hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Hosting Security and Technology : Hacker logged in via SSH - Need security audit or similar.
Reply

Hosting Security and Technology Configuring and optimizing web hosting servers and operating systems, developing administration scripts, building servers, protecting against hackers, and general security (SSL certificates, etc.)
Forum Jump

Hacker logged in via SSH - Need security audit or similar.

Reply Post New Thread In Hosting Security and Technology Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 11-14-2006, 06:29 AM
user_nick user_nick is offline
Newbie
 
Join Date: Nov 2006
Posts: 14

Hacker logged in via SSH - Need security audit or similar.


Hi we have a small company with some freebsd boxed running apache 1.3.

Lately we have been targeted by many crackers/script kiddies and proff people. And we have removed several .php files from our servers that were deployed by them and they contained scripts for searching and maybe dumping our mysql db. Last time when we files like these we searched the logs and saw a russian IP who was loggin in with my account name via SSH! So now my host has turned off all access to the server and we're trying to figure out what is going on, the SSH password was very strong so the theory is that the evil person got it from my local PC or something like that. But I have scanned my PC for spyware and i think it's unlikely they got it that way because if they did they would have ALL passwords and we have only seen this IP on 1 of the boxes.

How do we proceed from here? I do not expect my host to really be able to fix this and i would like someone to try and see if they can find the weak points.
But if we hired a security company, would we be able to trust them??

And Can you tell me if there's any way that it's possible to gather the SSh passwords from a server like mine with bad security or can we conclude that they got it from my email account or something like that - I hope not!

thank you.

the SSH password was as strong as this: "5W)rjKQ;V$hxEvz,A?" but it was also used for FTP access and I think it was also used for checking the mail account on the server, via outlook.


Last edited by user_nick; 11-14-2006 at 06:35 AM.
Reply With Quote


Sponsored Links
  #2  
Old 11-14-2006, 12:16 PM
user_nick user_nick is offline
Newbie
 
Join Date: Nov 2006
Posts: 14
Can anyone help me please?

Reply With Quote
  #3  
Old 11-14-2006, 03:41 PM
ConorP ConorP is offline
Newbie
 
Join Date: May 2005
Posts: 23
Quote:
Originally Posted by user_nick
the SSH password was as strong as this: "5W)rjKQ;V$hxEvz,A?" but it was also used for FTP access and I think it was also used for checking the mail account on the server, via outlook.
Bad idea right there. FTP and Mail access is ususally not encrypted over the wire so someone could sniff it off the network.

Although I've never had to deal with them http://www.rack911.com/ seem to get good reviews around here. You might want to try them.

Reply With Quote
Sponsored Links
  #4  
Old 11-14-2006, 06:58 PM
user_nick user_nick is offline
Newbie
 
Join Date: Nov 2006
Posts: 14
thank you for the feedback.

if not using the same pass for FTP mail and SSH, then what should we do? This is the setup our host has defined from the beginning. Is there a secure alternative to FTP? And when we check mail via outlook, should we just assume that someone is reading it while we're downloading it because it's possible?

thank you.

Reply With Quote
  #5  
Old 11-14-2006, 07:43 PM
Dacsoft Dacsoft is offline
Web Hosting Master
 
Join Date: May 2003
Location: Florida
Posts: 877
I second ConorP 's suggestion. Contact rack911.com. They can help secure your server and also assist you with correcting the passwords. I have used them in the past when a server was compromised and they did a great job.

Reply With Quote
  #6  
Old 11-14-2006, 08:56 PM
beet beet is offline
Junior Guru Wannabe
 
Join Date: Jun 2004
Posts: 37
restrict shell access to your chosen IPs, and use SFTP for file transfer. You won't have these problems if implemented.

Reply With Quote
  #7  
Old 11-14-2006, 09:23 PM
PersonalJ PersonalJ is offline
Web Hosting Master
 
Join Date: Nov 2006
Location: USA
Posts: 613
Quote:
Originally Posted by beet
restrict shell access to your chosen IPs, and use SFTP for file transfer. You won't have these problems if implemented.
You may also want to check for RSA keys for ssh.

Reply With Quote
  #8  
Old 11-15-2006, 07:01 AM
user_nick user_nick is offline
Newbie
 
Join Date: Nov 2006
Posts: 14
Thank you everyone for the tips! PersonalJihad can you explain the above in more detail?

Reply With Quote
  #9  
Old 11-15-2006, 07:17 AM
TRIBOLIS TRIBOLIS is offline
Web Hosting Master
 
Join Date: Aug 2004
Location: AU
Posts: 690
Did you disable direct root login? Without that, its likely to guess password only.

Reply With Quote
  #10  
Old 11-15-2006, 07:27 AM
doc_flabby doc_flabby is offline
Aspiring Evangelist
 
Join Date: Oct 2006
Location: uk
Posts: 448
some old versions of sshd have root exploits that mean you can obtain root without loggin in. once a machine is rooted you can install a rootkit which is undetectable so hackers can login without needin the root password. You should probabbly get expert help. The machine will need to be reformated (after taking backups of your data) in any case as you cant trust it...

__________________
Rediscover online gaming Get Continuum / Subspace | Play Trenchwars

Reply With Quote
  #11  
Old 11-15-2006, 11:52 AM
bloodyman bloodyman is offline
Web Hosting Guru
 
Join Date: Oct 2004
Posts: 283
Do you have any tips how to check if we are running old version of sshd? We are on cpanel server, running CentOS 4.4.

Thanks

Reply With Quote
Reply

Related posts from TheWhir.com
Title Type Date Posted
Hacker Leaks Customer Data Belonging to 79 Banks in US, UK, and Canada Web Hosting News 2012-06-19 14:22:18
Web Host INetU Boosts Security With Completion of SOC 2/3 Audit Web Hosting News 2012-02-29 16:16:11
Colocation Firm Waveform Completes SAS 70 Audit of Michigan Data Center Web Hosting News 2011-09-21 18:40:42
Web Host Adhost Internet Completes SSAE 16 Type II Audit Web Hosting News 2011-09-09 18:56:08
Cloud Firm Virtacore Systems Completes SSAE 16 Type II Audit Web Hosting News 2011-08-04 20:35:25


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?