This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

HostGator svrs exploited via cPanel, redirect, VML exploit

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://isc.sans.org/diary.php?storyid=1732
Last Updated: 2006-09-23 21:51:55 UTC
"Netcraft's Rich Miller is reporting on VML related exploitation, details at "HostGator: cPanel Security Hole Exploited in Mass Hack.". The article also contains links to their earlier coverage. "By early Saturday morning, HostGator managers were assuring users that the cause of the redirections had been isolated, and was due to a new exploit targeting cPanel". The article details and references a fix that is at the cPanel site."

* http://news.netcraft.com/archives/2006/09/…_mass_hack.html
Sep 23, 2006
"…"This issue affects all versions of cPanel, from what I can tell, from years ago to the current releases, including Stable, Release, Current and Edge." cPanel has just released a fix… "Running /scripts/upcp will fix the vulnerability in all builds," cPanel said in a message on its user forums**… Hackers gained access to HostGator's servers late Thursday and began redirecting customer sites to outside web pages that exploit an unpatched VML security hole in Internet Explorer to infect web surfers with trojans. The existence of the new "0-day" exploit of cPanel leaves a large number of hosting companies vulnerable to similar attacks until they install the patch…"

** http://forums.cpanel.net/

:ph34r: