Go Back   HostGator Peer Support Forums > HostGator Peer Support Forums > Web Hosting Services

Notices

Reply
 
Thread Tools
  #1  
Old 10-31-2008, 05:11 PM
alvarogtc alvarogtc is offline
Hatchling Croc
 
Join Date: Sep 2007
Posts: 20
Default How i can secure against this type of script

Sorry if its in a wrong section, today i got surprised 1 acount in my reseller acount had a script like a shell script, thats works like a mini-cpanel, give acess to up, down, delete files and more... so somebody know how i can block this type of acess, since i dont know how he have uploaded the file to the server?? its what i m find now, but i remember about see something about block shell acess and other class of hackers atemp.

I have attached the file in txt format, becuz if u rename to .php its alert antivirus against trojan virus.

Last edited by GatorDrewH; 10-31-2008 at 06:52 PM.
Reply With Quote
  #2  
Old 10-31-2008, 05:20 PM
cleanxhost's Avatar
cleanxhost cleanxhost is offline
Royal Croc
 
Join Date: Sep 2007
Location: Costa del Sol - Spain
Posts: 556
Default Re: How i can secure against this type of script

For me that file that is in .txt gives me a virus alert!
__________________
A REAL man loves his woman every day of the month
http://www.piclikes.com/like/444
Green Cigs
http://www.greencigs.info
Reply With Quote
  #3  
Old 10-31-2008, 05:24 PM
alvarogtc alvarogtc is offline
Hatchling Croc
 
Join Date: Sep 2007
Posts: 20
Default Re: How i can secure against this type of script

i now dude, but for sure, up to a acount in public_html or another folder then rename to something.php like j.php and go www.ursite.com/j.php u gonna see its a shell script --- my reseller acount is brhost.info u can check, its hosted in hostgator, i m not a hacker or something, i just want a answer for this.... yo vejo q oste es de espana, yo soy brasileno...
Reply With Quote
  #4  
Old 10-31-2008, 05:26 PM
cleanxhost's Avatar
cleanxhost cleanxhost is offline
Royal Croc
 
Join Date: Sep 2007
Location: Costa del Sol - Spain
Posts: 556
Default Re: How i can secure against this type of script

Quote:
Originally Posted by cleanxhost View Post
For me that file that is in .txt gives me a virus alert!
and my computer now is not happy and really playing up...I think that she needs a reboot after trying to open that .txt file......
__________________
A REAL man loves his woman every day of the month
http://www.piclikes.com/like/444
Green Cigs
http://www.greencigs.info
Reply With Quote
  #5  
Old 10-31-2008, 05:29 PM
alvarogtc alvarogtc is offline
Hatchling Croc
 
Join Date: Sep 2007
Posts: 20
Default Re: How i can secure against this type of script

go there [removed] i have uploaded the file in this host, but plz dont do nothing just for check..

Last edited by GatorZach; 10-31-2008 at 08:45 PM.
Reply With Quote
  #6  
Old 10-31-2008, 05:34 PM
cleanxhost's Avatar
cleanxhost cleanxhost is offline
Royal Croc
 
Join Date: Sep 2007
Location: Costa del Sol - Spain
Posts: 556
Default Re: How i can secure against this type of script

No thanx! Not after what it did to my computer 10 minutes ago!
__________________
A REAL man loves his woman every day of the month
http://www.piclikes.com/like/444
Green Cigs
http://www.greencigs.info
Reply With Quote
  #7  
Old 10-31-2008, 05:50 PM
quietFinn's Avatar
quietFinn quietFinn is offline
Veteran Croc
 
Join Date: Feb 2005
Posts: 3,557
Default Re: How i can secure against this type of script

It's a phpshell script, kind of hacker's toolbox.

It should not harm your PC if you try to download it in a text file, especially if your antivirus blocks it (my McAfee did).
__________________
quietFinn - netFinn Finland
"Be who you are and say what you feel because those who mind don't matter and those who matter don't mind." - Dr. Seuss
Reply With Quote
  #8  
Old 10-31-2008, 05:52 PM
alvarogtc alvarogtc is offline
Hatchling Croc
 
Join Date: Sep 2007
Posts: 20
Default Re: How i can secure against this type of script

yeah its shell script, my question is how i can block acess like this since i cant found how he uploaded this to the server.... maybe if i use a .hataccess file or only the hosting can do something???
Reply With Quote
  #9  
Old 10-31-2008, 05:59 PM
cleanxhost's Avatar
cleanxhost cleanxhost is offline
Royal Croc
 
Join Date: Sep 2007
Location: Costa del Sol - Spain
Posts: 556
Default Re: How i can secure against this type of script

My question is...
Do you really want a client like this who uploads this kind of stuff to your server?
__________________
A REAL man loves his woman every day of the month
http://www.piclikes.com/like/444
Green Cigs
http://www.greencigs.info
Reply With Quote
  #10  
Old 10-31-2008, 06:01 PM
alvarogtc alvarogtc is offline
Hatchling Croc
 
Join Date: Sep 2007
Posts: 20
Default Re: How i can secure against this type of script

for sure, its not my customer, why he was upload this, then make a backup of all files and download it, since he have total acess to ftp and cpanel.. its a hacker.. i still try to find how he have uploaded, but cant, i am waiting hostgator suport with log acess to check.
Reply With Quote
  #11  
Old 10-31-2008, 06:53 PM
GatorDrewH
HostGator Guest
 
Posts: n/a
Default Re: How i can secure against this type of script

Considering the nature of your problem, you'll need to contact security@hostgator.com to get help, not via the peer support forums.
Reply With Quote
  #12  
Old 10-31-2008, 06:55 PM
alvarogtc alvarogtc is offline
Hatchling Croc
 
Join Date: Sep 2007
Posts: 20
Default Re: How i can secure against this type of script

Quote:
Originally Posted by GatorDrewH View Post
Considering the nature of your problem, you'll need to contact security@hostgator.com to get help, not via the peer support forums.
I know Sr, and i did, but since i dont get any reply, i though about put it in a forum, and see members opinions.....
Reply With Quote
  #13  
Old 10-31-2008, 07:21 PM
riostyles riostyles is offline
Royal Croc
 
Join Date: Jan 2006
Location: Rio de Janeiro, Brazil
Posts: 765
Default Re: How i can secure against this type of script

Seems interesting,
Since the time everybody searches for to give separate cpanel access, the clean part can be a base.
Reply With Quote
  #14  
Old 10-31-2008, 07:35 PM
alvarogtc alvarogtc is offline
Hatchling Croc
 
Join Date: Sep 2007
Posts: 20
Default Re: How i can secure against this type of script

Quote:
Originally Posted by riostyles View Post
Seems interesting,
Since the time everybody searches for to give separate cpanel access, the clean part can be a base.
Poise ate agora, nao sei como ele upou no server, e nao descobri como bloquear, com hataccess nao sei se daria...


I m still find a solution to block shell acess, i think only hostgator can do it for me.
Reply With Quote
  #15  
Old 10-31-2008, 11:37 PM
Sergio's Avatar
Sergio Sergio is offline
Royal Croc
 
Join Date: Oct 2005
Location: Guatemala
Posts: 487
Default Re: How i can secure against this type of script

If you were in a dedicated I would recommend you to use a script that works really nice in my server. It is called Upload Guardian.

You can define any type of script that you want to block for any upload. So, it always check what is uploading to the server and if it has some of the scripts defined it will delete the file and alert you of the upload.

I am really happy with this script.

But this script can not be installed in a reseller account, sorry.

By the way, can you post only the first one or two lines of that script that you got? I will like to check that against my upload guardian script if you don't mind.

Obrigado.
__________________
Sergio
www.EspacioyDominio.com
espacio con dominio incluido.
www.HOSTnDOMAINS.com
domains, appraisals, SSL Certificates and more...
Reply With Quote
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Secure Form Mail Script Yari Gio Webhosting 1 11-22-2007 09:50 PM
what type of hosting to get? meesterrob Pre-Sales Questions 8 05-22-2007 01:31 PM

All times are GMT -5. The time now is 10:44 PM.