Skip to main content

/ftp_scanner on the WHM server, what is it?

Comments

2 comments

  • MisterGuru
    I think your server has been hacked and is being used to scan for other compromised servers. that file is looking for default users on the FTP servers it's listing. It's running as root, so the hacker has got you quite hard. You'll need to run a rootkit scanner on your server, and maybe block outbound FTP connections. You'll also probably need to check your logs to she when this started, so you can figure out which one of your users has been compromised, and let them know. You got some work ahead of you!!
    0
  • cPanelMichael
    Hello :) I've moved this thread to the "Security" forum. You may receive more user-feedback here. Thank you.
    0

Please sign in to leave a comment.