Webmaster Forum

Go Back   Webmaster Forum > Web Development > Web Hosting Forum > Dedicated Servers

Dedicated Servers Dedicated server help.


Reply
 
LinkBack Thread Tools Display Modes
Old 03-25-2005, 11:05 AM   #1 (permalink)
Junior Member
 
Join Date: 09-23-04
Location: Virginia Beach
Posts: 2
iTrader: 0 / 0%
Latest Blog:
None

Atlbsky is liked by many
Need some help/advice!

Was a former client of John's at V7 - now on dedicated hosting at the planet, and having a problem. As soon as we imported our site from V7, we started seeing in the WHM panel email that is constantly being sent through our domain - even though none of the accounts exist with us!

I'm guessing we had some sort of script inserted, but I really am at a loss to explain these emails. Worst of all, they are all infected with a netsky variant.

Can any of you masters point me down a path of enlightenment as to what to look for with this, how to stop it, and what antivirus solutions are best for a dedicated server (linux).

Thanks for any/all help!

PS - that earlier line sounded bad - I in no way suspect this had anything to do with V7, whose service was the best we ever had - just wanted to clear that up!
Atlbsky is offline  
Add Post to del.icio.us
Reply With Quote
Old 03-25-2005, 11:50 AM   #2 (permalink)
Member
 
Thermit's Avatar
 
Join Date: 02-14-05
Posts: 55
iTrader: 0 / 0%
Latest Blog:
None

Thermit is liked by many
Install and run a root kit checker ( chkrootkit ).

Look in every tmp directory on the machine for any hidden files or directories ( ... = bad news )

Look for infected files, check the datestamps.

A few of many things to do...
Thermit is offline  
Add Post to del.icio.us
Reply With Quote
Old 03-25-2005, 04:58 PM   #3 (permalink)
Banned
 
Jonathan VanSchaack's Avatar
 
Join Date: 02-09-04
Location: New York
Posts: 583
iTrader: 0 / 0%
Latest Blog:
None

Jonathan VanSchaack in the redJonathan VanSchaack in the redJonathan VanSchaack in the redJonathan VanSchaack in the redJonathan VanSchaack in the redJonathan VanSchaack in the redJonathan VanSchaack in the redJonathan VanSchaack in the redJonathan VanSchaack in the redJonathan VanSchaack in the redJonathan VanSchaack in the red
Send a message via ICQ to Jonathan VanSchaack Send a message via AIM to Jonathan VanSchaack Send a message via MSN to Jonathan VanSchaack Send a message via Yahoo to Jonathan VanSchaack
cpanel run basic allows ppl to route through yourdomain without securelogin, just enable secure login for email, this way pplneedtologin to send not just receive
Jonathan VanSchaack is offline  
Add Post to del.icio.us
Reply With Quote
Old 03-26-2005, 03:00 PM   #4 (permalink)
Contributing Member
 
docquesting's Avatar
 
Join Date: 07-14-04
Location: South-Middle, Georgia
Posts: 1,228
iTrader: 0 / 0%
Latest Blog:
None

docquesting is a jewel in the roughdocquesting is a jewel in the roughdocquesting is a jewel in the roughdocquesting is a jewel in the roughdocquesting is a jewel in the roughdocquesting is a jewel in the roughdocquesting is a jewel in the roughdocquesting is a jewel in the rough
Send a message via Yahoo to docquesting
I dont know anything about this much myself but if they are able to do the above perhaps the may have access to the whole system?

Just trying to think how a hacker would do things.
__________________
Inexpensive Hosting with Quality!
docquesting is offline  
Add Post to del.icio.us
Reply With Quote
Old 03-26-2005, 03:17 PM   #5 (permalink)
Banned
 
Jonathan VanSchaack's Avatar
 
Join Date: 02-09-04
Location: New York
Posts: 583
iTrader: 0 / 0%
Latest Blog:
None

Jonathan VanSchaack in the redJonathan VanSchaack in the redJonathan VanSchaack in the redJonathan VanSchaack in the redJonathan VanSchaack in the redJonathan VanSchaack in the redJonathan VanSchaack in the redJonathan VanSchaack in the redJonathan VanSchaack in the redJonathan VanSchaack in the redJonathan VanSchaack in the red
Send a message via ICQ to Jonathan VanSchaack Send a message via AIM to Jonathan VanSchaack Send a message via MSN to Jonathan VanSchaack Send a message via Yahoo to Jonathan VanSchaack
nope, they would just have access to the SMTP
Jonathan VanSchaack is offline  
Add Post to del.icio.us
Reply With Quote
Go Back   Webmaster Forum > Web Development > Web Hosting Forum > Dedicated Servers

Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Need advice kwiatek Web Design Lobby 11 09-29-2007 11:20 AM
We need some advice. Can any of you help??? mthomas Marketing Forum 6 09-21-2007 03:36 PM
Need Advice! shaw.kope Webmaster Revenue 8 09-13-2007 10:09 AM
SEO Advice is it Really Necessary? businessservicesuk SEO Forum 10 09-06-2007 01:24 PM
Advice as soon as possible!!! Tefy "") Web Hosting Forum 9 12-22-2006 09:23 PM


Sponsor Links
Get exposure! Contextual Links V7N SEO Blog V7N Directory


All times are GMT -7. The time now is 12:00 PM.
© Copyright 2008 V7 Inc
Powered by vBulletin
Copyright © 2000-2009 Jelsoft Enterprises Limited.


Search Engine Optimization by vBSEO 3.3.0 ©2009, Crawlability, Inc.