Since a week im dealing with multiple ftp hacking issues on cpanel in one server. As far I could investigate the uploads were done by ftp login and through cpanel file manager (assuming that both cpanel login and ftp login is the same)
All the hacks had to do with phishing sites like Bank of America, a Google Docs and other stuff.
On thing i figured is to disable file manager for the feature manager. Ok the icon goes away from cpanel, but if you put the direct folder on the address bar you gain access to the filemanager template so I desided to remove the filemanager folder from the x3 theme entirely.
By the accounts i set the password strenght to 70 and changed the password to the accounts that were compromised (not hacked again anymore) but still appearing new ones.
Is rare what happened cause one the compromised accounts was one of mine and has a very strong password.
Wait comments.
All the hacks had to do with phishing sites like Bank of America, a Google Docs and other stuff.
On thing i figured is to disable file manager for the feature manager. Ok the icon goes away from cpanel, but if you put the direct folder on the address bar you gain access to the filemanager template so I desided to remove the filemanager folder from the x3 theme entirely.
By the accounts i set the password strenght to 70 and changed the password to the accounts that were compromised (not hacked again anymore) but still appearing new ones.
Is rare what happened cause one the compromised accounts was one of mine and has a very strong password.
Wait comments.