http://news.netcraft.com/archives/2006/09/23/hostgator_cpanel_security_hole_exploited_in_mass_hack.html


HostGator: cPanel Security Hole Exploited in Mass Hack

HostGator says hackers compromised its servers using a previously
unknown security hole in cPanel, the control panel software that is
widely used by hosting providers. "I can tell you with all accuracy that
this is definitely due to a cPanel exploit that provides root access and
all cPanel servers are affected," said HostGator system administrator
Tim Greer. "This issue affects all versions of cPanel, from what I can
tell, from years ago to the current releases, including Stable, Release,
Current and Edge."

cPanel has just released a fix. "Running /scripts/upcp will fix the
vulnerability in all builds," cPanel said in a message on its user
forums. "Please note that this is a local exploit which requires access
to a cPanel account. ... If you believe you have been exploited through
this vulnerability, you are welcome to submit a support request for
assistance."

Hackers gained access to HostGator's servers late Thursday and began
redirecting customer sites to outside web pages that exploit an
unpatched VML security hole in Internet Explorer to infect web surfers
with trojans. The existence of the new "0-day" exploit of cPanel leaves
a large number of hosting companies vulnerable to similar attacks until
they install the patch. The riusk is mitigated somewhat by the fact that
it is a local exploit, meaning any attack on a host must be launched
from an existing account with cPanel access.

HostGator site owners said iframe code inserted into their web pages was
redirecting users to the malware-laden pages. Company staff made several
efforts to reconfigure servers on Friday, only to have the exploits
recur. Since the attacker controlled a cPanel account at HostGator, the
exploit could be repeated after each cleanup of the malicious code. By
early Saturday morning, HostGator managers were assuring users that the
cause of the redirections had been isolated, and was due to a new
exploit targeting cPanel.


-------------------------------------------------------------------------
Take Surveys. Earn Cash. Influence the Future of IT
Join SourceForge.net's Techsay panel and you'll get the chance to share your
opinions on IT & business topics through brief surveys -- and earn cash
http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV
_______________________________________________
linux-india-help mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/linux-india-help

Reply via email to