hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Hosting Security and Technology : Someone Hacked my Servers!!!
Reply

Hosting Security and Technology Configuring and optimizing web hosting servers and operating systems, developing administration scripts, building servers, protecting against hackers, and general security (SSL certificates, etc.)
Forum Jump

Someone Hacked my Servers!!!

Reply Post New Thread In Hosting Security and Technology Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 05-25-2011, 11:00 AM
Rezaa Rezaa is offline
Junior Guru
 
Join Date: Apr 2010
Posts: 244

Someone Hacked my Servers!!!


Hello

yesterday, I received an email from someone. he said he hacked my both windows and linux servers and also sent my passwords to me !
He hacked my linux and windows servers and also whmcs.
gladly, I still have access to my servers. but I don't know how he hacked my servers.
I'm sure, he is one of my customers, but I don't know which one.

How can I find that, how he hacked my servers? and how can I increase my servers security.
I configured php.ini and disabled some functions, but how can I prevent updloading shells and other malicious applications on my servers?

also how can I secure windows server? I'm new in windows security and need some help


Regards

Reply With Quote


Sponsored Links
  #2  
Old 05-25-2011, 11:08 AM
wdteam wdteam is offline
Junior Guru Wannabe
 
Join Date: May 2007
Posts: 81
If you still have access to both servers, I would suggest you to change root passwords immediately. It would be better if you change them from another computer.

He can control you via trojans or other viruses that probably running on your pc.

Reply With Quote
  #3  
Old 05-25-2011, 11:23 AM
Rezaa Rezaa is offline
Junior Guru
 
Join Date: Apr 2010
Posts: 244
I changed my passwords and ssh port yesterday.

How can I find trojans and viruses on my pc?

Reply With Quote
Sponsored Links
  #4  
Old 05-25-2011, 11:25 AM
Rezaa Rezaa is offline
Junior Guru
 
Join Date: Apr 2010
Posts: 244
I believe he can find my passwords again, how can I prevent him ?

Reply With Quote
  #5  
Old 05-25-2011, 11:32 AM
cpanellover cpanellover is offline
Aspiring Evangelist
 
Join Date: Aug 2005
Location: behind my screen
Posts: 396
Quote:
Originally Posted by Rezaa View Post
How can I find trojans and viruses on my pc?
hmmmm don't you know that ?

Reply With Quote
  #6  
Old 05-25-2011, 11:36 AM
wdteam wdteam is offline
Junior Guru Wannabe
 
Join Date: May 2007
Posts: 81
I would suggest you to switch on Linux or Mac os which provides 99% protection against trojans and viruses. That's general suggestion to prevent such issues in the future.

Regarding current situation, install Kaspersky and make full scan.

Reply With Quote
  #7  
Old 05-25-2011, 11:36 AM
Rezaa Rezaa is offline
Junior Guru
 
Join Date: Apr 2010
Posts: 244
I scaned my pc with kaspersky yesterday, but no infected files found!
do you know any powerful trojan killer?

Reply With Quote
  #8  
Old 05-25-2011, 11:40 AM
wdteam wdteam is offline
Junior Guru Wannabe
 
Join Date: May 2007
Posts: 81
Quote:
Originally Posted by Rezaa View Post
I scaned my pc with kaspersky yesterday, but no infected files founded!
do you know any powerful trojan killer?
If this guy true hacker, he probably was able to create unique trojan that wasn't detected by Kaspersky due to its fresh and unknow status for virus database. I was in such situation years ago.

However if you scanned yesterday and it doesn't show viruses, its good sign.

Reply With Quote
  #9  
Old 05-25-2011, 11:43 AM
Rezaa Rezaa is offline
Junior Guru
 
Join Date: Apr 2010
Posts: 244
I guess he is one of my customers, and he usedl shell applications to access root. How can I find which customer he is?

Reply With Quote
  #10  
Old 05-25-2011, 12:15 PM
bear bear is offline
Community Leader
 
Join Date: Oct 2002
Location: cognito
Posts: 17,289
Quote:
Originally Posted by seosuperhero View Post
I would suggest you to switch on Linux or Mac os which provides 99% protection against trojans and viruses.
No, it doesn't. The only reason there are less infections is that less people use them so less are written for those platforms. It's not protection, it's lack of market share.
Quote:
Originally Posted by Rezaa View Post
I guess he is one of my customers, and he usedl shell applications to access root. How can I find which customer he is?
Find the shell script(s), and then comb the logs to see where and how it was added to the server.

__________________
Have problems (don't we all)? Head over to the help desk
If at first you don't succeed, that's one data point.


Reply With Quote
  #11  
Old 05-25-2011, 12:22 PM
Chris_M Chris_M is offline
Community Liaison
 
Join Date: Oct 2004
Location: Ohio
Posts: 1,553
On the linux box, you should install http://www.rfxn.com/projects/linux-malware-detect/ and ClamAV and do a scan. This should help you locate any shell apps.

