hackers

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • halyfax
    Senior Member
    • Mar 2004
    • 124

    #1

    hackers

    if anyone else had problems with hackers let me know. I had a handful of sites hacked and I have yet to figure out how. they are different accounts on the same reseller account on cpanel28. Sites were developed by different people with different passwords. none using the same scripts etc.

    the hacker just changed the index.html page, and for some of the accounts actually changed the sites contact email to theirs.

    sounds like they had access to cpanel or something and it is funny it affected only a portion of my sites.

    any advice?

    p.
  • sdjl
    Senior Member
    • Mar 2004
    • 502

    #2
    It may be worth contacting support regarding this.
    -----
    Do you fear the obsolescence of the metanarrative apparatus of legitimation?

    Comment

    • halyfax
      Senior Member
      • Mar 2004
      • 124

      #3
      I did contact support regarding this matter and Andrew responded that he could not find anything out of the ordinary.

      I have since changed all my passwords hoping this may be of some help although I am not sure it will be of any help to me at this point.

      Is there anything I should be checking in permissions or something any advice would be great. Seeing as it was in multiple accounts all on my account I find this strange.

      Comment

      • sdjl
        Senior Member
        • Mar 2004
        • 502

        #4
        If they're not running the same software, then no, not really.
        Just advise your customers to be more wary of online security and to check their computers for spyware/viruses/etc.

        David
        -----
        Do you fear the obsolescence of the metanarrative apparatus of legitimation?

        Comment

        • Pedja
          Senior Member
          • Mar 2004
          • 329

          #5
          Hmmm. Dathon support could at least check what IP's from those alterations to your site were done. It could lead you to somewhere.

          If one has your whm account password he can access any cpanel account.

          Comment

          • halyfax
            Senior Member
            • Mar 2004
            • 124

            #6
            I actually provided the isp # from the hacker to support. But they didn't respond to it. I accessed the isp # from within the cpanel accounts with the last login isp. I checked all the hacked accounts and the isp # was the same.

            200.90.221.166.

            Comment

            • AndrewT
              Administrator
              • Mar 2004
              • 3655

              #7
              Originally posted by halyfax
              I actually provided the isp # from the hacker to support. But they didn't respond to it. I accessed the isp # from within the cpanel accounts with the last login isp. I checked all the hacked accounts and the isp # was the same.

              200.90.221.166.
              I must not have told you this, but I did look into the Apache access logs from that IP and there was nothing abnormal from that IP. Those are the only logs that would even record some relevant information with the IP.

              Comment

              • globalstorm
                Junior Member
                • May 2004
                • 5

                #8
                one Site hacked

                I had one site hacked (on CPanel08). Index.html was changed. They used a script from CMS Mambo 4.51.

                Cheers
                Kirby

                Comment

                • halyfax
                  Senior Member
                  • Mar 2004
                  • 124

                  #9
                  It is strange that that ip had nothing strange because it was recorded as the last cpanel login on different accounts from different customers of mine all using different isp's, so I knew it wasn't them logging in with that ip.

                  I just hope it doesn't happen again. I figure they somehow got into whm or something, how else could they enter multiple accounts and also change the contact email in some of those cpanel accounts. thanks for everyone's input. If anyone else has had this happen please share if you discovered what they were using.

                  cheers

                  Comment

                  • Jonathan
                    Senior Member
                    • Mar 2004
                    • 1229

                    #10
                    You can always make a nice PHP script to phrase
                    whatever you enter, through md5().

                    Do this maybe five times (different words), each time
                    cutting a small chunk from it. ~ then combine that, run it through.
                    Then cut two parts of that out, combie to form your password.
                    "How can someone be so distracted yet so focused?"
                    - C

                    Comment

                    • halyfax
                      Senior Member
                      • Mar 2004
                      • 124

                      #11
                      isn't mambo 4.5.1 the most recent version? have they had a security update? Scarry as this is a script available in the cpanel scripts library

                      after checking the cpanel library has an outdated version of mambo. there is a new security update on their site.

                      Comment

                      • Jonathan
                        Senior Member
                        • Mar 2004
                        • 1229

                        #12
                        Originally posted by halyfax
                        isn't mambo 4.5.1 the most recent version? have they had a security update? Scarry as this is a script available in the cpanel scripts library

                        after checking the cpanel library has an outdated version of mambo. there is a new security update on their site.
                        cPanel's version is always a handful behind...
                        Nothing Dathorn can do about it.
                        "How can someone be so distracted yet so focused?"
                        - C

                        Comment

                        Working...