hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Hosting Security and Technology : My Server Is Hacked!!
Reply

Hosting Security and Technology Configuring and optimizing web hosting servers and operating systems, developing administration scripts, building servers, protecting against hackers, and general security (SSL certificates, etc.)
Forum Jump

My Server Is Hacked!!

Reply Post New Thread In Hosting Security and Technology Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 09-20-2006, 06:02 AM
webhostbeginner webhostbeginner is offline
Web Hosting Evangelist
 
Join Date: Mar 2005
Posts: 521
*

My Server Is Hacked!!


Hello

I have a dedicated server, it is hacked , is there anyone who can help me to investigate how they have penetrant to my server?>

Please help.

thanks

Reply With Quote


Sponsored Links
  #2  
Old 09-20-2006, 07:04 AM
rOCk-MaStEr rOCk-MaStEr is offline
WHT Addict
 
Join Date: Feb 2006
Posts: 109
what do u mean with hacked !!!!!!!
they got root access !!!
or just defaced a website or changed something !!!

please provide the following info :

uname -r

...................

last

is there is any logins thats not you !!
....................
history
and
cat /root/.bash_history

and also check if there is any commands executed not by you

Reply With Quote
  #3  
Old 09-20-2006, 07:11 AM
firestarter firestarter is offline
Web Hosting Evangelist
 
Join Date: Oct 2004
Location: India
Posts: 491
How you concluded that the server got hacked ?

__________________
ESC :wq!

Reply With Quote
Sponsored Links
  #4  
Old 09-20-2006, 07:55 AM
webhostbeginner webhostbeginner is offline
Web Hosting Evangelist
 
Join Date: Mar 2005
Posts: 521
Thanks for your help

the 2.6.9-34.0.2.ELsmp in the resul of uname -r

and teher are some command that I have not executed and don't know what they do. would you please tae a look at them?

echo /dev/null > /proc/sys/kernel/core_pattern
Modify /etc/sysctl.conf
pico /etc/sysctl.conf
mount -o remount,noexec,nosuid /proc
pico /etc/fstab



lynx -source http://go-pear.org/ | php
pear install Mail
pear install Net_SMTP



Thanks

Reply With Quote
  #5  
Old 09-20-2006, 07:59 AM
webhostbeginner webhostbeginner is offline
Web Hosting Evangelist
 
Join Date: Mar 2005
Posts: 521
Thanks for yout help

This is the uname -r result is 2.6.9-34.0.2.ELsmp

and I checked the bach history and there were some command that I have not executed.
would you please taka a look at them?

echo /dev/null > /proc/sys/kernel/core_pattern
Modify /etc/sysctl.conf
pico /etc/sysctl.conf
mount -o remount,noexec,nosuid /proc
pico /etc/fstab



lynx -source http://go-pear.org/ | php
pear install Mail
pear install Net_SMTP


Thanks

Reply With Quote
  #6  
Old 09-20-2006, 08:02 AM
firestarter firestarter is offline
Web Hosting Evangelist
 
Join Date: Oct 2004
Location: India
Posts: 491
Seems that someone hardened the server and installed net-snmp to monitor the server bandwidth usages to me. Ask your DC if they did anything on your server.

__________________
ESC :wq!

Reply With Quote
  #7  
Old 09-20-2006, 02:29 PM
tamar tamar is offline
Junior Guru
 
Join Date: May 2006
Posts: 232
Which company do you have a dedicated server on? I don't think my dedicated server company would ever install anything without my authorization first.

What made you conclude that you were hacked? Is it because you logged in and saw that the last login IP wasn't yours? (Do you have root logins disabled?)

__________________
I'm female.

Reply With Quote
  #8  
Old 09-20-2006, 04:53 PM
besty besty is offline
Web Hosting Master
 
Join Date: Mar 2006
Posts: 644
Are you facing any low performance on the server or malicious activity taking place?

__________________
Live Your DreamZ
~Besty

Reply With Quote
  #9  
Old 09-20-2006, 05:55 PM
layer0 layer0 is offline
Performance Specialist
 
Join Date: Dec 2004
Location: New York, NY
Posts: 10,341
Quote:
2.6.9-34.0.2.ELsmp
Update your kernel!

