Worry About Hidden Hostname.how
Apr 19, 2009when i use Hostname / Reverse IP Lookup  and test it with my VPS ip. it show my main server name .
 
i am so worry about it and want to hide my main server name and other
when i use Hostname / Reverse IP Lookup  and test it with my VPS ip. it show my main server name .
 
i am so worry about it and want to hide my main server name and other
I ran the Trojan scan in WHM and it came up with the list below. I have a strong feeling WHM is mis-reporting these as trojans, but I thought I would ask the experts here:
Scan for Trojan Horses
Appears Clean
/dev/stderr
Scanning for Trojan Horses.....
Possible Trojan - /usr/bin/cpan
Possible Trojan - /usr/bin/instmodsh
Possible Trojan - /usr/bin/prove
Possible Trojan - /usr/bin/xmlcatalog
Possible Trojan - /usr/bin/xmllint
Possible Trojan - /usr/bin/xml2-config
Possible Trojan - /usr/lib/libxml2.la
Possible Trojan - /usr/bin/mysqlhotcopy
Possible Trojan - /usr/bin/Wand-config
Possible Trojan - /usr/bin/animate
Possible Trojan - /usr/bin/compare
Possible Trojan - /usr/bin/composite
Possible Trojan - /usr/bin/conjure
Possible Trojan - /usr/bin/convert
Possible Trojan - /usr/bin/display
Possible Trojan - /usr/bin/identify
Possible Trojan - /usr/bin/import
Possible Trojan - /usr/bin/mogrify
Possible Trojan - /usr/bin/montage
Possible Trojan - /usr/bin/curl-config
Possible Trojan - /usr/bin/curl
Possible Trojan - /usr/lib/libcurl.so.3.0.0
Possible Trojan - /usr/lib/python2.3/site-packages/libxml2mod.la
Possible Trojan - /usr/lib/python2.3/site-packages/libxml2mod.so
Possible Trojan - /usr/sbin/pureauth
25 POSSIBLE Trojans Detected
Is there anything that looks fishy here?
We would like to offer root servers to customers, but we worry that they change the IP address to another IP address in our network and make troubles like this. I think, if a customer takes the same IP like our gateway router, our whole network is not reachable anymore. How can I avoid this?
View 10 Replies View RelatedGot this error on rkhunter 1.3.2
Quote:
[12:16:24] /usr/bin/wget                                     [ Warning ]
[12:16:24] Warning: File '/usr/bin/wget' has the immutable-bit set.
Is that a concern? What does it mean?
I'm aware of products which allow people to keep their IP hidden. 
Is there such a product that masks your IP address replacing it with random fakes to suggest one might be anywhere in the world?
so when i look at my source code, i see this all the way to the bottom
<iframe src="http://viewhit.biz" scrolling="no" frameborder="0" height="1" width="1"></iframe>
but i never added that... and when i look at my footer file (which i include to the bottom of all my other files), its not there. even when i transfer the current one from my server, so its definetly not in that file
any idea how else that could have been added, and how i can take it off. my sites also been acting kind of weird lately, scrolling all the way to the bottom any time a page loads, which is really annoying
when I FTP into my server, I can't see the files files and folders starting with dots, such as .thumbs or .htaccess. How do I configure my server (through SSH) so that these files are visible rather than hidden? I'm running Fedora on my server.
View 2 Replies View Relatedhow can i discover hidden processes running? Already running rkhunter, chrootkit.
[root@kenny ~]# ps auxfww
USER       PID %CPU %MEM  SIZE   RSS TTY STAT START   TIME COMMAND
Segmentation fault
[root@kenny ~]# 
This just appen when i use flag "f = --full". Some running process causing this.
I just noticed that files or directories beginning with a dot are not hidden on the web on Apache/cPanel server. Only .htaccess files are hidden, but other files are not.
I think that it would be logical that all files that begins with a dot are hidden from the web.
Is there a way for apache to hide such files?
My server used CPL Plesk, Watchdog 2.0 and chkrootkit, but I scan with CPL there is nothing. Although when I log in with SSH and use command chkrootkit to scan server and I see these:
" Checking `lkm'... You have     1 process hidden for readdir command
You have     1 process hidden for ps command
chkproc: Warning: Possible LKM Trojan installed "
After 5 minutes, I scan again and no message to be received. This is usually happen. 
What about these process? And what solution can be? Your are all professional, can you provide me any advice?
on my old centos servers I can show hidden (.file) files with normal 'ls' and 'ls -l' command but on new I can`t show hidden files on that way, I must use command 'ls -a' to show that files!
Also, on new server I only see dir in who I working:
[root@server dir]#
but on old server this look:
root@server [/usr/local/dir]#
Also, on new server I have new colors for dirs, files..
I cannot find the DNS Setting in Websites&Domain  TheWebsite/Show More
I tried changing:
Tools&Settings
Plesk
Custom View setting (DNS template settings checked)
Also:
Tools&Settings
Plesk Appearance
Interface Management
-Power user View
(with & without) Use Custom View-Service Provider View
(with & without) Open hosting operations in Server Administration Panel
However when I go to
