unsecure server?

Hi,

I'm a reseller on a cpanel/WHM server - (I run a small gaming network). The problem is, a few weeks back , one of my sites fired their joint webmaster, we changed the ftp pass but now the fired webmaster has found some kind of program to scan the server and tell him the ftp/cpanel password? Have any of you heard of anything like this before? Could this be a loophole in proftpd or redhat itself?

Thanks,

exploiter

 

 

 

 

Top