Welcome to the JaguarPC Community
JaguarPC
Sales: (888) 338-5261
Support: (888)-551-3050
Results 1 to 6 of 6

This is a discussion on VPS hacked - Iframe Redirect in the VPS & Dedicated forum
My VPS got hacked. Interestingly, I have four cPanel accounts. Only one of them got hacked. The attacker added an iframe redirect to the bottom ...

  1. #1
    Loyal Client
    Join Date
    Jan 2005
    Posts
    159

    VPS hacked - Iframe Redirect

    My VPS got hacked.

    Interestingly, I have four cPanel accounts. Only one of them got hacked.

    The attacker added an iframe redirect to the bottom of the page for around 20 index.html/index.php pages.

    They did this on Aug 30, 2009, at 11:30am (took them 2 minutes - so probably an automated script)

    I just realized that we're often logging into cPanel using domain.org:2082 which sends the password unencrypted. I've been doing this for perhaps six years on one of my websites. Is this a likely cause? Any other suggestions?

    I've filed a support ticket...

  2. #2
    JPC Dream Team
    Join Date
    Apr 2008
    Posts
    708
    Hi akreider2,

    This kind of iframe injections are usually caused by weak ftp passwords, make sure you are using strong passwords for any of the logins you use for vps, accounts, sub accounts.

    Also avoid using plain ftp logins and for any ftp activity for your accounts use sftp. Also making sure that all applications in this account are running on latest stable versions reduces the chances of such hacks/injections a lot.


    The access logs for the account and vps logs can give some idea on how this was done, so steps can be taken to avoid such hacks in future. We will check your vps and let you know our findings in your ticket.
    Rizwan - Technical Support Manager
    JaguarPC

    Helpful Links
    Knowledge Base | Network Status | Current Specials

  3. #3
    Loyal Client
    Join Date
    Jan 2005
    Posts
    159
    Is there a way to disable plain ftp?

  4. #4
    Loyal Client
    Join Date
    Jan 2005
    Posts
    159
    WHM - FTP server configuration.
    I set TLS Encryption Support to "Required"

    Before it was "optional".

  5. #5
    Loyal Client
    Join Date
    Jan 2005
    Posts
    159
    How do I disable unsecure cpanel and webmail (ports 2082 and 2095)?

    I found the setting to redirect them. But it only redirects some of the time (www.domain.org/cpanel redirects, but www.domain.org:2082 does not).

  6. #6
    JPC Dream Team
    Join Date
    Apr 2008
    Posts
    708
    Quote Originally Posted by akreider2 View Post
    WHM - FTP server configuration.
    I set TLS Encryption Support to "Required"

    Before it was "optional".
    Yes this is correct.

    For enforcing secure cpanel or webmail logins if applying that from Tweak Settings is not working , then it will need to be checked further.
    Please update the ticket with required logins and we can check that further.
    Rizwan - Technical Support Manager
    JaguarPC

    Helpful Links
    Knowledge Base | Network Status | Current Specials

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •