LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 11-28-2015, 05:28 PM   #16
spindlelegs
LQ Newbie
 
Registered: Nov 2015
Posts: 6

Original Poster
Rep: Reputation: Disabled

No Worries, @Habitual! I realise I was barking up the wrong tree with the IP spoofing theory, and didn't realise how difficult (if not impossible) it would be to find the right one. Chopping that tree down and planting a new one is the way to go, though I'd still love to know how the blighters got up my tree in the first place. Am I taking this metaphor too far...?

Quote:
Originally Posted by descendant_command View Post
Compromised php website or control panel is the most common vector.
A planted php script sending mail directly (so your MTA is not involved) as your www user.
I did install Webmin right at the start (2 years ago), but actually find myself doing most stuff from the command line now. Do you recommend avoiding Webmin, CPanel, Plesk et al completely, or is there a place for them?
 
Old 11-28-2015, 06:42 PM   #17
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
Quote:
Originally Posted by spindlelegs View Post
No Worries, @Habitual! I realise I was barking up the wrong tree with the IP spoofing theory, and didn't realise how difficult (if not impossible) it would be to find the right one. Chopping that tree down and planting a new one is the way to go, though I'd still love to know how the blighters got up my tree in the first place. Am I taking this metaphor too far...?

I did install Webmin right at the start (2 years ago), but actually find myself doing most stuff from the command line now. Do you recommend avoiding Webmin, CPanel, Plesk et al completely, or is there a place for them?
I've tilted at more than a few windmills.
Are you asking me, or descendant_command about control panels?
If you're not using webmin (c-line is, and always will be King) nuke it to orbit.

How they got "into" your tree...
Find out where it's originating and that should lead to the "how" of it.
 
Old 11-28-2015, 08:47 PM   #18
sag47
Senior Member
 
Registered: Sep 2009
Location: Raleigh, NC
Distribution: Ubuntu, PopOS, Raspbian
Posts: 1,899
Blog Entries: 36

Rep: Reputation: 477Reputation: 477Reputation: 477Reputation: 477Reputation: 477
Quote:
Originally Posted by spindlelegs View Post
I did install Webmin right at the start (2 years ago), but actually find myself doing most stuff from the command line now. Do you recommend avoiding Webmin, CPanel, Plesk et al completely, or is there a place for them?
Any time you expose administrator functions and capabilities via a web interface one is asking for their server to get owned. Feel free to search NVD for your favorite software. https://web.nvd.nist.gov/view/vuln/search

Last edited by sag47; 11-28-2015 at 08:50 PM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Upgrading Glibc Without Damaging Linux btbx Linux - Software 4 12-24-2007 10:07 AM
am I damaging my monitor? case1984 Linux - Hardware 4 11-25-2004 01:13 PM
Damaging an IP address HadesThunder General 7 06-21-2004 04:17 AM
Unnecessary/damaging updates?? Barry Bingham Mandriva 8 01-25-2004 07:25 AM
Repartitioning Without Damaging Data Cr4wford Linux - Hardware 5 11-02-2003 01:06 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 06:08 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration