hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Hosting Security and Technology : Anyone got hack before?
Reply

Hosting Security and Technology Configuring and optimizing web hosting servers and operating systems, developing administration scripts, building servers, protecting against hackers, and general security (SSL certificates, etc.)
Forum Jump

Anyone got hack before?

Reply Post New Thread In Hosting Security and Technology Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 09-21-2002, 11:52 AM
albertg albertg is offline
Junior Guru Wannabe
 
Join Date: Sep 2002
Posts: 30

Anyone got hack before?


Hello everyone!

I think my server (running as a web host on Red Hat Linux 7.2 and cPanel) was hacked.

What is the best solutions. I am quite a newbie and started my web hosting bizness a couple months ago.

What are the steps i should do and can do to prevent such from happening again?

Someone is sending out alot SPAM MAILS from nobody@hostname
So i suppose it is internal ..It should not be a buggy mail script (cgi) because i have check that.

What should i do..any ideas...solutions..advise will be very very much appreciated.

Anyone of you got your server hacked before? What do you do to prevent it from happening again? How often this kinda things happen?
Thank You very very much!

Have a nice day! and thank you for your time.

Reply With Quote


Sponsored Links
  #2  
Old 09-21-2002, 12:00 PM
Webdude Webdude is offline
Web Hosting Master
 
Join Date: Dec 2000
Location: The Woodlands, Tx
Posts: 5,955
Maybe get rid of Cpanel for a better control panel?

Seriously though, first thing you need to do is command line to your server and do the following command..

locate -i formmail.pl

Chmod all the ones it finds to 000 and chown them to root ownership. Formmail.pl allows anyone to spam thru a client's account, and has been banned from most hosts. Spammers can scan domains to see if there is a formmail.pl on any of them, and abuse them when they find them.

Reply With Quote
  #3  
Old 09-21-2002, 12:17 PM
albertg albertg is offline
Junior Guru Wannabe
 
Join Date: Sep 2002
Posts: 30
Thank you for your input...any further advise will be very very very much appreciated..any advise....thanks...

Reply With Quote
Sponsored Links
  #4  
Old 09-21-2002, 12:55 PM
Andrew Andrew is offline
Web Hosting Master
 
Join Date: Jul 2002
Posts: 3,729
Or if you have a lot of clients who use formmail.pl and don't want to inconvenience the innocent ones, you can

pico formmail.pl

after you locate all of them and check the version number on each one to make sure it's the latest version.

Reply With Quote
  #5  
Old 09-21-2002, 12:58 PM
albertg albertg is offline
Junior Guru Wannabe
 
Join Date: Sep 2002
Posts: 30
Let say if the problem is not formmail...what can it be..I have check that and have ask my provider to check that...they also agree that most prob my server was hacked..and somehow..the hacker is able to send mail via my machine..using nobody account...

Reply With Quote
  #6  
Old 09-21-2002, 01:05 PM
albertg albertg is offline
Junior Guru Wannabe
 
Join Date: Sep 2002
Posts: 30
May i know....if you guys have much problem with security issue while u all are running a web hosting business? Ie: your server got hacked.....user sending out spam mail..and etc...thanks.

Reply With Quote
  #7  
Old 09-21-2002, 01:39 PM
Webdude Webdude is offline
Web Hosting Master
 
Join Date: Dec 2000
Location: The Woodlands, Tx
Posts: 5,955
No, we dont have that problem. We did once, it was an issue with formmail. On a server not running the Apache wrap, formmail operates as nobody. You dont have to hack a server to accomplish that. Look at one of the spam headers and it might show a UID in it. If it does, that is the UID of the account the spam was sent from. Feel free to post the headers here also if you dont understand what I mean.

Reply With Quote
  #8  
Old 09-21-2002, 09:21 PM
albertg albertg is offline
Junior Guru Wannabe
 
Join Date: Sep 2002
Posts: 30
Hello guys, this is the header of the mail

Received: from eguard1.maxhostings.net ([194.147.179.02]) by e-mail.ru ; Fri, 20 Sep 2002 07:11:32 3
Received: from nobody by eguard1.maxhostings.net with local (Exim 3.36 #1)
id 17sDtw-0003nn-00
for bookmaker@e-mail.ru; Thu, 19 Sep 2002 19:52:16 -0700
To: bookmaker@e-mail.ru
Subject:
From: journals-na@nm.ru
Subject: =?koi8-r?Q?=EF=E4=E9=EE_=EE=EF=ED=E5=F2_=EE=EF=F7=EF=E7=EF_=F6=F5=F2=EE=E1=EC=E1_=E2=E5=F3=F0=EC=E1=F4=EE=EF?=
Date: Fri, 20 Sep 2002 05:16:18 +0400
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2653.19)
Content-Type: multipart/alternative;
boundary="----_=_NextPart_001_01C26043.52CE91E0"
Message-Id: <E17sDtw-0003nn-00@eguard1.maxhostings.net>
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - eguard1.maxhostings.net
X-AntiAbuse: Original Domain - e-mail.ru
X-AntiAbuse: Originator/Caller UID/GID - [99 99] / [0 99]
X-AntiAbuse: Sender Address Domain - eguard1.maxhostings.net
Return-Path: <nobody@eguard1.maxhostings.net>
X-Rcpt-To: <bookmaker@e-mail.ru>
X-DPOP: Version number supressed
X-UIDL: 1032590015.62690
Status: U


Please help me if this header is able to tell u more.
I have change the host name --eguard1.maxhostings.net and IP--...I am sorry..jus trying to play it safe.

