WHM/cPanel root access alert from unknown IP.. Now what?

Post Reply
ramystyle1
Junior Member
Posts: 1
Joined: 22 Oct 2013, 14:48

WHM/cPanel root access alert from unknown IP.. Now what?

Post by ramystyle1 »

Hi,

Last night, I got an email alert saying that someone logged in to root from an IP in the Netherland (I'm in Canada). Two mins later, I get another alert email saying someone logged in as root from USA.

I was lucky enough I was infront of my PC. I quickly logged in, blocked both IPs and changed my password.

I am baffled as to how the 2 ips were able to login as root in whm.. We keep our password very secure and it's a very hard to guess password (It's a 10 characters, alpha numeric, case sensitive password!!).

Is there anyway to trace those to logins ? How they got in?

Thanks.
sawbuck
Junior Member
Posts: 366
Joined: 10 Dec 2006, 16:20

Re: WHM/cPanel root access alert from unknown IP.. Now what?

Post by sawbuck »

Depending on what OS you're on, /var/log/secure might yield some additional information.
Post Reply