hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Dedicated Server : How did my developer get access to my server after I deleted his FTP user account?
Reply

Dedicated Server Current and past experiences with dedicated server providers, bandwidth, and server performance. Review managed and unmanaged dedicated web servers, discuss both Windows and Unix dedicated server solutions, and discuss dedicated hosting providers. If your service is unavailable, please click here.
Forum Jump

How did my developer get access to my server after I deleted his FTP user account?

Reply Post New Thread In Dedicated Server Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 06-06-2011, 06:15 PM
Eldan88 Eldan88 is offline
Junior Guru Wannabe
 
Join Date: Sep 2009
Posts: 49

How did my developer get access to my server after I deleted his FTP user account?


HI,


I have been working with my developer for a while. He used to have access to the root folder a while ago. I have then seen some strange activity on the server 1 month ago. Therefore I have restricted access to a specific folder that he needs to work on, and changed the cpanel and WHM passwords so he won't access it.

Today I fired him, however right before I fired him I deleted all his user accounts, so he won't access the server. He then somehow accessed my server a few hours later and overwritten all my new files with some old files I previously has.

When I submitted a ticket regarding this, softlayer couldn't find a trace of him logging in to the specific directory . Then I spoke with softlayer again and they said that he might have opened a backdoor if he had access to my previous files.

How might this happen? Were can I find a service that patch up the open holes he got int through?

Reply With Quote


Sponsored Links
  #2  
Old 06-06-2011, 06:20 PM
chasebug chasebug is offline
Web Hosting Master
 
Join Date: Apr 2009
Posts: 1,320
You shouldn't have allowed him access to your production server at all. What I do is get a VPS and let the developer work on there. I manually transfer the changes to the production server. I think you should consider something like this in the future.

Reply With Quote
  #3  
Old 06-06-2011, 06:31 PM
MMrs MMrs is offline
WHT Addict
 
Join Date: May 2008
Posts: 117
Looks like he didn't get what he wanted for his/her job and just removed it.
He probably wrote backdoor into his project so in case he get fired or scammed he could just delete his work.
I might be wrong.

Reply With Quote
Sponsored Links
  #4  
Old 06-06-2011, 06:49 PM
Dougy Dougy is offline
Rockin' the beer gut
 
Join Date: May 2006
Location: NJ, USA
Posts: 6,032
Or a ssh key.

__________________
simplywww: directadmin and cpanel hosting that will rock your socks
coming very soon: Cheapest Comodo SSL certificates on the market

Need some work done in a datacenter in the NYC area? NYC Remote Hands can do it.

Reply With Quote
  #5  
Old 06-06-2011, 08:33 PM
Ufkabakan Ufkabakan is offline
Newbie
 
Join Date: Dec 2010
Posts: 26
Maybe he was uploaded a Perl Script for acces like FTP.

Reply With Quote
  #6  
Old 06-06-2011, 09:24 PM
TheJoker TheJoker is offline
Web Hosting Master
 
Join Date: Oct 2010
Posts: 1,778
Karma?

__________________
Hosting is like a box of chocolates, you never know what you're gonna get.

Reply With Quote
  #7  
Old 06-06-2011, 09:26 PM
Azar-A Azar-A is offline
WHT Addict
 
Join Date: Jan 2003
Location: Budapest, Hungary
Posts: 100
Probably a backdoor. You should check the scripts. Also if he had root, you probably should rkhunt and chkrootkit also.
Also look for additional software running and listening, like in inetd.conf or in linux you can find out which software is listening by using 'netstat -ln' command, in freebsd it's easier to use sockstat -l, in windows as far as i remember it's netstat -nb

__________________
ServerAstra.com website / e-mail: info @ serverastra.com
HU/EU Co-Location / Managed and Unmanaged VDS & Dedicated servers in Hungary with unmetered connections


Last edited by Azar-A; 06-06-2011 at 09:33 PM.
Reply With Quote
Reply

Similar Threads
Thread Thread Starter Forum Replies Last Post
Remote backups with user ftp access RW-Steven Running a Web Hosting Business 5 03-19-2007 02:53 AM
FTP access for user anlene Hosting Security and Technology 3 06-05-2006 12:24 PM
ftp from SSH as user and access / (root) .com Hosting Security and Technology 2 09-04-2003 06:38 AM
how do i create a root user with ftp access to entire server? kimrari Hosting Security and Technology 10 05-21-2003 06:37 PM
Restrict access for ftp user? keyDet79 Hosting Security and Technology 3 04-20-2003 05:44 AM

Related posts from TheWhir.com
Title Type Date Posted
Colocation America to Support Fedora Linux Project with Dedicated Server Web Hosting News 2012-08-17 09:49:26
DiscountASP.NET Launches Free Beta for Microsoft SQL Server 2012 Hosting Web Hosting News 2011-12-13 22:02:03
Stonesoft Releases Secure Authentication Portal for Cloud Environments Web Hosting News 2011-09-30 17:51:25
Web Host A2 Hosting Launches QuickInstaller Tool for VPS Plans Web Hosting News 2011-08-19 20:00:53
LinkedIn Access Cookie Opens Users to Security Breaches, says Security Analyst Web Hosting News 2011-05-24 14:19:01


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?