Sl1k said:
Hello,
I run cPanel on multiple servers, something has been happening and I am not sure what the cause can be.
I believe I am being exploited, but i cannot trace the source of what is happening.
What happens is the /home folder will get wiped clean all the data gets deleted, this has been happening to all servers, seems like it does its rounds month after month.
I am looking for a good way to be able to trace and essentially prevent this from happening.
Any insight would be greatly appreciated.
Sl1k:p
The only way I can conceive that anyone could delete the 'home' directory which is the root in front of the actual 'public_html' directory is NOT in cpanel. The way this is done is through FTP access or if file mananger of somekind is done through actual server cp 'root_access'.
What I think is actually happening is NOT Cpanel. But, someone is hacking through annoymous FTP access.
Here are the steps to disable 'Annoymous FTP' for (ALL ACCOUNTS):
If you are using someting like Virutuisol cp for server acess, click on FTP SETUP and check the box that says disable "FTP Annoymous Login Server"
If you are using WHM (Webhost Manager) which is made by Cpanel, then you can look in the FTP setup in there and check the box that disables Annoymous FTP.
You see what happens with allowing Annoymous login ftp is that anyone can with an ftp client of somekind enter your domains, and click the "Annoymous" button and it bypasses even passwords. This is especially true with Endora FTP or even Smart FTP. You NEVER allow annoymous even for your host customers or any accounts you setup on your servers. Disable this promptly as it is a very dangerous security risks.
Please let me know in the near future if this helps your current problem.
Cheers!