Jump to content

Hacked


Sonu2007

Recommended Posts

A couple of steps I took...

 

1. Move the location of the admin directory to a nondescript location.

 

2. Make a master account with full access and a very strong password, don't use this account for daily use and change the password on a regular basis. Make limited accounts for your admins daily use, where they cannot change things like payment gateways and server settings. Make sure your admins change their passwords on a regular basis and use strong passwords.

Link to comment
Share on other sites

There were some incidents on another forum that I visit that were having FTP compromised through iFrame injection attacks. As stated by simplybe, it's likely that you have a keylogger on your computer if you're changing passwords and they're still getting in with the correct password.

 

Two things:

http://www.kaspersky.com/ --- get it. They seem to do a better job finding keyloggers

 

The other is to change the passwords on the server using ANOTHER computer. It sure sounds like your computer you're using is compromised.

Link to comment
Share on other sites

If it's a keylogger then any time you TYPE it will log it. So putting an extra layer of protection does no good if the system is infected.

 

no not have keylogger on my pc. i am using kaspersky from 3 years. when i searched i forund c99 shell in my whmcs dir. and 1 whmcs database backup file of 1 reputable hosting provider.

also i am always use system generated password

don't know how they done

 

Thanks

Link to comment
Share on other sites

If it was in the main directory, that implies it was via FTP or some local shell. Unless the server/account/directory had incorrect permissions or settings, an intruder should not have been able to upload a file there without other credentials.

 

Did you check the FTP logs around the time of the timestamp on the shell script?

What about the cpanel logs for access through that?

Have you grepped the domlogs for mention of the file name?

Have open_basedir protection on?

PHP up to date?

 

I'd also be curious to know how someone on your server had the database backup of someone else's WHMCS if no others are installed there. I'd check the logs for that filename as well, and suggest you do a security audit of your server right away. If you aren't familiar with the steps, you should hire someone to do it for you.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use & Guidelines and understand your posts will initially be pre-moderated