Cable Forum

Cable Forum (https://www.cableforum.uk/board/index.php)
-   Security & Virus Discussion (https://www.cableforum.uk/board/forumdisplay.php?f=38)
-   -   Webhost hit by cPanel exploit (https://www.cableforum.uk/board/showthread.php?t=53071)

Paul 27-09-2006 12:11

Webhost hit by cPanel exploit
 
The popular linux [server] control software cPanel got hacked the other day ;

http://www.seopedia.org/internet-mar...-in-mass-hack/

punky 27-09-2006 12:19

Re: Webhost hit by cPanel exploit
 
Thanx for the heads up mate. Just wonder if I should warn my hosting co...

Shame about cPanel though, I really like it.

KingPhoenix 27-09-2006 12:56

Re: Webhost hit by cPanel exploit
 
Unfortunately this is alot worse than made out in Paul's post.

None of I-Webs servers were affected in this bug, we secured the servers as soon as the patch was released. Unfortunately a number of other hosts were victims even before the bug was widely known.

What did the bug do : Well it allowed someone to use the server as their own, allowing them to input code into other peoples files.

Then what? : If a user then visited your site, due to an exploit in IE too, a keylogger was installed into there system.

A key logger? : Yes, it basically logs every key you press and sends it to a remote server. This includes capturing login details for e-mail, online banking etc.

How do i know if i have been affected? : Apparently this site should crash if you are affected http://www.isotf.org/zert/testvml.htm

If that site crashes, then it is highly likely you are affected by this exploit, that was delivered using an exploit in cPanel.


Again, i would just like to clarify that none of the I-Web servers fell victim to this bug.

bopdude 27-09-2006 13:19

Re: Webhost hit by cPanel exploit
 
1 Attachment(s)
Quote:

Originally Posted by KingPhoenix (Post 34124777)
How do i know if i have been affected? : Apparently this site should crash if you are affected http://www.isotf.org/zert/testvml.htm

If that site crashes, then it is highly likely you are affected by this exploit, that was delivered using an exploit in cPanel.


When I try and access that site my AV kicks in with this, does this mean I'm infected or what does it mean ??

Paul K 27-09-2006 13:24

Re: Webhost hit by cPanel exploit
 
Might want to get it checked
http://vil.nai.com/vil/content/v_140629.htm

bopdude 27-09-2006 13:36

Re: Webhost hit by cPanel exploit
 
Quote:

Originally Posted by Paul (Post 34124790)
Might want to get it checked
http://vil.nai.com/vil/content/v_140629.htm

I can't find any trace of it..yet, still searching :tu: of all the days to log onto my online banking :(

Druchii 27-09-2006 13:55

Re: Webhost hit by cPanel exploit
 
Not affected by it.
It's bad to see things such as cPanel, with big jobs to do getting compromised. But it's bound to happen at some point. Let's hope all damage done ca be reverted.

Paul K 27-09-2006 14:16

Re: Webhost hit by cPanel exploit
 
Possibly just a warning that it was detected as you logged into Cpanel Bop, might want to get your host to check the server just in case.

bopdude 27-09-2006 17:09

Re: Webhost hit by cPanel exploit
 
Quote:

Originally Posted by Paul (Post 34124821)
Possibly just a warning that it was detected as you logged into Cpanel Bop, might want to get your host to check the server just in case.

:blush: :blush: :blush: :erm: I take it people are only at risk if they have a site running cpanel then , oops: oops: oops: ( no site )I thought that link was a general 'log on and see' type thing :D :dozey: :dunce: :dunce:

Sorry, but why then would my AV flash up that warning ???

marky 27-09-2006 17:18

Re: Webhost hit by cPanel exploit
 
Oh blummin great, you have just answered a lot of questions :(

Graham M 27-09-2006 17:18

Re: Webhost hit by cPanel exploit
 
Is there a fix for Cpanel then?

Paul K 27-09-2006 17:20

Re: Webhost hit by cPanel exploit
 
KP said in his post that I-web have patched their servers already so a patch must be out there for the problem.

bopdude 27-09-2006 17:23

Re: Webhost hit by cPanel exploit
 
Quote:

Originally Posted by marky (Post 34124961)
Oh blummin great, you have just answered a lot of questions :(

Who did ? me ? you fell for the same thing ???? I'm not alone in the world then :D

marky 27-09-2006 17:27

Re: Webhost hit by cPanel exploit
 
Quote:

Originally Posted by bopdude (Post 34124967)
Who did ? me ? you fell for the same thing ???? I'm not alone in the world then :D

