Sponsor:

Server and Web Integrator
Link:
Kloxo-MR logo
6.5.0 or 7.0.0
Click for "How to install"
Donation/Sponsorship:
Kloxo-MR is open-source.
Donate and or Sponsorship always welcome.
Click to:
Click Here
Please login or register. 2024-04-28, 12:00:13

Author Topic: My FTP is getting hacked each day !  (Read 5237 times)

0 Members and 1 Guest are viewing this topic.

Offline Spacedust

  • Super Grand Master
  • ****
  • Posts: 4,050
  • Karma: +1/-0
    • View Profile
My FTP is getting hacked each day !
« on: 2013-05-08, 01:55:49 »
What's this Mustafa !!! I've created a test domain with just phpinfo.php file on it.

Code: [Select]
188.138.112.23 - admin2 [06/May/2013:17:58:02 +0200] "PUT /home/admin2/test.domain.pl/j3CQRFYD.gif" 200 10
188.138.112.23 - admin2 [06/May/2013:17:59:08 +0200] "PUT /home/admin2/test.domain.pl/php.php" 200 27
188.138.112.23 - admin2 [06/May/2013:17:59:15 +0200] "PUT /home/admin2/test.domain.pl/php.php" 200 105936
82.165.150.42 - admin2 [06/May/2013:22:54:12 +0200] "PUT /home/admin2/test.domain.pl/xw7WN9cR.gif" 200 10
82.165.150.42 - admin2 [06/May/2013:22:55:21 +0200] "PUT /home/admin2/test.domain.pl/php.php" 200 105936
82.165.150.42 - admin2 [06/May/2013:22:55:36 +0200] "GET /home/admin2/test.domain.pl/.htaccess" 200 1585
82.165.150.42 - admin2 [06/May/2013:22:55:36 +0200] "PUT /home/admin2/test.domain.pl/.htaccess" 200 3247
82.165.150.42 - admin2 [06/May/2013:22:55:37 +0200] "GET /home/admin2/test.domain.pl/.htaccess" 200 3298
82.165.150.42 - admin2 [06/May/2013:22:55:37 +0200] "PUT /home/admin2/test.domain.pl/.htaccess" 200 3247
188.138.112.23 - admin2 [06/May/2013:23:26:56 +0200] "PUT /home/admin2/test.domain.pl/GrvwJTBq.gif" 200 10
188.138.112.23 - admin2 [06/May/2013:23:28:03 +0200] "PUT /home/admin2/test.domain.pl/php.php" 200 105936
62.149.195.237 - admin2 [06/May/2013:23:28:32 +0200] "PUT /home/admin2/test.domain.pl/YjkXnxZd.gif" 200 10
62.149.195.237 - admin2 [06/May/2013:23:29:38 +0200] "PUT /home/admin2/test.domain.pl/box.php" 200 27
62.149.195.237 - admin2 [06/May/2013:23:29:40 +0200] "PUT /home/admin2/test.domain.pl/box.php" 200 105936

Inside there is something strange - professionally written virus that steal passwords, databases etc. !

« Last Edit: 1970-01-01, 01:00:00 by Guest »

Offline MRatWork

  • Administrator
  • The Elite
  • *****
  • Posts: 15,807
  • Karma: +119/-11
  • Gender: Male
    • View Profile
    • MRatWork Forum
« Last Edit: 1970-01-01, 01:00:00 by Guest »
..:: MRatWork (Mustafa Ramadhan Projects) ::..
-- Server/Web-integrator - Web Hosting (Kloxo-MR READY!) --

Offline Spacedust

  • Super Grand Master
  • ****
  • Posts: 4,050
  • Karma: +1/-0
    • View Profile
Re: My FTP is getting hacked each day !
« Reply #2 on: 2013-05-08, 18:26:11 »
How to protect ?
« Last Edit: 1970-01-01, 01:00:00 by Guest »

Offline MRatWork

  • Administrator
  • The Elite
  • *****
  • Posts: 15,807
  • Karma: +119/-11
  • Gender: Male
    • View Profile
    • MRatWork Forum
Re: My FTP is getting hacked each day !
« Reply #3 on: 2013-05-08, 19:17:43 »
Try disable anonymous ftp and change ftp password.
« Last Edit: 1970-01-01, 01:00:00 by Guest »
..:: MRatWork (Mustafa Ramadhan Projects) ::..
-- Server/Web-integrator - Web Hosting (Kloxo-MR READY!) --

Offline Spacedust

  • Super Grand Master
  • ****
  • Posts: 4,050
  • Karma: +1/-0
    • View Profile
Re: My FTP is getting hacked each day !
« Reply #4 on: 2013-05-08, 19:23:47 »
Quote from: "MRatWork"
Try disable anonymous ftp and change ftp password.

Anonymous FTP is already disabled. Changing FTP password does not help.
« Last Edit: 1970-01-01, 01:00:00 by Guest »

Offline MRatWork

  • Administrator
  • The Elite
  • *****
  • Posts: 15,807
  • Karma: +119/-11
  • Gender: Male
    • View Profile
    • MRatWork Forum
Re: My FTP is getting hacked each day !
« Reply #5 on: 2013-05-08, 19:55:25 »
What about rkhunter log?. If your system have backdoor, ftp is not importance.
« Last Edit: 1970-01-01, 01:00:00 by Guest »
..:: MRatWork (Mustafa Ramadhan Projects) ::..
-- Server/Web-integrator - Web Hosting (Kloxo-MR READY!) --

Offline Spacedust

  • Super Grand Master
  • ****
  • Posts: 4,050
  • Karma: +1/-0
    • View Profile
Re: My FTP is getting hacked each day !
« Reply #6 on: 2013-05-08, 20:07:06 »
Quote from: "MRatWork"
What about rkhunter log?. If your system have backdoor, ftp is not importance.

No backdoors :/
« Last Edit: 1970-01-01, 01:00:00 by Guest »

Offline Spacedust

  • Super Grand Master
  • ****
  • Posts: 4,050
  • Karma: +1/-0
    • View Profile
Re: My FTP is getting hacked each day !
« Reply #7 on: 2013-05-08, 20:44:18 »
I wrote a script so I will get e-mail if a different IP than mine logs on my FTP accounts ;)
« Last Edit: 1970-01-01, 01:00:00 by Guest »

Offline MRatWork

  • Administrator
  • The Elite
  • *****
  • Posts: 15,807
  • Karma: +119/-11
  • Gender: Male
    • View Profile
    • MRatWork Forum
Re: My FTP is getting hacked each day !
« Reply #8 on: 2013-05-08, 22:29:18 »
I am not sure this issue related to with pure-ftpd (as ftp server). As I know no report about pure-ftp vulnerability.

But, please googling about pure-ftp vulnerability.
« Last Edit: 1970-01-01, 01:00:00 by Guest »
..:: MRatWork (Mustafa Ramadhan Projects) ::..
-- Server/Web-integrator - Web Hosting (Kloxo-MR READY!) --

Offline Spacedust

  • Super Grand Master
  • ****
  • Posts: 4,050
  • Karma: +1/-0
    • View Profile
Re: My FTP is getting hacked each day !
« Reply #9 on: 2013-05-08, 23:11:43 »
Quote from: "MRatWork"
I am not sure this issue related to with pure-ftpd (as ftp server). As I know no report about pure-ftp vulnerability.

But, please googling about pure-ftp vulnerability.

I will monitor this and keep you informed.
« Last Edit: 1970-01-01, 01:00:00 by Guest »

 


Top 10 Social Networking:    Facebook    Twitter    LinkedIn    Pinterest    Google Plus    Tumblr    Instagram    VK    Flickr    Vine
Click Here

Page created in 0.032 seconds with 21 queries.

web stats analysis