Skip to main content

Phishing attacks on multiple accounts (does anyone having the same issue)

Comments

2 comments

  • cPanelMichael
    Hello :) You can review/search the following log files to see if you are able to determine how access to the account was gained, and what actions were performed: /var/log/messages /usr/local/cpanel/logs/access_log /usr/local/cpanel/logs/login_log
    Thank you.
    0
  • Un Area
    189.182.230.148 - ahz [05/23/2014:04:14:17 -0000] "GET /cpsess7217122952/ HTTP/1.1" 302 0 "https://www.blackshop.pro/index.html" "Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" 189.182.230.148 - ahz [05/23/2014:04:14:19 -0000] "GET /cpsess7217122952/frontend/x3/passwd/index.html?msg=strength HTTP/1.1" 200 0 "https://www.blackshop.pro/index.html" "Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" 189.182.230.148 - ahz [05/23/2014:04:14:25 -0000] "GET /cPanel_magic_revision_1261011831/frontend/x3/branding/local.css HTTP/1.1" 200 0 "https://domain.com.ar:2083/cpsess7217122952/frontend/x3/passwd/index.html?msg=strength" "Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" 189.182.230.148 - ahz [05/23/2014:04:15:23 -0000] "POST /cpsess7217122952/backend/passwordstrength.cgi HTTP/1.1" 200 0 "https://domain.com.ar:2083/cpsess7217122952/frontend/x3/passwd/index.html?msg=strength" "Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" I found this in one account, passwordstrenght.cgi file is called. Is there a way a hacker can read/catch the cpsess files?
    0

Please sign in to leave a comment.