cpanel21 Compromised & Upgrade

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • AndrewT
    Administrator
    • Mar 2004
    • 3653

    cpanel21 Compromised & Upgrade

    I'm not going to disclose too much information at this time, but cpanel21 has been compromised through the use of a customer's account which has now been disabled entirely. This user performed a mass defacement of all file names beginning with "index" or "home".

    We can no longer ensure the integrity of the cpanel21 server so all customers will be moved to other servers. Currently we are backing up all of the accounts and transfering the files to another server for safe storage. All users will have to restore any files that may have been defaced unless you are paying for our backup service.

    Right now we're waiting on additional hardware to setup cpanel47 so that we can move all cpanel21 customers to this server. I do not have an ETA on this at this time. Most of our spare hardware was used last week during the cpanel35 failure so not all parts are on hand.

    I'll continue to update this thread as more information is available.
  • AndrewT
    Administrator
    • Mar 2004
    • 3653

    #2
    Most of the accounts have already been backed up and the backup files have been transfered to another server temporarily. Until cpanel47 is ready to go we will maintain cpanel21 as best as possible.

    You should go ahead and replace all files that have names that begin with "home" or "index" along with logo.jpg and login.php files. Note that in most cases you will have to do this again on cpanel47 since the backups have already been made.

    We've already identified the single customer responsible for this but the server integrity is still questionable so we are not going to take any chances, all customers will be moved to cpanel47.

    Comment

    • AndrewT
      Administrator
      • Mar 2004
      • 3653

      #3
      All newly created backups have been transfered on to the temporary server. We've just received the remaining hardware for cpanel47 and it should be ready to go within the next 2-3 hours. At that point we will then begin restoring accounts on cpanel47.

      Comment

      • AndrewT
        Administrator
        • Mar 2004
        • 3653

        #4
        All reseller accounts have been transfered to cpanel47 and you should now be able to login to WHM. Please do not do anything with this login at this time other than monitor your account list.

        All of the backup files have been transfered to cpanel47 already and the remaining accounts are now restoring as well.

        More information on this server will be posted once we receive the remaining IP allocations for the cpanel47 nameservers.

        Comment

        • AndrewT
          Administrator
          • Mar 2004
          • 3653

          #5
          Accounts are still being restored to cpanel21. This process should be complete by later this morning at which point DNS information for the new server will be provided.

          Comment

          • AndrewT
            Administrator
            • Mar 2004
            • 3653

            #6
            All accounts have been restored to cpanel47. We're still waiting on our new nameserver IPs to be allocated to us from The Planet. Since cpanel21 is currently functioning fairly normally we are not going to push this final step until everything is ready to go.

            However, meanwhile, you can access your domains on cpanel47 and update any files that may need to be updated.

            Comment

            • AndrewT
              Administrator
              • Mar 2004
              • 3653

              #7
              cpanel47 is now completely setup and ready to go. Please make DNS changes as necessary.

              If you login to the customer control panel and view your welcome e-mail, it should now list cpanel47 as your server.

              Instead of being on cpanel21, all customers are now on cpanel47.

              Server: cpanel47.gzo.com - 67.19.34.210
              DNS #1: dns93.gzo.com - 67.19.34.212
              DNS #2: dns94.gzo.com - 67.18.113.56

              IMPORTANT
              Anyone that has custom nameservers or that has used the cpanel21 DNS IP addresses (69.56.139.10 and 69.56.139.11) for anything will need to update their entries to the new nameservers and IPs listed above.

              Those that are using the cpanel21 gzo.com nameservers (dns41/dns42) will need to update their nameservers to use the new dns93 and dns94 nameservers.

              Also, you may need to re-install SSL certificates on the new server (cpanel47). If you purchased one from us simply submit a ticket and we can re-install it for you.

              Comment

              • AndrewT
                Administrator
                • Mar 2004
                • 3653

                #8
                HTTP on cpanel21 will be disabled on 8/14/06. Please be sure that all DNS changes are made well before this.

                Comment

                • AndrewT
                  Administrator
                  • Mar 2004
                  • 3653

                  #9
                  HTTP has been disabled on cpanel21. cpanel21 will be taken offline entirely on 8/21/06.

                  Comment

                  • AndrewT
                    Administrator
                    • Mar 2004
                    • 3653

                    #10
                    cpanel21 has now been taken offline entirely.

                    Comment

                    Working...