__________________
MediaLayer, LLC - Lightning fast web hosting since 2005. Ask about our new pure SSD storage platform!
›› First and leading provider of LiteSpeed based hosting combined with enterprise grade hardware.
›› Free Account Migrations, Custom Solutions, and Servers in US, EU, and Asia
›› Our Application Hosting plans outperform the typical VPS. Ask us about special offers on yearly plans!

Reply With Quote
  #10  
Old 09-20-2006, 05:57 PM
rOCk-MaStEr rOCk-MaStEr is offline
WHT Addict
 
Join Date: Feb 2006
Posts: 109
he still didn't explain .... what happend to make him say its hacked !!

Reply With Quote
  #11  
Old 09-21-2006, 06:03 AM
webhostbeginner webhostbeginner is offline
Web Hosting Evangelist
 
Join Date: Mar 2005
Posts: 521
the group that has hacked us has informed us and has upload a file on all our accounts on my server,
Thast why I think it is hacked, but I don't think wheather he has the root access because if so he would deffenetely change the password.

I just want to know how he has entered our server and uploaded that files on the server.

Thanks for your replies

Reply With Quote
  #12  
Old 09-21-2006, 10:31 AM
rOCk-MaStEr rOCk-MaStEr is offline
WHT Addict
 
Join Date: Feb 2006
Posts: 109
what type of files he uploaded !!!
a deface like hacked by..............
are you using PhpSuexec or running apache as nobody
are turning SafeMode on or not !!

Reply With Quote
  #13  
Old 09-21-2006, 11:45 AM
tamar tamar is offline
Junior Guru
 
Join Date: May 2006
Posts: 232
Quote:
Originally Posted by IRLAMP
the group that has hacked us has informed us and has upload a file on all our accounts on my server,
Thast why I think it is hacked, but I don't think wheather he has the root access because if so he would deffenetely change the password.

I just want to know how he has entered our server and uploaded that files on the server.

Thanks for your replies
Have you confirmed that those files exist?

Honestly, most hackers won't tell you their backdoors. Just secure your system as best as you can or hire a company to do so.

__________________
I'm female.

Reply With Quote
  #14  
Old 09-21-2006, 08:44 PM
Website Rob Website Rob is offline
learning is in the doing
 
Join Date: Sep 2000
Location: Alberta, Canada
Posts: 3,109
Sounds like a site defacement situation for every/most accounts on the Server.

Login to shell and run this command: /scripts/hackcheck
If it returns the following you are OK, sort of.
findutils passes checksum
net-tools passes checksum

Anything else means your Server has been rooted (taken over by someone else) and your only recourse is an OS reload. If your Server has not been rooted, should take about 2 hrs. for an experienced person to find and remove the hacker files and harden your Server security.

__________________
PotentProducts.com - for all your Hosting needs
Helping people Host, Create and Maintain their Web Site
ServerAdmin Services also available

Reply With Quote
  #15  
Old 09-22-2006, 04:49 AM
juangake juangake is offline
Web Hosting Guru
 
Join Date: Nov 2005
Location: Palma de Mallorca, Spain
Posts: 259
Quote:
Originally Posted by Website Rob
Login to shell and run this command: /scripts/hackcheck
If it returns the following you are OK, sort of.
findutils passes checksum
net-tools passes checksum
I was wondering how this "hackcheck" script goes with every linux distribution, but not in my CentOS 4.4 What Linux/Unix do you have?

Reply With Quote
Reply

Related posts from TheWhir.com
Title Type Date Posted
SwaggSec Hackers Release 900 Admin Credentials from China Telecom Attack Web Hosting News 2012-06-04 15:24:03
Whistleblower Site Cryptome Hacked, Infects PCs with Drive-By Exploits Web Hosting News 2012-02-14 14:48:24
Security Firm ArtSec Launches Website and Server Migration Service Web Hosting News 2011-12-09 18:43:03
Bangladeshi Hacker TiGER-M@TE Targets InMotion Hosting Web Hosting News 2011-09-26 15:24:05
Toshiba Server Breach Compromises Email Information of 681 Customers Web Hosting News 2011-07-18 17:29:46


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?