Hello!
Today 14 accounts on one server was deleted.
After checking this I found that it was a reseller account deleting them.
This reseller account had root priviligies.
The reseller account was setup by the "hacker".
It is not one of our clients so we have not installed this account.
After going over our servers I found one more account on another server
and the password it had was: hackedhost010.
I restore the deleted accounts and suspended the "hacker account".
I change root password, force cpanel upgrade.
chrootkit and rkhunter report nothing.
What else should I do ?
What has happened - how ??
Anyone, please give your thoughts on what I should do next!!
Logs/info:
[email protected] [~]# grep arabserv /var/log/*
/var/log/secure:Dec 15 14:59:14 gais groupadd[23494]: new group: name=arabserv, gid=32283
/var/log/secure:Dec 15 14:59:14 gais useradd[23496]: new user: name=arabserv, uid=32282, gid=32283, home=/home/arabserv, shell=/bin/bash
/var/log/secure:Dec 15 15:05:41 gais Cp-Wrap[30620]: Pushing "32282 RESELLERSUSERS arabserv " to '/usr/local/cpanel/bin/reselleradmin' for UID: 32282
/var/log/secure:Dec 15 15:05:41 gais Cp-Wrap[30622]: Pushing "32282 GETDOMAINIP arabservers.com " to '/usr/local/cpanel/bin/apacheadmin' for UID: 32282
/var/log/exim_mainlog:2006-12-15 14:59:21 1GvDar-00068i-B7 <= [email protected] U=root P=local S=717 T="New account on zzzhostzz.com (arabservers.com)" from <[email protected]> for [email protected]
/var/log/messages:Dec 15 14:59:18 gais named[1976]: zone arabservers.com/IN: loaded serial 2006121501
/var/log/messages:Dec 15 14:59:18 gais named[1976]: zone arabservers.com/IN: sending notifies (serial 2006121501)
/var/log/messages:Dec 15 14:59:18 gais named[1976]: received notify for zone 'arabservers.com'
Mail new account:
+===================================+
| New Account Info |
+===================================+
| Domain: serv2arab.com
| Ip: dd.dd.dd.dd (n)
| HasCgi: y
| UserName: serv2ara
| PassWord: 151213
| CpanelMod: x
| HomeRoot: /home
| Quota: 0 Meg
| NameServer: ns1.xxzzxx.com
| Contact Email:
+===================================+
Account was setup by: root (root)
Today 14 accounts on one server was deleted.
After checking this I found that it was a reseller account deleting them.
This reseller account had root priviligies.
The reseller account was setup by the "hacker".
It is not one of our clients so we have not installed this account.
After going over our servers I found one more account on another server
and the password it had was: hackedhost010.
I restore the deleted accounts and suspended the "hacker account".
I change root password, force cpanel upgrade.
chrootkit and rkhunter report nothing.
What else should I do ?
What has happened - how ??
Anyone, please give your thoughts on what I should do next!!
Logs/info:
[email protected] [~]# grep arabserv /var/log/*
/var/log/secure:Dec 15 14:59:14 gais groupadd[23494]: new group: name=arabserv, gid=32283
/var/log/secure:Dec 15 14:59:14 gais useradd[23496]: new user: name=arabserv, uid=32282, gid=32283, home=/home/arabserv, shell=/bin/bash
/var/log/secure:Dec 15 15:05:41 gais Cp-Wrap[30620]: Pushing "32282 RESELLERSUSERS arabserv " to '/usr/local/cpanel/bin/reselleradmin' for UID: 32282
/var/log/secure:Dec 15 15:05:41 gais Cp-Wrap[30622]: Pushing "32282 GETDOMAINIP arabservers.com " to '/usr/local/cpanel/bin/apacheadmin' for UID: 32282
/var/log/exim_mainlog:2006-12-15 14:59:21 1GvDar-00068i-B7 <= [email protected] U=root P=local S=717 T="New account on zzzhostzz.com (arabservers.com)" from <[email protected]> for [email protected]
/var/log/messages:Dec 15 14:59:18 gais named[1976]: zone arabservers.com/IN: loaded serial 2006121501
/var/log/messages:Dec 15 14:59:18 gais named[1976]: zone arabservers.com/IN: sending notifies (serial 2006121501)
/var/log/messages:Dec 15 14:59:18 gais named[1976]: received notify for zone 'arabservers.com'
Mail new account:
+===================================+
| New Account Info |
+===================================+
| Domain: serv2arab.com
| Ip: dd.dd.dd.dd (n)
| HasCgi: y
| UserName: serv2ara
| PassWord: 151213
| CpanelMod: x
| HomeRoot: /home
| Quota: 0 Meg
| NameServer: ns1.xxzzxx.com
| Contact Email:
+===================================+
Account was setup by: root (root)