How to find specific files and send alerts

CentOS, How to, Linux, Tips and Tricks, Ubuntu
Maintaining a shared hosting server is a full time job but tools and proper checks and balances can help make this burden lot less. I manage a shared hosting server for one of my friends and numerous times the scripts that people have installed over on their websites have vulnerabilities and hackers exploit it to upload stuff that mass-email or do other nasty stuff. Luckily, most of these exploits have common patterns like files names or other signatures that make them traceable (most of the time the so called hackers are just kiddy scripts) Create a file and put this in it This is a small script that finds specific named scripts in the /home directory (mostly cPanel servers). You can put this in the crontab to do a scan…
Read More

How to configure repos to not overwrite base packages?

CentOS, How to, Linux
The greatest fear with adding additional and especially third party repos such as EPEL (we did a blog post on how to install EPEL earlier) is that it MAY overwrite base packages and bring the system to an unstable state. We can fix this issue by installing Yum Priorities plugin on CentOS 5: on CentOS 4 or CentOS 6: Then make sure that the plugin is enabled Now there are two ways to do it, either set HIGHEST priority to CentOS repos OR set lowest priority to other repos. This is done by adding the line In this blog post, I will set 1 as the priority (highest) for my CentOS Base repo So that it becomes Other repos do not need updating since I have assigned CentOS repos with…
Read More

WHMCS Hacked, 1.7GB of data posted online

News
Ok, so I didn't had enough time and information to blog this but most of you already know it that WHMCS got hacked yesterday. We have a long LET thread here. I was expecting this to get fixed soon hence I created a Video and uploaded on Youtube (later it was clear that my initial idea was wrong, it took much longer for WHMCS to come back online on its feet before getting hacked for the second time) http://www.youtube.com/watch?v=eGlf-HBPXK8 Hackers released about 1.7GB of data on pasteBin note (unsure whats with pastebin but every hacker seem to be doing that) (more…)
Read More

Freshclam daemon not running

CentOS, How to, Linux
Normally, I have two things on every Linux box so that I know whats going on NAGIOS monitoring (nrpe) Logwatch Today, I got something in my logwatch email and it was strange because just the other day, I upgraded the clamav to latest version using epel reo. It appears that the latest version has some permission issues on the log file because when I try to run freshclam on command line I get this The solution? The solution is very simple :) just do the following and after that, run freshclam (the service that updates the virus-definition for clamav)
Read More