View Single Post
Old 27-09-2006, 12:56   #3
KingPhoenix
Inactive
 
KingPhoenix's Avatar
 
Join Date: Jun 2003
Location: On top of this heat sink
Age: 45
Services: Sky+ & 8mb ADSL + BT Together option 3
Posts: 2,345
KingPhoenix has a bronze arrayKingPhoenix has a bronze arrayKingPhoenix has a bronze array
KingPhoenix has a bronze arrayKingPhoenix has a bronze arrayKingPhoenix has a bronze arrayKingPhoenix has a bronze arrayKingPhoenix has a bronze arrayKingPhoenix has a bronze arrayKingPhoenix has a bronze arrayKingPhoenix has a bronze array
Send a message via MSN to KingPhoenix
Re: Webhost hit by cPanel exploit

Unfortunately this is alot worse than made out in Paul's post.

None of I-Webs servers were affected in this bug, we secured the servers as soon as the patch was released. Unfortunately a number of other hosts were victims even before the bug was widely known.

What did the bug do : Well it allowed someone to use the server as their own, allowing them to input code into other peoples files.

Then what? : If a user then visited your site, due to an exploit in IE too, a keylogger was installed into there system.

A key logger? : Yes, it basically logs every key you press and sends it to a remote server. This includes capturing login details for e-mail, online banking etc.

How do i know if i have been affected? : Apparently this site should crash if you are affected http://www.isotf.org/zert/testvml.htm

If that site crashes, then it is highly likely you are affected by this exploit, that was delivered using an exploit in cPanel.


Again, i would just like to clarify that none of the I-Web servers fell victim to this bug.
KingPhoenix is offline   Reply With Quote