Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
PostPosted: Sun May 12, 2013 7:18 pm 
Offline
Senior Member
User avatar

Joined: Thu Jul 12, 2012 3:55 pm
Posts: 133
Website: http://www.amitywebsolutions.co.uk
We host several hundred websites with various CMS's. We've been hacked several times.

There were only two methods used:

1) File manager in CPanel, some exploit or root password (probably exploit, I dont think anyone would find out root password)

2) insecure CMS and their plugins - they were all Wordpress, Joomla and Zencart. In Joomla it was an exploit in the older version of the plugin JCE Editor for the Wysiwyg editor. Don't know about Wordpress or Zencart.

We don't use these CMS's anymore, they're older sites not upgraded for some time.

For 1) we now use CSF firewall to block all ports except http/https/email and only allow on approved IP addresses and hostnames access to CPanel, SSH, FTP etc. This has a massive benefit on securing the servers. We don't use CPanel on new servers either, but use Virtualmin.

For 2) we upgraded the offending systems/plugins and not seen hacks since

If we do get hacked now its likely because of 2) on old systems not upgraded for sometime. We have also put htaccess directives to disable PHP in the folders they upload to (always images and tmp) in case they do get in they can't do anything.


So could be an exploit in ModX. The software is the most common way they got in with us.

_________________
Web Development Agency in South Wales


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 4 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group