Hi, I received the following email notification from my server:
WHM/cPanel root access alert from 77.30.66.116 (SA/Saudi Arabia/-)
Time: Wed Aug 15 06:55:46 2012 +0300
IP: 77.30.66.116 (SA/Saudi Arabia/-)
User: root
Since I am the only one with the password and not anywhere even near Saudi Arabia, I got little worried.
I have dedicated server with very limited support, so I asked them about this. They just basically logged in the account and said it should not be compromised since they got in, but asked me to change the root password, what I did.
Does this notification mean that someone really got in? Is there something I could do to investigate this further?
I'm not too familiar with running server so any help would be greatly appreciated!
WHM/cPanel root access alert from 77.30.66.116 (SA/Saudi Arabia/-)
Time: Wed Aug 15 06:55:46 2012 +0300
IP: 77.30.66.116 (SA/Saudi Arabia/-)
User: root
Since I am the only one with the password and not anywhere even near Saudi Arabia, I got little worried.
I have dedicated server with very limited support, so I asked them about this. They just basically logged in the account and said it should not be compromised since they got in, but asked me to change the root password, what I did.
Does this notification mean that someone really got in? Is there something I could do to investigate this further?
I'm not too familiar with running server so any help would be greatly appreciated!