Skip to main content

brute forcing all accounts

Comments

4 comments

  • cPanelMichael
    Hello :) You should ensure a firewall such as CSF is installed to help prevent the brute force attempts. In addition, you can enable cPhulk brute force protection as an additional security measure. It's difficult to say how exactly the usernames on your system were discovered. The "Security Advisor" is a good place to start in order to determine methods to increase the overall security of the server: "WHM Home " Security Center " Security Advisor" However, you may also want to consult with a qualified security specialist to have you server's security audited. Thank you.
    0
  • daveyb17
    Hi Michael, Cheers for the feed back it's very much appreciated. I have CSF and cPHulk installed/enabled already i am having a bit of a problem with Jail Apache i have it enabled but the security adviser thinks it's disabled (i'll look further into this myself). [QUOTE]However, you may also want to consult with a qualified security specialist to have you server's security audited.
    by this i take it the usernames should not be being hit like they are and this is out of the ordinary. cheers Dave
    0
  • quietFinn
    It sounds like (at least) one of the accounts in your server is already compromised, and the attacker was able to get list of all accounts in the server.
    0
  • quizknows
    [quote="quietFinn, post: 1541871">It sounds like (at least) one of the accounts in your server is already compromised, and the attacker was able to get list of all accounts in the server.
    I concur with this. Start with a clamAV and/or Maldet scan of all the public_html directories on your server and go from there.
    0

Please sign in to leave a comment.