my directadmin got hacked!

Frej

Verified User
Joined
Jun 15, 2008
Messages
155
I don't how how the attackers did it, but they were able to breach DA and reset the password for the user. His username is 'projectx'. I suspended his account for the moment.

He told me that the attacker changed their passwords in their blog, modified their blog content AND have resetted their DA password as a prank. Take note, they're not using the same password for their blog account and DA account. The user is suspecting that the attacker has a 0day exploit or some sort.
I don't how how the attackers did it, but they were able to breach DA and reset the password for the user. His username is 'projectx'. I suspended his account for the moment.

He told me that the attacker changed their passwords in their blog, modified their blog content AND have resetted their DA password as a prank. Take note, they're not using the same password for their blog account and DA account. The user is suspecting that the attacker has a 0day exploit or some sort.

That users da account has the DA random generated pw which was sent to his email
 
Last edited:
I would have thought rather than DA having an exploit, the attacker got root in some other way, therefore changing the admin password.
 
Anyone with the DirectAdmin login password can change it. This doesn't mean that DirectAdmin has been compromised.

Jeff
 
Back
Top