Skip to main content

Hacked by another mail server?

Comments

5 comments

  • cPanelMichael
    Hello :) Are you using a firewall that could be blocking the webmail ports? If not, try installing a firewall management utility such as CSF to easily manage firewall rules and ensure ports are not blocked: ConfigServer Security & Firewall Thank you.
    0
  • LaxSlash1993
    No way of doing or checking that... I'm locked out of sudo. Edit: Have an update. Good news is it appears to be a flase flag. The hostname was a residual ReverseDNS entry from a spammer that leased my IP Address before I did. The provider took care of that pretty quickly. Bad news is that I'm still locked out of sudo. If possible... can this be moved out of security and somewhere more appropriate, seeing as this ended up not being a security issue but rather an issue of a ReverseDNS Pointer still existing from the previous owner that I never knew about?
    0
  • LaxSlash1993
    Going to bump this. I can not use root in WHM, use sudo, or su into root, because of the errors mentioned in the OP. I have to reboot it (the server) every 2 hours to be able to get back in - and that doesn't even always work. Nothing in limits.conf, and limits.d's config file says that root should be entitled to 'unlimited' processes. This happens when root only has 39 processes up and running.
    0
  • cPanelMichael
    sudo: PERM_ROOT: setresuid(0, -1, -1): too many processes

    Hello :) Does the issue persist if you disable "Shell Fork Bomb Protection" in WHM? It's documented at: Shell Fork Bomb Protection - Documentation - cPanel Documentation Thank you.
    0
  • keat63
    Maybe i'm barking up the wrong tree here, in which case please accept my apologies. I had something very similar happen to me when i first got my server. I was locked out of root access via ssh, and it turned out to be CPHulk. Apparently, there were a large number of failed login attempts (assumed to be potential hackers i guess). I also had to reboot to gain access, this was literally within hours of whm going live. Since deploying CSF, moving the SSH port and tightening up HostAccesControl i've not seen this issue.
    0

Please sign in to leave a comment.