WebHostingBlog

About..WebHosting

  • Home
  • About

Welcome!

Welcome to WebHostingBlog the best blog of Webhosting!.

Feed Rss

Jan 25
Digg
Stumbleupon
Technorati
Delicious
WebHosting

10,000 Web Sites Rigged with Advanced Hack Attack

Add

News of cPanel:

cPanel announced today that it’s security team has identified several
key components of a hack known as the Random JavaScript Toolkit. The
systems affected by this hack appear to be Linux® based and are running
a number of different Hosting platforms. While this compromise is not
believed to be specific to systems running cPanel® software, cPanel has
worked with a number of Hosting providers and server owners to
investigate this compromise.

The cPanel Security Team has recognized that the vast majority of
affected systems are initially accessed using SSH with no indications of
brute force or exploitation of the underlying service. Despite
non-trivial passwords, intermediary users and nonstandard ports, the
attacker is able to gain access to the affected servers with no password
failures. The cPanel security team also recognized that a majority of
the affected servers come from a single undisclosed data-center. All
affected systems have passwordbased authentication enabled. Based upon
these findings, the cPanel security team believes that the attacker has
gained access to a database of root login credentials for a large group
of Linux servers. Once an attacker manually gains access to a system
they can then perform various tasks. The hacker can download, compile,
and execute a log cleaning script in order to hide their tracks. They
also can download a customized root-kit based off of Boxer version 0.99
beta 3. Finally, the attacker searches for files containing credit card
related phrases such as cvc, cvv, and authorize.

The actual root-kit has been the subject of much speculation. The cPanel
security team asserts that the Boxer variant includes a small web-server
which is how the Javascript is distributed to unsuspecting users of any
website on the server. It is believed that the Javascript include is
injected into the HTML code after Apache® has served the file but before
it has traveled through the TCP transport back to the user of the
website. The web-server is not loaded onto the hard drive directly but
loaded directly into memory from the infected Boxer binaries. More
information about the infected binaries can be found at:
http://www.cpanel.net/security/notes/random_js_toolkit.html.

The JavaScript being loaded by this web-server is directing users to
another server that scans the website user for a number of known
vulnerabilities. These vulnerabilities are then used to add the website
user to a bot net. More information about the JavaScript hacks can be
found at:
http://www.finjan.com/Pressrelease.aspx?id=1820&PressLan=1819&lan=3.

Cleaning the Random JavaScript Toolkit requires the server to be booted
into single user mode and the removal of all infected binaries. More
details on how to do this can be found at:
http://www.cpanel.net/security/notes/random_js_toolkit.html.

The cPanel security team believes that the hacker has access to the
database of login credentials, the only way to prevent being hacked
again is changing the password and not releasing it to anyone. The
preferred method however is to move to SSH Keys and remove password
authentication altogether.


Author: admin

No Comments

No comments yet.

Comments RSS TrackBack Identifier URI

Leave a comment

*
To prove you're a person (not a spam script), type the answer to the math equation shown in the picture. Click on the picture to hear an audio file of the equation.
Click to hear an audio file of the anti-spam equation

  • Pages

    • About
  • Categories

    • Domains
    • Friends
    • Internet
    • Make Money Online
    • WebDesign
    • WebHosting
    • WebMaster
  • Archives

    • April 2008
    • March 2008
    • February 2008
    • January 2008
    • December 2007
    • November 2007
    • October 2007
    • September 2007
    • August 2007
    • July 2007
  • Blogroll

    • Bidlinkeasy
    • GadgetsBlog
    • MeuPDA
    • Money From Home
    • Submit Free Articles
    • WebHosting
  • Hosted by:

    ss_blog_claim=bc5bf2859e0c6aea1b3dcc0b9bc96486
    ss_blog_claim=bc5bf2859e0c6aea1b3dcc0b9bc96486
Recent Posts
  • WHMCS V3.6.1 Released Hi, WHMCS V3.6.1 has Released today! This version has great many new functions and fixes! Particularly referent to new admin area design! WHMCS aldo include new new modules for LXAdmin (very good free...
  • New WHMCS Beta Version Matt as lanched yesterday the WHMCS V3.6.1 BETA Released! This new version fixes several bugs and includes some new functions such as support for LXAdmin, Register.com, PayOffline! More new functions: Redesigned...
  • Your Nr.1 web for Live TV BlogTV is a well known platform that has won several awards worldwide including the GSM “Best Made for Mobile” award in Barcelona, and the GMCA “New Trend Leader” award at the...
Recent Comments
  • David Parkinson: If you’re already a ShoppingAds user, or considering becomin...
  • unsecured business loans: Thanks! Now I know where to go when I have problems with fin...
  • admin: Thanks for the information but I still have my account block...
  • Warren Frost: I received the same message when I tried to log in to my acc...
  • admin: Yes, is true :)...
  • Is alexa widgets or using redirection myth?: Visit here http://www.alexa.com/data/details/main?url=www.fo...
Theme design by Web 2.0 Themes. Supported by Free phplinkbid templates, Bid directory and Green cars info.