Our servers blocked several ip's at the time this happened, and the site posted here crashes :(

bopdude 27-09-2006 17:29

Re: Webhost hit by cPanel exploit
 
Quote:

Originally Posted by marky (Post 34124972)
Our servers blocked several ip's at the time this happened, and the site posted here crashes :(

I see :(

pedantic 27-09-2006 17:54

Re: Webhost hit by cPanel exploit
 
I thought the latest patch from MS has sorted that out. :confused:

http://secunia.com/advisories/21989/

Druchii 27-09-2006 17:55

Re: Webhost hit by cPanel exploit
 
Quote:

Originally Posted by pedantic (Post 34124989)
I thought the latest patch from MS has sorted that out. :confused:

http://secunia.com/advisories/21989/

It did, i'm thinking that was before the patch was released 2 days ago was it?

Halcyon 27-09-2006 18:00

Re: Webhost hit by cPanel exploit
 
Quote:

Originally Posted by bopdude (Post 34124948)
But why then would my AV flash up that warning ???

My Nod32 came up with the same thing too.
Anyone know if we are at risk or why it came up ?

pedantic 27-09-2006 18:01

Re: Webhost hit by cPanel exploit
 
Quote:

Originally Posted by Druchii (Post 34124990)
It did, i'm thinking that was before the patch was released 2 days ago was it?

Dunno lol

I just used the link supplied by KP and got this.....

Quote:

VML test case, CVE-2006-4868

This is a test page to determine whether your browser is vulnerable to the VML vulnerability specified in CVE-2006-4868.

Since your browser is not Internet Explorer 5 or higher it does not support the vulnerable VML module, and you are therefor not vulnerable.

If you would like to know more about the Zeroday Emergency Response Team, please visit http://isotf.org/zert/
Which does point to that exploit in my previous post. No big deal though. :tu:

Paul 27-09-2006 19:41

Re: Webhost hit by cPanel exploit
 
Quote:

Originally Posted by KingPhoenix (Post 34124777)
How do i know if i have been affected? : Apparently this site should crash if you are affected http://www.isotf.org/zert/testvml.htm

That site tests if your IE is vulnerable to the VML security hole.

Mine was, so I installed the MS patch available here ;

http://www.microsoft.com/technet/sec.../MS06-055.mspx

Now IE passes the test ok.

Halcyon 27-09-2006 20:58

Re: Webhost hit by cPanel exploit
 
So is that why Nod32 thinks it is a virus then when I click on that link ?
I never use IE, just Firefox.

Graham M 27-09-2006 21:01

Re: Webhost hit by cPanel exploit
 
Quote:

Originally Posted by Paul (Post 34124964)
KP said in his post that I-web have patched their servers already so a patch must be out there for the problem.

OK well I'll run a CPanel update and see what happens.

---------- Post added at 20:01 ---------- Previous post was at 20:00 ----------

Yeah there was a news item at the top of my WHM Admin Page telling me there was an update to fix the vulnerability. Running the update now

Paul K 27-09-2006 21:05

Re: Webhost hit by cPanel exploit
 
Quote:

Originally Posted by Zeph (Post 34125107)
OK well I'll run a CPanel update and see what happens.

---------- Post added at 20:01 ---------- Previous post was at 20:00 ----------

Yeah there was a news item at the top of my WHM Admin Page telling me there was an update to fix the vulnerability. Running the update now

Cool. Thought you may have missed KPs post ;)

marky 27-09-2006 21:07

Re: Webhost hit by cPanel exploit
 
Quote:

Originally Posted by Paul M (Post 34125074)
That site tests if your IE is vulnerable to the VML security hole.

Mine was, so I installed the MS patch available here ;

http://www.microsoft.com/technet/sec.../MS06-055.mspx

Now IE passes the test ok.

All fixed, i feel better now :D

Gareth 27-09-2006 22:53

Re: Webhost hit by cPanel exploit
 
What, that site is knowingly hosting a trojan and asking people to click the link?!? How irresponsible of them.

Druchii 27-09-2006 23:00

Re: Webhost hit by cPanel exploit
 
Quote:

Originally Posted by Gareth (Post 34125215)
What, that site is knowingly hosting a trojan and asking people to click the link?!? How irresponsible of them.

No, they are knowingly osting the exploit, then seeing if you're immune to it or not. No malicious code. Just the exploit. If you get my drift.

SnoopZ 28-09-2006 00:01

Re: Webhost hit by cPanel exploit
 
My IE crashed when i went to http://www.isotf.org/zert/testvml.htm. Installing all the patches from MS update sorted that though. Glad i only use Opera to log into sites!


All times are GMT +1. The time now is 18:03.

Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
All Posts and Content are © Cable Forum