Add to Favorites
Hosting Discussion
 

Hosting Discussion > Web Hosting Forums > Web Hosting Discussion > a word of warning. There is a hacker about caled jamaycka
forgot password?


SPONSORED LINKS

Reply


Old
  Post #1 (permalink)   03-22-2007, 04:41 AM
HD Newbie
 
Join Date: Mar 2007
Location: uk
Posts: 13

Status: dbosch is offline
This is a security advisary. Be warned ladies and gentlemen that this hacker has already defaced over 8,000 websites in a matter of days and he is making his rounds. Sould you be so unfortunate to have your box targetted, a mass defacement of all websites on your server will occur.

It seems that cPanel servers running CentOS and RHEL are currently being targetted, but there could be other distro's and control panels involved. It is also believed that this is being done via the system kernel v 2.6 version unknown.

If you have not done so, ensure that your /tmp and /dev/shm partitions are mounted nosuid,noexec to reduce the likelyhood that this script can be executed. Note, once the hacker accesses your server he creates a user account on your server called rOOt and creates a password for it. Search your /etc/passwd file to ensure that rOOt doesnt already exist.

There is no indication that there is an available patch at this time. Your best course of action is to make sure that each and every website is backed up on a nightly basis until a patch or fix is released by RH. You are advised to view every site on your server to ensure that he has not already attempted to deface a website on your server.

If you are experienced in compiling your own kernel source, now would be a good time to do so. Recompiling the kernel source from the latest distro seems to do that trick so if you are master in the art of recompiling your own kernel source, this is your best protection at this time.

Do not ignore this warning!!!

You may view his doings here. Click on a few websites to reveal the defaced websites.

http://www.zone-h.com/component/opti...acer,JaMaYcKa/

At this time it seems FreeBSD servers, the BSD kernel is not affected by this exploit but thats only a preliminary guess as there is no evidenance to support that any FreeBSD boxes have been rooted.

Thank you.
 
 
 


Old
  Post #2 (permalink)   03-22-2007, 06:00 AM
HD Newbie
 
Join Date: Mar 2007
Location: uk
Posts: 13

Status: dbosch is offline
here are some site that have been hack

http://www.zone-h.com/component/opti...acer,JaMaYcKa/

Last edited by dbosch : 03-22-2007 at 06:07 AM.
 
 
 


Old
  Post #3 (permalink)   03-22-2007, 10:11 AM
HD Addict
 
Join Date: May 2006
Posts: 129

Status: alemcherry is offline
Sounds like a hoax
 
 
 


Old
  Post #4 (permalink)   03-22-2007, 03:31 PM
HD Community Advisor
 
Blue's Avatar
 
Join Date: Oct 2003
Location: PEI
Posts: 1,895

Status: Blue is offline
Why does this look familiar?

http://forums.theplanet.com/index.php?showtopic=86029


Kind of late with the news if it even is true.
__________________
Hampshire Hosting
Affordable Shared and Reseller Hosting
 
 
 


Old
  Post #5 (permalink)   03-22-2007, 07:01 PM
HD Newbie
 
Join Date: Mar 2007
Location: uk
Posts: 13

Status: dbosch is offline
just try to help thats all !
 
 
 


Old
  Post #6 (permalink)   03-23-2007, 03:09 AM
HD Addict
 
Join Date: Jan 2006
Posts: 203

Status: bandboy is offline
Thanks dbosch. Gesture appreciated. No matter if its little delayed or a hoax, its always better to check server settings. Little effort here saves a lot of time later.
 
 
 


Old
  Post #7 (permalink)   03-24-2007, 10:54 PM
HD Newbie
 
Join Date: Mar 2007
Posts: 1

Status: lcubehost is offline
Thanks for the heads up even if it is old news.
 
 
 


Old
  Post #8 (permalink)   03-29-2007, 06:25 AM
HD Amateur
 
Join Date: Feb 2007
Posts: 89

Status: MisterV is offline
I have nothing, so I am not affraid of him.
 
 
 


Old
  Post #9 (permalink)   03-30-2007, 03:04 AM
HD Addict
 
Join Date: Sep 2006
Posts: 149

Status: tarsick is offline
Quote:
Originally Posted by MisterV
I have nothing, so I am not affraid of him.
Lucky you are then.
 
 
 


Old
  Post #10 (permalink)   03-30-2007, 08:13 PM
HD Master
 
Join Date: Mar 2007
Location: B.C, Canada
Posts: 361

Status: Harry is offline
Thanks for the heads up. I know if I was running a hosting biz, I'd look into this more. Usually managed servers are pretty good with security updates and security patches. I think if your not too knowledgeable in security issues with servers, that you for sure read and look into it. I remember working with a company and one of the servers was hacked. All because someone was too lazy to update apache, so always be sure everything is up to date and all ports or holes left open are closed off most of the time.
 
 
 


Old
  Post #11 (permalink)   04-02-2007, 11:28 PM
Account Disabled
 
Join Date: Apr 2007
Posts: 1

Status: humminn is offline
thanks for the info
 
 
 
Reply

Thread Tools

New Post New Post   Old Post Old Post
Posting Rules:
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On