hello
i have strange hacking on my box
http://3zz.cc/iplog2.txt
that is log from my web site
it is on shared server with centos 4.4
iam run vbulletin last version
and server is well secure but i don't know what is this hacking method
can any one help us to prevent is
i know the hacker is get help.txt file from his web site
but i don't know where does he put thats file i have check my web site there are no suspension file i check the log i don't know also the name does he request to hack my web site
i think he can delete, read and change files and folders for my web site and i think he also can control my website from other web site on that server
notice :
iam use php4.4.4 with safe_mode and this disable_functions
phpinfo, mkdir, unlink, symlink, ini_restore, popen, pclose, system, exec, shell_exec, suExec, dl, passthru, pclose, proc_open, proc_nice, proc_terminate, proc_get_status, proc_close, leak, posix_kill, posix_mkfifo, posix_setpgid, posix_setsid, posix_setuid, posix_uname, posix_getpwuid, escapeshellcmd, escapeshellarg, fpassthru, psockopen, cmd, backtick, virtual, pcntl_exec , ini_alter, parse_ini_file, show_source, apache_child_terminate, apache_get_modules , apache_get_version , apache_note, openlog, popens, filegetcontents, get_dir, dos_conv, myshellexec, get_current_user, php_uname, fileperms, filegroup, fileowner, getmyuid, getmygid
i have set allow_url_fopen to off
and php run with phpsuexec
i have installed mod_security with accunett rules or others rules i have add it
i have install rfx network LES
my system is centos 4.4 with cpanel current version
i know the person who try to hack me and i know he is get files to my website or other web site on my server then he try hacking
i have strange hacking on my box
http://3zz.cc/iplog2.txt
that is log from my web site
it is on shared server with centos 4.4
iam run vbulletin last version
and server is well secure but i don't know what is this hacking method
can any one help us to prevent is
i know the hacker is get help.txt file from his web site
but i don't know where does he put thats file i have check my web site there are no suspension file i check the log i don't know also the name does he request to hack my web site
i think he can delete, read and change files and folders for my web site and i think he also can control my website from other web site on that server
notice :
iam use php4.4.4 with safe_mode and this disable_functions
phpinfo, mkdir, unlink, symlink, ini_restore, popen, pclose, system, exec, shell_exec, suExec, dl, passthru, pclose, proc_open, proc_nice, proc_terminate, proc_get_status, proc_close, leak, posix_kill, posix_mkfifo, posix_setpgid, posix_setsid, posix_setuid, posix_uname, posix_getpwuid, escapeshellcmd, escapeshellarg, fpassthru, psockopen, cmd, backtick, virtual, pcntl_exec , ini_alter, parse_ini_file, show_source, apache_child_terminate, apache_get_modules , apache_get_version , apache_note, openlog, popens, filegetcontents, get_dir, dos_conv, myshellexec, get_current_user, php_uname, fileperms, filegroup, fileowner, getmyuid, getmygid
i have set allow_url_fopen to off
and php run with phpsuexec
i have installed mod_security with accunett rules or others rules i have add it
i have install rfx network LES
my system is centos 4.4 with cpanel current version
i know the person who try to hack me and i know he is get files to my website or other web site on my server then he try hacking