Thank you very very much

Reply With Quote
  #9  
Old 09-21-2002, 09:23 PM
albertg albertg is offline
Junior Guru Wannabe
 
Join Date: Sep 2002
Posts: 30
I have just notice this one...

is this helpful in anyway??

X-Authentication-Warning: relay2.mailru.com: Host [194.147.179.02] claimed to be eguard1.maxhostings.net

thanx again

Reply With Quote
  #10  
Old 09-21-2002, 09:35 PM
Webdude Webdude is offline
Web Hosting Master
 
Join Date: Dec 2000
Location: The Woodlands, Tx
Posts: 5,955
I'm sorry. I dont know Exim. I cant be much help to you other than the fact you have an open mail relay. This means domains that you dont can bounce their email (relay) through your server.

Here's the tricky part, since I dont know how Exim works, I dont know how to tell you to turn relaying off. Someone else will have to help you on that. Once you close that relay, you will be fine. I was hoping the header would tell what user, but it only showed "nobody" (which is 99). However, it also shows 0, which is root.

X-AntiAbuse: Originator/Caller UID/GID - [99 99] / [0 99]

Usually people would jump and say you've been hacked, but that depends on if your mail prog under Exim ops as root.....or perhaps the root part is Exim itself...which is most likely the case. However, based on my experience with Linux/Apache, and other control panels......I am simply reading that you were relayed thru, not hacked.

Reply With Quote
  #11  
Old 09-22-2002, 03:17 AM
rusko rusko is offline
Web Hosting Master
 
Join Date: Sep 2002
Posts: 3,892
roothat

albert,

your biggest problem is the redhat (aka roothat) install youve got. there are a number of security issues in the default redhat 7.2 install. the way to go is to go to the redhat website and locate the security-related errata and patch/upgrade all of the packages which are vulnerable (quite a lot, the default rh 7.2 install contained vuln apache, php, ssh and openssl ) also, go to the websites of vendors for all of your third-party packages and install their security fixes, if any.

if you suspect your server has been compromised, the only way to know for sure that its clean is to do a full reinstall. loadable kernel modules (called rootkits) installed by crackers on compromised servers are extremely hard to detect (several programs exist for that, but they cant detect the more sophisticated and less popular rootkits).

if you want to prevent this from happening again, i suggest you spend some time learning about security, preventive and remediation measures etc. the second option is to hire someone knowledgeable in this issues to provide managed security services for you - that usually includes updating all vulnerable software, hardening of you server and ongoing monitoring. it can be affordable or rather pricey depending on what you need, but its almost always worth the money considering the downtime caused by security breaches.

pm me if the above doesnt help =]

good luck,
paul

Reply With Quote
  #12  
Old 09-22-2002, 06:37 AM
albertg albertg is offline
Junior Guru Wannabe
 
Join Date: Sep 2002
Posts: 30
Quote:
Originally posted by Webdude
I'm sorry. I dont know Exim. I cant be much help to you other than the fact you have an open mail relay. This means domains that you dont can bounce their email (relay) through your server.

Here's the tricky part, since I dont know how Exim works, I dont know how to tell you to turn relaying off. Someone else will have to help you on that. Once you close that relay, you will be fine. I was hoping the header would tell what user, but it only showed "nobody" (which is 99). However, it also shows 0, which is root.

X-AntiAbuse: Originator/Caller UID/GID - [99 99] / [0 99]

Usually people would jump and say you've been hacked, but that depends on if your mail prog under Exim ops as root.....or perhaps the root part is Exim itself...which is most likely the case. However, based on my experience with Linux/Apache, and other control panels......I am simply reading that you were relayed thru, not hacked.
I have check myself at http://www.abuse.net/relay.html and it says i am not a open relay...I hope the prob is jus a open relay

Reply With Quote
Reply

Related posts from TheWhir.com
Title Type Date Posted
GoGrid Partners with Boston Big Data Research Group hack/reduce With Free Cloud Hosting Web Hosting News 2012-11-08 17:42:48
Dutch Security Firm Gemnet and Certificate Authority Division Gemnet CSP Offline Following Hack Web Hosting News 2011-12-09 15:33:53
Sony Temporarily Locks Accounts After Hack Attempt Detected Web Hosting News 2011-10-12 16:21:46
Anonymous Hacks Turkish Government Websites to Protest Internet Censorship Web Hosting News 2011-07-07 18:45:33
Citi Says 200,000 Customers Credit Card Data Stolen in Hack Web Hosting News 2011-06-09 17:04:24


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?