• You MUST read the Babiato Rules before making your first post otherwise you may get permanent warning points or a permanent Ban.

    Our resources on Babiato Forum are CLEAN and SAFE. So you can use them for development and testing purposes. If your are on Windows and have an antivirus that alerts you about a possible infection: Know it's a false positive because all scripts are double checked by our experts. We advise you to add Babiato to trusted sites/sources or disable your antivirus momentarily while downloading a resource. "Enjoy your presence on Babiato"

Server Hacked - replaced OS

Sebrof

Member
Babiato Lover
Feb 13, 2019
67
16
8
My server at knownhost was just hacked - Instead of one or more sites getting hacked, they actually installed a new installation of Ubuntu on the server. This essentially erased all content from the server including all web sites, ftp, email, cpanel accts, etc.

The WHM and cpanel passwords were heavily encripted - passwords something like "lzCZCv(lZ5gBtjw2iAuAOh0q"

What access would they have needed to completely wipe a server and then install a new OS ? My OS "was" centos" before it was wiped and replaced with Ubuntu
I don't think it could have been done thru any of the websites on that server, and I don't think a new OS can be installed via cpanel. Am I wrong?

I am thinking that it had to come via WHM or SSH. Your thoughts?
 
He must have root ssh access to that site
 
The WHM and cpanel passwords were heavily encripted - passwords something like "lzCZCv(lZ5gBtjw2iAuAOh0q"

What access would they have needed to completely wipe a server and then install a new OS ? My OS "was" centos" before it was wiped and replaced with Ubuntu

I am thinking that it had to come via WHM or SSH. Your thoughts?

In the light of your information someone has root (SSH) access to your server, so you need to check double-triple your laptop or whicever you connecting to server. If you were connected before common place or with common network connection (such as starbucks etc) so it might be happen.

I strongly suggest to contact with your hosting provider to check your environment (logs etc) and change root password.
 
  • Like
Reactions: jackdanielz
AdBlock Detected

We get it, advertisements are annoying!

However in order to keep our huge array of resources free of charge we need to generate income from ads so to use the site you will need to turn off your adblocker.

If you'd like to have an ad free experience you can become a Babiato Lover by donating as little as $5 per month. Click on the Donate menu tab for more info.

I've Disabled AdBlock