Posts by gpeter73

    I tried but didn't found any usable. Just the same answer as yours: may false positives :S


    What I saw is, that my Mail Server is under attack since yesterday. 1000's of login errors on sasl from IP's all over the world.
    Just set fail2ban to maxtries = 1 and bantime > 3 Years (just for a moment) . Now I don't have any new bans, it seems the hacker runned out of Proxy IP's ;)

    Hi,


    everynight I run maldet / f-secure antivirus on my complete server.
    Today I got an report that maldet found several malware at some customers phptmp folders:



    How they come in on several domain at the same time. I manage the most of these Pages and keep them up2date and check also all extension via http://vel.joomla.org/.
    The Foldersecurity is done as strong it is possible.


    How they can come in? How find the security problem?!



    Cheers Peter

    Hi Laurent,


    Thanx a lot. But never changed something directly on the root (/). I used some scripts of i-MSCP to set permissions (i think they recreate permissions from the DB).


    I restored the DB's and run imscp-autoinstall.
    I got the same why I started this thread, three users are unknown. They exist in the DB (domains table) if I use :

    Code
    1. getent passwd


    they are didn't shown.


    Can I add them manualy?


    Sicher, es löscht alle Konfigs und abhängigen Pakete.
    Das war mein letzte ausweg, hatte vorher ein reines neuinstallieren versucht aber auch ohne erfolg. dann habe ich versucht die db's unter /var/lib/mysqld zu verschieben (hätte ja sein können das eine quer liegt).
    Habe aber generell eine Backup gefahren, vom gesamten System.

    So wie es aussieht ist der server platt. habe versucht mysql neu zu installieren

    Code
    1. apt-get remove --purge mysql-common mysql-client mysql-server


    Dann per aptitude

    Code
    1. aptitude install apache2-threaded-dev courier-authlib-mysql libaprutil1-dev libdbd-mysql-perl libmysqlclient-dev libmysqlclient16 libmysqlclient18 libqt4-sql-mysql mysql-client-5.5 mysql-common mysql-server-5.5 php5-mysql proftpd-mod-mysql


    Werde dann nach dem neuen mysql psw gefragt und zu guter letzt sagt dat system das es das neue psw nicht setzen kann.