Hi,
I think my site got hacked. I'm not sure how, but this is what has happened:
When i login through the WHN site with regular user/password, i get "invalid login".
I have logged into my root account on SSH (which works), and tried running
" /usr/local/cpanel/scripts/realchpass root MYPASS", but then get the following message:
I hade 32 attemts to login this night, all from China, but they are still trying for some reason. My syste was pretty thight after definition of the security advisor, so i'm not sure what has happened.
How can i restore access? Am i doing something wrong from Commandline? Or is there another way in apart from reinstall of system?
I think my site got hacked. I'm not sure how, but this is what has happened:
When i login through the WHN site with regular user/password, i get "invalid login".
I have logged into my root account on SSH (which works), and tried running
" /usr/local/cpanel/scripts/realchpass root MYPASS", but then get the following message:
Code:
File hosts.deny not changed so no update needed
[email protected] [/etc]# /usr/local/cpanel/scripts/realchpass root ************
warn [realchpass] Insecure passing of password on ARGV.
ERROR: /usr/local/cpanel/scripts/realchpass
Invocation changes only the system
password and does not have any effect
on other services associated with your
cPanel account, including FTP, SSH,
WebDAV, and FrontPage. It is strongly
encouraged for you to change the
password via the WHM & cPanel
interface. You can force a password
change through this script by setting
the environment variable
'ALLOW_PASSWORD_CHANGE=1'.
How can i restore access? Am i doing something wrong from Commandline? Or is there another way in apart from reinstall of system?