Scan Virus On Sever?
Mar 2, 2007Is this possible we can scan virus on the account on server?
View 1 RepliesIs this possible we can scan virus on the account on server?
View 1 RepliesWe have a client claming that she gets a Trojan warming when she trys to access her website but using the Trojan scan in cpanel doesn't show anything.
What can we use to scan for Trojan?
is this a good deal for a sever for $69 a month
320GB STORAGE
3,000GB MONTHLY TRAFFIC
2.6Ghz AMD PHENOM II X3
2GB RAM MEMORY
how do i prevent the hosting company from significantly raising my monthly cost?
What type of server and connection I need to handle more than 50.000 visits per day in a Webserver Front-End / Database Back-End.
View 5 Replies View Relatedi have VPS CentOs5 running 2.6.9-023stab044.11-entnosplit with Plesk 8.3 Panel ..
last nigth when i was talking with the support center and i past my root passwd ..
after 10-15 mnts some attacker has change my page (index.html)
the server is new .. i just take VPS server before 3 days .. so there is no way to upload or run any php script ( worm ) in my server kz i didn't install anything there else (.html) pages ..
so i stop my VPS tell today and now i change my password and run the command to find any php files in my Vhosts folder wich content my sites directory...
i didn't find anything there and everything looking as a Defualt..
now the question is there anyway for the attacker to hack NixCore V1.5.0 Support Center ...?
and if there any way to check my server if there any uploading new files? whatever is .php ; .pl ; .rar ; .gif ; etc ...
and what command to show what the user group have the root permission?
firewall for my new server. I will be running cpanel 11 on it... so i was looking into configserver.com . Are they good? Is there any other firewall software's you can recommend besides configserver?
View 3 Replies View RelatedWhat is a rootkit? The following link is a very good read to answer that question.
http://linux.oreillynet.com/pub/a/li...4/rootkit.html
In Summary, a rootkit is a trojan installed on your Linux server after someone has broken into it. These files are used to cover the hackers tracks, and to give the hacker tools to do more dirty work from your server.
Usage:
1. su - (change to root user)
2. mkdir /usr/local/chkrootkit
3. wget ftp://ftp.pangeia.com.br/pub/seg/pac/chkrootkit.tar.gz
4. tar -xvzf chkrootkit.tar.gz
5. cd chkrootkit*
6. cp * /usr/local/chkrootkit
7. cd /usr/local/chkrootkit
8. make sense
Now scan your system:
1. cd /usr/local/chkrootkit
2. ./chkrootkit
chkrootkit may from time to time give false positives. If you ever get a positive or "infected hit" scan a second time. If you do get a positive hit, google the hit to research the issue and steps to correct.
Part 2 - automated chkrootkit, and emailed results.
I'm lazy, and like my server to do the work for me so I have it scan every day, and email me the results.
Usage:
1. vi /etc/cron.daily/chkrootkit
2. add the following code.
Code:
#!/bin/bash
(cd /usr/local/chkrootkit; ./chkrootkit -q 2>&1 | mail -s "Daily chkrootkt scan" you@yourdomain.com)
3. chmod 0755 /etc/cron.daily/chkrootkit
This will email you@yourdomain.com every morning with your chkrootkit results. the -q option will only show you exploits.
Removal:
If you don't like getting the emails or just want to remove this from your server:
1. rm /etc/cron.daily/chkrootkit
2. rm -rf /usr/local/chkrootkit
All files will now be deleted from your server.
I'm wondering what the benefits are from switching a hosting server's nameservers to OpenDNS's.
Will this be better for the server or will it cause issues?
how to correct it?
Code:
---------------------- Start Rootkit Hunter Scan ----------------------
Warning: Checking for prerequisites [ Warning ]
The file of stored file properties (rkhunter.dat) does not exist, and so must be created. To do this type in 'rkhunter --propupd'.
Warning: WARNING! It is the users responsibility to ensure that when the '--propupd' option
is used, all the files on their system are known to be genuine, and installed from a
reliable source. The rkhunter '--check' option will compare the current file properties
against previously stored values, and report if any values differ. However, rkhunter
cannot determine what has caused the change, that is for the user to do.
One or more warnings have been found while checking the system.
Please check the log file (/var/log/rkhunter/rkhunter.log)
I rented out a server from leaseweb for 6 months (prepaying) before doing any real researching.. the price was great but the support apparently sucks. Now that I found this out, and my server hasn't been setup yet, I want a full refund. I've contacted them via email, but yet to recieve a response; who should I contact or what should I do.
View 12 Replies View RelatedThis weird issue has poped up only this weekend , when csf blocks all ips and even ssh, email and all services are not accesible, even though server is working, but firewall puts a block on everyone, and appears offline to others, any ideas why csf and iptables are not responding and acting in this behavior, i asked jonesolutions.com last time it happened i got no reason/response which could be the culprit.
Could it be the kernel update/upgrade that was done, to optimize load which broke csf and its working?
as this is 2nd incident over last 2 days , and i had thought my management had fixed it. Upset here over the unwanted for no reason downtimes!
Here is the output for this command after i restart csf again, and thats like average too i get over the entire day.
root@webhosting1 [~]# netstat -an |grep :80 |wc -l
188
root@webhosting1 [~]# netstat -an |grep :80 |wc -l
168
Connections to server dont seem to be high enough to pooch the firewall.
With increased traffic lately I'm trying to plan my next move so I was hoping for some kind recommendation from you guys.
My current setup is 1 VPS from knownhost (managed) where i have my wordpress sites and 1 VDS at FDC (unmannged) for static content like images and zip files but i would like to have everything in one place because it would work out cheaper.
So the question is would i be risking too much if I moved my whole site to a unmanaged dedicated sever without having any expreice other than very basic stuff like intalling afp/ddos deflate?
Right now it seems like their isn't anything to it except upgrading the OS or mysql and things like that in the future...
Is it advisable to have someone scan your server setup, ie the firewall? If so, what is used to scan the firewall?
View 13 Replies View Relatedto put together a file server. This server will only accept SFTP connections and send/receive data. Also, planning to use RAID 10 with a hardware controller. Just looking to get a feel for the CPU and RAM. While the server load will not be much, scalability is a factor when considering hardware.
View 7 Replies View RelatedWhat's the best way to do a daily check for xss scripts injected into php and html files on a linux box?
I am referring to stuff like framer.z
[url]
which essentially has a telltail signature of
<script>eval(unescape("%77%69...
Is there anything for linux that keeps up with those kinds of script signatures?
I doubt CSF or Clam looks for that kind of stuff, right?
to install secuity patches for each VPS hosted on single host or appling it to host running multiple VPS is enough.
Does same applies to firewall related software..Use it for individual VPS on single host?
i have server and i want to do shell scan and delete the shell
View 4 Replies View RelatedI am not much familiar with windows server scan. How can I do full scan on the server? I want to make sure that server is secure.
View 3 Replies View RelatedI am looking for a dedicated server for my flash games site. I am currently using 1and1.com for a Titan 16gb ram, 6gb monthly transfer(bandwidth) but not enough. I end up paid almost $2k last month. So I am need is at least 15-20gb bandwidth monthly transfer and about 8gb ram....
View 7 Replies View RelatedWe want to build a file server in our office - either Windows or Linux (doesn't make a difference to us).
We have a lot of satellite offices, and want to have certain computers have access to specific files/folders on the fileserver.
The catch is this... we would like some of our satellite computers to "sync" with the files/folders on the fileserver.
For example, a developer who is constantly working with a particular client, will always want his/her files to sync up with what is on the server.
The developer will want to work with a local copy of the files, and once finished, will upload them to the file server.
A few days go by, and there is a possibility the fileserver has additional information for that client. The developer would then want to download the changed files from the fileserver.
The benefit of working with local files, is that it is quicker to make changes. We can always leave the desktop on overnight to sync between the fileserver and the desktop.
Any suggestions what to look into here?
All of our desktops are on Windows, so we would need a windows application that has this functionality.
Rsync seems to be the closest thing I've found so far.
I will buy a new Dell server to stream webcasts and also do live streaming.
I will buy a PowerEdge 2950 III with 2 CPU's 2.5 GHZ and 8MB Ram.
Any body knows of free server security scan for my dedicated?
View 4 Replies View Related[url]
[url]
One of my users posted this in the forum saying my server is scanning his computer. His this serious? Do I have virus? Should i be worried? Well i am kinda worried. I tried googling it, but i can't seem to figure the right keywords for a good result.
I have set up a HA network.
Web Servers #1 and #2 have their own IPS, but share a dedicated load balanced IP via the H5 Load Balancer.
We have our domain name registered with Yahoo!
How do we point the domain name at Yahoo! to the load balanced IP?
I have my web server hacked several times and I am beating my head against the wall trying to find the problem(s).
Way back when my sites have been defaced and CHMODing my *.html files to 744 seemed to have done the trick
Now someone has put a phishing site somehow, which by the way I'm not able to remove still, I can't help but to think that I may have more CHMODing to do, I have recursevly set my site to 755, shoud this do the trick? I know I need to chmod .htaccess and alike files to 644, but what about...imagesCGI/PHP?cssetc?
What other steps can I take to secure this thing?
it's a shared host, limited access, but I do have SHELL.
we are expanding to offer vps. i have seen diferent servers config. but am not sure what to choose in terms of hardware
View 14 Replies View RelatedSo I have a client using Wordpress 3.6, so the scan does little good.
I update the Wordpress to 4.1.1 and do the Scan again. Plesk cannot find the updated install of WP still?
In fact i am a customer of PC-CORE.net's directly customer.They send me a email to let me translate my website a few days ago.But i was in a travel then.I recieved it yesterday night. But it is too late that i cannot enter my website then.It is likely the sever ha been shutdown.My ip was 64.191.125.149.The guy rent me the space said he is powerless with it.
I did not get any backups of my site.They are gone when i format my hard drive last time.But the website's date is very important with me.
Anyone related with it?What i can do to save my site? What is going on with PC-CORE.net?