View Full Version : Inbreco - Compromised
JasonS
April 2nd, 2008, 11:52
Hello,
The Inbreco node was compromised by a kiddy client which was hosted. All of our clients services remain up and running with no error, but the main Inbreco website was cleared and we are working to resolve this.
With Regards,
Jason S
Skylar
April 2nd, 2008, 12:02
Clearly you didn't install security.. I would work on that
JasonS
April 2nd, 2008, 12:03
Clearly you didn't install security.. I would work on that
Hey,
It appears as an SQL attack, but thank heavens it has not affected clients.
With Regards
Decker
April 2nd, 2008, 12:31
Skylars right, if a script kiddy can do that to the main site :(
More work on security is a must.
JasonS
April 2nd, 2008, 12:39
Skylars right, if a script kiddy can do that to the main site :(
More work on security is a must.
Hey,
Kiddy by age, not by knowledge. We're working on tighter security now. We will also cease to provide Shared & Reseller services.
Skylar
April 2nd, 2008, 12:54
Hey,
Kiddy by age, not by knowledge. We're working on tighter security now. We will also cease to provide Shared & Reseller services.
Regardless, it should show you need tighter security.
http://hostsocial.net/showthread.php?t=14 -- ELS, very nice to use, this should help you out a lot with security.
Decker
April 2nd, 2008, 12:57
Kiddy by age, not by knowledge.
Unless they were using some pretty neat tools/methods (in other words if you can find what they did on the internet) it makes them a script kiddy :wink2:
JasonS
April 2nd, 2008, 13:29
Unless they were using some pretty neat tools/methods (in other words if you can find what they did on the internet) it makes them a script kiddy :wink2:
Hehe,
SSH Logs reckons that is could have been through WHM Sonic, not too sure right now. Still investigating!
Decker
April 2nd, 2008, 13:32
Again with shell access :wink2:
Skylar
April 2nd, 2008, 13:32
Hehe,
SSH Logs reckons that is could have been through WHM Sonic, not too sure right now. Still investigating!
You really need to install security, firewalls, etc, and not give out shell access. if you give out Shell, give them jailshell
JasonS
April 2nd, 2008, 13:43
You really need to install security, firewalls, etc, and not give out shell access. if you give out Shell, give them jailshell
Hey,
I dont give out root logins or anything like that. I've installed that ELS and looking for a firewall from the data center now :)
EDIT:
About to install IPTables as a firewall on the node.
Cam.
April 2nd, 2008, 15:04
Hey,
I dont give out root logins or anything like that. I've installed that ELS and looking for a firewall from the data center now :)
EDIT:
About to install IPTables as a firewall on the node.
You never had a firewall :eek2:
JasonS
April 2nd, 2008, 15:07
You never had a firewall :eek2:
Hey,
We had IPTables setup originally, it was just not configured correctly.
Eclouds
April 2nd, 2008, 15:10
What a great start! :)
Install a firewall, brute force detection, and other neat little tools i won't reveal.
Decker
April 2nd, 2008, 15:17
Hey,
We had IPTables setup originally, it was just not configured correctly.
Fup me! :eek2:
And shell doesn't need root to do some nasties if you don't at least jail it.
utcrazy
April 2nd, 2008, 15:17
Script kiddies are pretty crafty.
Eclouds
April 2nd, 2008, 17:11
I don't think it is a good idea to post on your main site that you have been compromised.
Decker
April 2nd, 2008, 17:14
He'll learn :wink2:
SC-Daniel
April 2nd, 2008, 19:44
Hmmm... That is a scary thought! A host has their server compromised... Makes your clients feel all warm and fuzzy ;)
Seriously though... If I were you I would remove that placeholder page and put down for maintenance instead...
Also, take a look at CSF/LFD if you are running cPanel... That is what I use and it works awesome, if configured properly.
SC-Daniel
April 2nd, 2008, 19:45
BTW, I seriously thought this was a belated April Fool's joke at first.
JasonS
April 3rd, 2008, 11:40
BTW, I seriously thought this was a belated April Fool's joke at first.
Well you were wrong :)
The IP has been located and the issue is being resolved. The site will be up momentarily.
Skylar
April 3rd, 2008, 13:06
Also, take a look at CSF/LFD if you are running cPanel... That is what I use and it works awesome, if configured properly.
CSF/LDF is really bad if under ddoss attacks. If you have anti-ddoss protection in place, plus CSF, CSF will block out other IP's if they have too many connections for too long, to help against the attacks. Now with the anti-ddoss scripts such as Mod_Deflate, the CSF Firewall will end up blocking out the loopback and main IP as it has "too many connections" attempting to combat the attack -- just to keep that in mind.
Jan
April 3rd, 2008, 17:11
I don't think it is a good idea to post on your main site that you have been compromised.
Or a public forum viewed by 1000s of people ;)
http://www.google.com.au/search?q=Inbreco++Compromised+&hl=en&client=firefox-a&rls=org.mozilla:en-US:official&hs=QlW&filter=0
Decker
April 4th, 2008, 05:44
Or a public forum viewed by 1000s of people ;)
http://www.google.com.au/search?q=Inbreco++Compromised+&hl=en&client=firefox-a&rls=org.mozilla:en-US:official&hs=QlW&filter=0
Even worse the first result;
The Inbreco node was compromised by a kiddy client
Powered by vBulletin® Version 4.1.7 Copyright © 2012 vBulletin Solutions, Inc. All rights reserved.