Skip to main content

Server compromised with new password set?

Comments

1 comment

  • cPanelMichael
    Hello, It's possible the SSH session referenced in your logs stems from the attacker starting a separate SSH instance over a different port, however it's difficult to know for sure how someone accessed SSH as root or hacked the system. We typically recommend contacting a qualified security specialist or system administrator for help investigating these matters. You may also want to review the following document: Why can't I clean a hacked machine - cPanel Knowledge Base - cPanel Documentation Thank you.
    0

Please sign in to leave a comment.