INDISHELL Found - Listing all capenl accounts

Hello,

i just found one of our cpanel ac has been hacked and having a folder named "indishell" and it is having atleast one php file for each cpanel account in our server. ex : abcdef .. conf_global.php

so i wonder while we have the apache simlink racecondition patch applied, how the shell manage to list all of our capnel account names?

INDISHELL Found - Listing all capenl accountsINDISHELL Found - Listing all capenl accounts

i have centos5 vps.

 

 

 

 

Top