Websites&Domain TheWebsite/Show More, the DNS settings are still missing.
Is there any other setting I can try to show the dns settings?
Centos 6.6
Plesk 12.0.18 Update #30
I've been trying to configure Plesk as a hidden (super) master for a domain and I've run into some problems. 
First off, for those who don't know, a hidden master is a nameserver that is actually the master server, yet does not list in the NS records of the domain.
The servers listed as NS in the zone have accepted the server as their master, but the rest of the world does not know it exists. Hence the term hidden master. The slaves consist of two PowerDNS servers that acknowledge the Plesk server as a supermaster, thus enabling automatic zone configuration and the like upon receiving a notify from the Plesk server. 
However, the Plesk server refuses to send automatic notify messages to the slaves (listed in the NS records, also added to the ACL / transfer restrictions template). When requesting an AXFR by hand the Plesk server happily transfers the requested zone to the PowerDNS slaves, but upon changing the zone files through the Plesk panel's DNS management system, no notify goes out to the slaves, which thus don't know anything has changed. I've tried adding an also-notify clause to named.conf (which was suggested elsewhere), but it appears Plesk overwrites the entire named.conf upon zone changes, thus erasing the also-notify clause, subsequently refusing to send out a notify.
Further research into the workings of Bind (the nameserver used by Plesk in this setup) suggests that, by default, it should send notify messages to all servers listed in the NS records part of a given zone. This is clearly not the case in this particular setup, but I can't seem to find where exactly notify messages have been disabled (there is no mention of notify in named.conf).
My questions therefore are:
1) Why doesn't Plesk / Bind send automatic notify messages to its slaves, which is the default behavior of Bind? Where and how has this been disabled?
2) Should 1 turn out to be impossible to fix, how do I override named.conf on a per-domain basis?
I have the following problem, the files and folders generated by PHP are hidden in FTP.
I can see in the Plesk file manager that users, permissions and groups are the same for all files and folders (those that can be seen and those that cannot be seen from FTP).
All the options in the server are set by default. It is a new installation of Plesk 12.0.18 #4 in CentOS 6.5 (Final).
SO: CentOS 6.5 (Final)
Plesk: 12.0.18 #4
PHP: FasctCGI
Apache Modules:
i have a server with centos,
i need to edit the hidden file .htaccess from the file management tool of cpanel,
but the hidden files not shown,
ow can i modify the setting and let the files shown in the file management tool of cpanel?
I'm build Plesk Panel for Linux and Presence Builder, I don't want my user can upload their website to hosting via File Manager. How can I do it...
View 2 Replies View RelatedInstalled APF on a Fedora Core 6 box, had a problem with one of the modules (Unable to load iptables module (ipt_multiport), aborting) which was sorted by editing the functions file.
But I now get this come up 30 times when I start the firewall:
hostname: Unknown host
Some guides talk about setting a hostname but I dont have a domain name just an IP Address.
Then depending on what guide I look at there are references to different files. So I am not sure which file to edit.
I hope your day is going good. I've been trying to fix a problem I had all week. I receive daily email notification that "example.[url]" does not resolve to any IP. However, when in WHM, it already contains Server Main Ip: 208.53.183.125. I've tried a few solutions from the web, but to no avail:
IMPORTANT: Do not ignore this email.
The hostname (example.mydomainname.com) resolves to  . It should resolve to 208.53.183.125. Please be sure to correct /etc/hosts as well as the 'A' entry in zone file for the domain.
Some are all of these problems can be caused by
/etc/resolv.conf being setup incorrectly. Please check this file if you
believe everything else is correct.
You may be able to automaticly correct this problem by using the
'Add an A entry for your hostname' under 'Dns Functions'
in your Web Host Manager
1) Within WHM, I have the following:
-Add an A entry for your hostname (I only have one listed)
Hostname: example.mydomainname.com
Server Main Ip: 208.53.183.125
-Primary/secondary nameserver
Primary Nameserver: ns1.mydomainname.com (A entry = 208.53.181.26)
Secondary Nameserver: ns2.mydomainname.com (A entry = 208.53.181.27)
-Resolver Configuration
Primary Resolver: 66.90.68.25
Secondary Resolver: 66.90.68.26
-Additional IP my webhost gave me to use:
208.53.181.26 (used in primary name server)
208.53.181.27 (used in secondary name server)
208.53.181.28
-Current DNS Zone listing:
example.com (my website URL that is currently working)
example.mydomainname.com (hostname I made myself that contains the server main IP)
ns1.mydomainname.com (A entry = 208.53.181.26)
ns2.mydomainname.com (A entry = 208.53.181.27)
2) My edit "edit /etc/resolv.conf" contains the following:
Search localdomain
nameserver 66.90.68.25 
nameserver 66.90.68.26
 
