well if he uploads a txt files with an include of the config then echo's the config cars. he can include that and get your mysql. I highly dout this is cpanels falt. Check your site/server secruity.
     
  5. jamesbond

    jamesbond Well-Known Member

    Joined:
    Oct 9, 2002
    Messages:
    738
    Likes Received:
    1
    Trophy Points:
    168
    What commands should I type exactly to install the mysql rpm's?
     
  6. sexy_guy

    sexy_guy Well-Known Member

    Joined:
    Mar 19, 2003
    Messages:
    848
    Likes Received:
    0
    Trophy Points:
    166
    Well mysql can also be upgraded using RPM however there were other upgrades performed besides Mysql and those were.

    There was a upgrade to Spamassisin, Mail-SpamAssassin-2.52.tar.gz
    To Exim, exim-3.36-121
    To at least 3 cpan modules, 01mailrc.txt.gz, 02packages.details.txt.gz, 03modlist.data.gz.

    Because the upgrade process is hosted on alot of our servers this means non of the above has been upgraded. While you may be able to do the mysql upgrades using RPM the rest go uninstalled.
    :mad:
     
    #26 sexy_guy, Mar 25, 2003
    Last edited: Mar 25, 2003
  7. Curious Too

    Curious Too Well-Known Member

    Joined:
    Aug 31, 2001
    Messages:
    428
    Likes Received:
    1
    Trophy Points:
    318
    cPanel Access Level:
    Root Administrator
    Running /scripts/sysup upgraded exim and spamassassin on all of my servers. The only thing that had to be upgraded manually was mysql.
     
  8. dgbaker

    dgbaker Well-Known Member PartnerNOC

    Joined:
    Sep 20, 2002
    Messages:
    2,574
    Likes Received:
    3
    Trophy Points:
    343
    Location:
    Toronto, Ontario Canada
    cPanel Access Level:
    DataCenter Provider
    Am I curious as to the date being year 1969

    MySQL is up to date (Wed Dec 31 18:59:59 1969)
    MySQL-client is up to date (Wed Dec 31 18:59:59 1969)
    MySQL-devel is up to date (Wed Dec 31 18:59:59 1969)
    MySQL-bench is up to date (Wed Dec 31 18:59:59 1969)
    MySQL-shared is up to date (Wed Dec 31 18:59:59 1969)

    I think that is part of the issue.

    Remember that *nix time is the amount of seconds fron Jan 1, 1970 and those having the date before that is probably screwing it up.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  9. sexy_guy

    sexy_guy Well-Known Member

    Joined:
    Mar 19, 2003
    Messages:
    848
    Likes Received:
    0
    Trophy Points:
    166
    rpm -Uvh *.rpm
    error: failed dependencies:
    MySQL-DBI-perl-bin is needed by MySQL-bench-3.23.56-1

    Mysql-DBI-perl-bin? So we have to install this before upgrading? This is ridiculous.
     
  10. sexy_guy

    sexy_guy Well-Known Member

    Joined:
    Mar 19, 2003
    Messages:
    848
    Likes Received:
    0
    Trophy Points:
    166
    Everyones dates seem to be 1969!
     
  11. xsenses

    xsenses Well-Known Member

    Joined:
    Aug 29, 2002
    Messages:
    233
    Likes Received:
    0
    Trophy Points:
    166
    Location:
    Huntington Beach, Ca
    Yeah - I am getting that error also. 56 is showing though.
     
  12. cPanelNick

    cPanelNick Administrator Staff Member

    Joined:
    Mar 9, 2015
    Messages:
    3,486
    Likes Received:
    31
    Trophy Points:
    158
    cPanel Access Level:
    DataCenter Provider
    Do you have two copies of mysql installs ?

    rpm -q MySQL
     
  13. xsenses

    xsenses Well-Known Member

    Joined:
    Aug 29, 2002
    Messages:
    233
    Likes Received:
    0
    Trophy Points:
    166
    Location:
    Huntington Beach, Ca
    root@fire [/]# rpm -q MySQL
    MySQL-3.23.56-1
    root@fire [/]#
     
  14. jamesbond

    jamesbond Well-Known Member

    Joined:
    Oct 9, 2002
    Messages:
    738
    Likes Received:
    1
    Trophy Points:
    168
    I do apparently:

    root@host [/]# rpm -q MySQL
    MySQL-3.23.53a-1
    MySQL-3.23.54a-1

    So what do I do now?
     
  15. cPanelNick

    cPanelNick Administrator Staff Member

    Joined:
    Mar 9, 2015
    Messages:
    3,486
    Likes Received:
    31
    Trophy Points:
    158
    cPanel Access Level:
    DataCenter Provider
    put in a ticket so we can fix it :)
     
  16. joana

    joana Well-Known Member

    Joined:
    Sep 29, 2001
    Messages:
    103
    Likes Received:
    0
    Trophy Points:
    316
    We got the exact same issue..
     
  17. joana

    joana Well-Known Member

    Joined:
    Sep 29, 2001
    Messages:
    103
    Likes Received:
    0
    Trophy Points:
    316
    Well, just checked and 3 servers have the same.. 2 installs, any reason for that?
    Is it easy to fix ourselves so we don't need to open tickets?
     
  18. sexy_guy

    sexy_guy Well-Known Member

    Joined:
    Mar 19, 2003
    Messages:
    848
    Likes Received:
    0
    Trophy Points:
    166
    According to what needs upgrading as far as mysql is this;

    MySQL-client-3.23.56-1.i386.rpm
    MySQL-devel-3.23.56-1.i386.rpm
    MySQL-bench-3.23.56-1.i386.rpm
    MySQL-shared-3.23.56-1.i386.rpm

    However, im getting a dependency error when i try to applyMySQL-bench-3.23.56-1.i386.rpm

    error: failed dependencies:
    MySQL-DBI-perl-bin is needed by MySQL-bench-3.23.56-1

    Ok so i attempt to install MySQL-DBI-perl-bin then i get another dependency error

    error: failed dependencies:
    DBI-perl-bin >= 0.90 is needed by Mysql-DBI-perl-bin-1.1825-rh50.1

    So now in install DBI-perl-bin but attempting to run MySQL-bench-3.23.56-1 tells me

    error: failed dependencies:
    MySQL-DBI-perl-bin is needed by MySQL-bench-3.23.56-1

    So im back to square 1, WTH!
     
  19. cPanelNick

    cPanelNick Administrator Staff Member

    Joined:
    Mar 9, 2015
    Messages:
    3,486
    Likes Received:
    31
    Trophy Points:
    158
    cPanel Access Level:
    DataCenter Provider
    sysup has been updated to detect multiple version of mysql installed. It will remove them and install the latest version if you run the following:


    /scripts/updatenow
    /scripts/sysup
     
  20. jamesbond

    jamesbond Well-Known Member

    Joined:
    Oct 9, 2002
    Messages:
    738
    Likes Received:
    1
    Trophy Points:
    168
    Thanks Nick!

    root@host [/]# rpm -q MySQL
    MySQL-3.23.56-1
     
Loading...
Similar Threads - Backdoor
  1. DennisMidjord
    Replies:
    4
    Views:
    736

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice