Control Web Panel

Other => Other => Topic started by: Cyril on December 17, 2018, 01:29:35 AM

Title: My server is hacked
Post by: Cyril on December 17, 2018, 01:29:35 AM
Hi all,

I just installed the CWP and it looks wonderful

however we had an unwanted login from Japan.

We have a fairly strong password with caps, letters, numbers & symbols

How did he get in?

Below is a screenshot of the CWP User Admin Panel

(https://image.prntscr.com/image/Moj7S_-0QBeogwhD1RKfVQ.png)

http://prntscr.com/lvttj5 (http://prntscr.com/lvttj5)
Title: Re: My server is hacked
Post by: studio4host on December 17, 2018, 07:50:44 AM
you should check access logs from cwpsrv
Title: Re: My server is hacked
Post by: Netino on December 20, 2018, 03:33:41 AM
Just installing CWP is not enough to ensure the security of your server.

You have a firewall installed..?!
You check regularly you logs..??
You have installed Logwatch, LogCheck, or similar tool..??
How you are reactive with security events in your logs..??
Servers connected to the internet suffer from constant virtual harassment, and should be constantly monitored.

However, all this may still not be enough. Your server has scripts / programs installed, of which you know / audit .. ??
The security of a server is like a "chain": it is as strong as its weakest link.
You can monitor all your logs, but if you have programs with weak security, that's where the crackers will come in.
It all depends a lot on your experience as a server administrator.

Regards,
Netino