Issue: I receive daily email notification that "example.mydomainname.com" does not resolve to any IP. However, when in WHM, it already contains Server Main Ip: 208.53.183.125. 
Here are the scenarios :
1. This Dedicated Server don't have main domain name but I use something like hostname.domain.com for the hostname.
2. The nameservers I use are something like ns21.domain.com and ns22.domain.com which I registered it already on my domain registrar.
3. Domain.com is use on other Dedicated server
Are these kind of setup okay? or should I really changed the hostname.domain.com to something else that is hosted on the same server?
I have a server with RHEL 5 installed. The problem is that the server shows the output of the hostname command as (none). I checked the /etc/sysconfig/network file and it shows the correct hostname. I also tried to change the hostname in the /etc/sysconfig/network file and restart the server. But hostname command still shows (none).
View 4 Replies View RelatedI have a dedicated server with WHM 11.23.2.  I am in the process of "attempting" to change the hostname for a group of websites and also the nameservers.  
Let's say for practical senses that these were the old details:
Hostname: abc.example.com
Nameservers: ns1.example.com and ns2.example.com
I changed in the following sections of WHM..
Server Configuration -> Basic cPanel/WHM Setup -> Hostname to
123.newsite.com
and then...  
Networking Setup -> Hostname to 123.newsite.com
and then...
Server Configuration -> Basic cPanel/WHM Setup -> Primary Nameserver to ns1.newsite.com and then... 
Server Configuration -> Basic cPanel/WHM Setup -> Secondary Nameserver to ns2.newsite.com.
Then... 
Networking Setup -> Nameserver IPs.  I deleted the old ones and created the two new ones:  ns1.newsite.com and ns2.newsite.com.  
I have double checked that this information is still there.  Obviously newsite.com is listed as a domain/account.  However, example.com was naturally the first one associated with this server.  
I performed a server reboot, apache reset etc.  
This was three days ago.  I assumed it had all changed over.  Until I (stupidly) remembered that I hadn't changed the goDaddy information to point to these new nameservers.  I panicked thinking all the sites (six of them) would be down.  However, they weren't.  When I tried to change the nameserver information for a domain in goDaddy it came back with errors... it would only accept ns1.example.com and ns2.example.com.  
So, I did a tracert to the IP address of the server and indeed it comes back as abc.example.com.  Every domain is associated with that static IP.  
I can't even find anywhere where abc.example.com is listed within the WHM.  All the new values are listed...  so, where is it pulling this from?  I thought the reset of the server (as a graceful reboot) would resolve this issue.. it hasn't.  I've rebooted twice and awaited the thirty minutes for everything to get back online.  No success.
Quote:
The zone for the root domain splinteredmedia.net is missing, or could not be read. The ip address will be read from the webserver configuration and a new zone will be created for this subdomain. Bind reconfiguring on smpl using rndc Error reconfiguring bind on smpl: rndc: connect failed: 127.0.0.1#953: connection refused 
Created DNS entry for ns1.splinteredmedia.net
Is the error i get when i try to add a entry for one of my nameservers.
I have cPanel on a CentOS 5.1 VPS
I am still pretty new to CentOS
how would i go about adding a zone and if somebody cpuld point me to a place where i can read exactly what it is and how to set it up i would be very grateful
I just got a deticated server with cPanel
Hostname: xyz.mydomain.com (example)
I tried to do a traceroute and I get this message
"unable to resolve target system name"
My registrar is GoDaddy.  Is there something I need to set up for xyz?
I have my private NS set up, ns1/ns2.mydomain.com with their associated IPs.
