Vesta Control Panel - Forum

Community Forum

Skip to content

Advanced search
  • Quick links
    • Main site
    • Github repo
    • Google Search
  • FAQ
  • Login
  • Register
  • Board index Main Section General Discussion
  • Search

Help! Server hacked, root renamed

General questions about VestaCP
Post Reply
  • Print view
Advanced search
3 posts • Page 1 of 1
gogoi
Posts: 10
Joined: Tue Dec 01, 2015 3:20 am

Help! Server hacked, root renamed
  • Quote

Post by gogoi » Fri Dec 23, 2016 7:59 pm

My server was hacked .. probably within the last 10 days.

The hacker logged in from an IP owned by Digital ocean -- which I have reported them with logs.
https://twitter.com/Superhit_in/status/ ... 4782523392

1. the hacker somehow entered into my server
2. changed just the 'root' user name to something else... in the /etc/passwd file as well as changed it's password.
3. added an account in the server
I think thats it..

I saw it in 'last' command
and root's history file

===========

What I did to recover

1. i did a rescue boot from the VPs's admin panel -- with emergency root access
2. changed the 1st user name in the /etc/passwd into root again..
3. reboot the vps and it worked
..
..
4. changed all account passwords.. from VEtacp.. with no login

THEn I did a maldet scan .. found couple of threatening files.... which I deleted immediately.

One of the uploaded file by the hacker -- I copied into pastebin at http://pastebin.com/ddeQS8wD
** There are 2 lines of base64 encoded codes in the file.. BUT not sure the intention of this.

Can someone experienced please look and elaborate on this?

ALSO, please suggest me possible locations where the hacker may have left backdoor?
ssh keys, etc.
I want to refresh all ssh keys/expire all keys .. if there is a way.

regards

Bg
Top

huloza
Posts: 32
Joined: Thu Jul 28, 2016 5:15 am

Re: Help! Server hacked, root renamed
  • Quote

Post by huloza » Sat Dec 24, 2016 4:59 am

Read this:

https://www.akamai.com/us/en/multimedia ... d-rats.pdf

regards!
Top

gogoi
Posts: 10
Joined: Tue Dec 01, 2015 3:20 am

Re: Help! Server hacked, root renamed
  • Quote

Post by gogoi » Sun Dec 25, 2016 2:02 pm

Thanks a lot for pointing to this document.. the hacker used the same script mentioned there.

I did maldet scan which found the script as well as few others and deleted.
https://vpstalk.club/secure-harden-your ... checklist/

regards

Bg
Top


Post Reply
  • Print view

3 posts • Page 1 of 1

Return to “General Discussion”



  • Board index
  • All times are UTC
  • Delete all board cookies
  • The team
Powered by phpBB® Forum Software © phpBB Limited
*Original Author: Brad Veryard
*Updated to 3.2 by MannixMD
 

 

Login  •  Register

I forgot my password