E
E
Elena2016-01-13 08:25:40
Information Security
Elena, 2016-01-13 08:25:40

How to reflect a hacker attack on the server (hosting)?

I really need help. Immediately, I note that I do not own the subject area. The other day, all sites on the hosting (vps server) were hacked and mass mailings were made, as a result, all sites were filled up. Technical support pointed to suspicious files, we deleted them and rolled back all sites to last year's version. We changed passwords, denied access to all IPs, except for workers, in .htaccess. At night, one of the sites gave a 403 error, after which this appeared on the sites b0b81e819c8d45b4ba8fbd549f12ac72.png. What measures can be taken independently / together with technical support, or can one not do without the services of a specialist?

Answer the question

In order to leave comments, you need to log in

6 answer(s)
N
nirvimel, 2016-01-13
@nirvimel

It looks like hacking the OS itself on a VPS. You are concentrating on sites - perhaps you are looking in the wrong place.
Update your OS (by the way, which one do you have?). If it is possible to stop the server for a while and have all the backups, then it may be better (and faster) to install a fresh OS from a clean image from the offsite, and then raise the backups.
In general, you need a competent administrator, not a site specialist, but an OS administrator who understands system security. He may not have to be hired permanently, but simply given one-time work on installing the OS, setting up security, uploading and raising sites. But don't skimp on it too much, you don't want to see that green flag again in a couple of weeks.

X
xmoonlight, 2016-01-13
@xmoonlight

Change host. Maybe the problem is not yours.

A
Alexander Taratin, 2016-01-13
@Taraflex

Update everything that can be updated (os, apache, nginx, php, cms, cms plugins) + How to protect sites from hacking?
Move cms admins to non-standard url addresses and close them via www.softtime.ru/info/apache.php?id_article=27
Prohibit execution of php code in directories where there should be no php code at all, especially if user files can be uploaded into it.
Prevent the user from which the web server is running from writing and reading directories that he should not touch.

P
Puma Thailand, 2016-01-13
@opium

just look at the logs of how you were hacked and close the hole

V
Vlad Zhivotnev, 2016-01-13
@inkvizitor68sl

proftpd installed? What version?
UPD: as expected, this is CVE-2015-3306 ( habrahabr.ru/post/257027/)

E
Elena, 2016-01-21
@olenne

Thanks everyone for the replies and recommendations! The viruses were removed, according to the logs it was determined that the hack was made through holes in the joomla. The mod_copy module has been disabled.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question