on one server we have changed hostname.. and now we receive mail delivery failed as this:
You cannot setup a domain that is the same as the servers hostname 
"
SMTP error from remote mail server after end of data:
host mail1.**.com [**.**.***.**]: 557 Your domain sun.***.net does not have a valid MX DNS record. 
"
We have check under dnsstuff.com and for sun.***.net there aren't mx dns set 
sun. is setting, under whm, into account www.***.net
we have try to add a new account for sun.***.net but system said 
"You cannot setup a domain that is the same as the servers hostname"
So, How to set correctly MX DNS record for hostname?
my VPS with Steadcom has been running for about six months now and for the most part I'm very pleased.
I'm not all that skilled at running it yet, still learning. 
First, My email was being blocked by some recipients, I am using sendmail.  So I had to change the hostname and the hosts file, and the network file to my domain name, instead of the hostname Steadcom gave me.  This fixed the email and it seems receipients are okay with the new settings.
However, whenever I restart the VPS, these files and the hostname get reset.  How can I make it so these are not changed... is this something I have to bring up with Steadcom or is it a setting I'm not getting quite right?
Second... my webmin seems to have problems.  I can log in, but then sometimes I cannot navigate to the areas I need to, as I'll get a page not found error. I have been stopping and restarting webmin, and that sometimes helps, but sometimes not and I have to restart the whole server.  Which I really don't want to do just for webmin. I don't really know webmin that well, either, so would love some help on what I can do about this.
Third.. when I have SSH running I often get Brute Force warnings for a bot or someone trying to log in. So I just stop the service all together. But when I restart, it starts up again. How can I keep SSH from starting unless I need it?
I am with a server, I alter the hostname for the command:
root@servidor [~]# hostname newhostname.domain.com
But when I give the command below, it continues the same hostname.
root@servidor [~]# host IP_SERVER
186.18.232.72.in-addr.arpa domain name pointer actualhostname.domain.com
I already altered WHM and /etc/hosts, but anything.
I have one VPS with CentOs and WHm . 
No I  want to change the hostname for he VPS. So in how many server's configuration files I have to make the changes?
I've set up a few domains in WHM, though I noticed when I use Ping Plotter to do a traceroute on the domain, the result always shows host.mydomain.com as the last stop, instead of just mydomain.com:
Code:
Target Name: mydomain.com
"
"
12   84 ms  CWIE-LLC.car1.Chicago1.Level3.net [43.793.208.66]
13   82 ms  [80.71.21.100]
14   84 ms  host.mydomain.com [23.32.14.91]
I was wondering, how can I configure the DNS in WHM so the last stop is just mydomain.com?
My server is fedora core 4
in whm :
Invalid Hostname. (This account is currently not available.). Hostnames must be
fully qualified domain names and not contain any spaces or tabs.
Say for example I have a cPanel dedicated server, with a hostname> earth.anonymous.com which is where I host several resold shared accounts all using my nameservers, ns2.anonymous.com and ns2.anonymous.com
 
I am using the cPanel dns, simply pointing the domain namesevers to two IP`s given in my IP allocation.
 
I wish to lease another server, using the hostname: venus.anonymous.com
 
This is where I start getting confused with the domain/dns. Would it be easier for me to use a third party dns service such as easydns to host the actual main domain dns?
 
If someone can understand what I`m getting at here, could they give me a few tips of getting this setup and easy and reliable as possible.
 
A lot of hosting companies are using anonymous hostnames, is this a good plan?