__________________
WebNX.com - Professional Hosting Solutions – Premium Los Angeles Servers and Colo
Quality Dedicated Servers in Los Angeles – From single core to 64 core servers 2GB ram to 512GB Ram
1 hard drive to 45+ drive setups. sales@webnx.com

Have you tried the new Intel Xeon e5's yet?

Reply With Quote
  #12  
Old 05-25-2011, 12:45 PM
Rezaa Rezaa is offline
Junior Guru
 
Join Date: Apr 2010
Posts: 244
Quote:
Originally Posted by Chris_M View Post
On the linux box, you should install http://www.rfxn.com/projects/linux-malware-detect/ and ClamAV and do a scan. This should help you locate any shell apps.
I have clamav installed on my server but it didn't show any virus on my server. just some files in /mail/news directory of my main domain. do you think they are shell apps?

Quote:
Originally Posted by bear View Post
No, it doesn't. The only reason there are less infections is that less people use them so less are written for those platforms. It's not protection, it's lack of market share.

Find the shell script(s), and then comb the logs to see where and how it was added to the server.
thank you, I'll try it tonight

Reply With Quote
  #13  
Old 05-25-2011, 12:47 PM
Chris_M Chris_M is offline
Community Liaison
 
Join Date: Oct 2004
Location: Ohio
Posts: 1,553
Quote:
Originally Posted by Rezaa View Post
I have clamav installed on my server but it didn't show any virus on my server. just some files in /mail/news directory of my main domain. do you think they are shell apps?



thank you, I'll try it tonight
Install the app I linked to and rescan. It will help you locate many things that may be on the system. Shell apps can land anywhere if the attacker has already compromised the system. Why not open the files in an editor and see what the contents are?

__________________
WebNX.com - Professional Hosting Solutions – Premium Los Angeles Servers and Colo
Quality Dedicated Servers in Los Angeles – From single core to 64 core servers 2GB ram to 512GB Ram
1 hard drive to 45+ drive setups. sales@webnx.com

Have you tried the new Intel Xeon e5's yet?

Reply With Quote
  #14  
Old 05-25-2011, 01:08 PM
Scott.Mc Scott.Mc is offline
Engineer
 
Join Date: Jan 2005
Location: Scotland, UK
Posts: 2,379
Quote:
Originally Posted by Rezaa View Post
he hacked my both windows and linux servers and also sent my passwords to me !
He hacked my linux and windows servers and also whmcs.
I take it you stored the passwords to the servers in whmcs? Somewhere that you stored the auth details was compromised, most likely whmcs, hence why your servers were then compromised. Pretty basic firewalls + authentication methods could have prevented that from escalating to all your systems.

__________________
Server Management - AdminGeekZ.com
Infrastructure Management, Web Application Performance, mySQL DBA. Keep your servers online.
United Kingdom: *0800 8620073* // United States: *585 563 1729* // Australia: *02 9037 2448* // International: *+44.1412800134*
Scott Mcintyre

Reply With Quote
  #15  
Old 05-25-2011, 01:15 PM
TexasCrane TexasCrane is offline
Junior Guru Wannabe
 
Join Date: Jan 2011
Posts: 33
Am I the only person that finds the lack of server admin/security knowledge among many people providing hosting services to be frightening and possibly even negligent?

I mean if you don't know how to secure a server (or even scan your own pc for malware), why would you think you're qualified to offer hosting services?

To the OP, you need to contact somebody like Rack911 and pay them to fix this for you and lock down your servers so this doesn't happen again in the future. Based on your posts there is virtually no chance you're going to figure out what happened on your own, much less fix it.

Reply With Quote
Reply

Similar Threads
Thread Thread Starter Forum Replies Last Post
Help I think my servers been hacked` Kmaid Hosting Security and Technology 5 11-14-2007 02:16 PM
Hacked servers and your business ICALIV Dedicated Server 18 04-01-2004 05:52 PM
servers down? all windows servers hacked with ddos atjeu Dedicated Server 38 01-28-2003 11:59 AM
Hacked RS servers? What happens to them. jic Dedicated Server 18 11-13-2002 04:52 AM

Related posts from TheWhir.com
Title Type Date Posted
SwaggSec Hackers Release 900 Admin Credentials from China Telecom Attack Web Hosting News 2012-06-04 15:24:03
Parallels Plesk Flaw Left FTC Websites Open to Security Breaches Web Hosting News 2012-02-23 13:32:43
Dutch Security Firm Gemnet and Certificate Authority Division Gemnet CSP Offline Following Hack Web Hosting News 2011-12-09 15:33:53
Bangladeshi Hacker TiGER-M@TE Targets InMotion Hosting Web Hosting News 2011-09-26 15:24:05
South Korean Domain Registrar Gabia, Epson Korea Websites Hacked Web Hosting News 2011-08-24 14:04:01


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?