Compromised???

Posted by Chinese Democracy, 04-20-2009, 12:01 PM
It appears that one new sign-up on a shared Cpanel box was able to somehow attempt phishing using OTHER clients domains. This happened 3 times on the same server (that user is now deleted) Example: Note that this happened to 3 different client's, in the same method! How is this possible??? mod_userdir is enabled suPHP is enabled Running PHP 5.2.9 w/ suPHP as mentioned and Apache 2.2 Keep in mind, these are 3 long time good customers. Here's the strangest thing, the files were NOT uploaded under the ''goodclients" accounts at all, only linked that way. How is that possible?

Posted by ServerManagement, 04-20-2009, 01:08 PM
You have to check the logs to see how it got there. It could have been through an insecure script, weak password, vulnerability in another account, etc. You also need to increase the server's security to prevent the most common types of hacks that cause that.

Posted by brianoz, 04-21-2009, 04:00 AM
That isn't a hack, it's just using mod_userdir to make it look like the files are linked under the other user's directory.

Posted by Chinese Democracy, 04-21-2009, 01:33 PM
mod_userdir protection is enabled, so how is that possible?

Posted by brianoz, 04-21-2009, 07:00 PM
I have no idea but the two obvious alternatives are that it is either broken or configured incorrectly. I'd test to see which is the case. If it appears to be broken, may be worth doing an apache recompile.

Was this answer helpful?

 Print this Article

Also Read

PHP bug? PHP can't resolve domains, server can..

Posted by Drifter13, 07-23-2007, 10:51 PMHello fellow techs, I'm having a strange problem. My...

Database server in different continent?

Posted by UberTricep, 10-27-2012, 08:23 AMHello, Is it wise to have a web server hosted in...

how to get multiple form values as variables in PHP?

Posted by SoftDux, 03-06-2010, 01:21 PMHi, Can someone please help me with this? I have a...

looking for creditcard processing international

Posted by zhai, 09-05-2001, 07:36 PMi'm nearly decide to use service from revecom.com but after...

WHM/apache problems

Posted by madpato, 06-26-2008, 11:08 AMHi I've started a similar topic once but couldnt...