Z
z0q
Guest
Hi everyone,
Since a few months our webserver keeps getting hacked. When this happens a lot of files are added or modified in our webroot. These
files and modifications include mailbots. This results in our webserver sending spam mails and the exim mail queue fills up. Another
thing that happens after an attack is that we cannot create new files, because all the inodes are being used. After every attack we clean
the server and it works again, but it is, of course, very annoying.
We have already tried multiple things. Such as:
- Change the CHMOD of all folders in the webroot to 775 and all the files to 664.
- Run a virusscan with ClamAV
- Run RKHunter
- Install Apache Mod Security, but we have disabled it again, because some of our websites did not work properly anymore with it
- Empty the mail queue and delete infected files
- Installing SFTP instead of FTP
- Block Root access via SSH
- Upgrade the server
- Restart the server
- And more
Is anyone experienced in this area? Or does anyone know how we can secure our server?
We would really appreciate your help
.
Sincerely,
Z0q
Since a few months our webserver keeps getting hacked. When this happens a lot of files are added or modified in our webroot. These
files and modifications include mailbots. This results in our webserver sending spam mails and the exim mail queue fills up. Another
thing that happens after an attack is that we cannot create new files, because all the inodes are being used. After every attack we clean
the server and it works again, but it is, of course, very annoying.
We have already tried multiple things. Such as:
- Change the CHMOD of all folders in the webroot to 775 and all the files to 664.
- Run a virusscan with ClamAV
- Run RKHunter
- Install Apache Mod Security, but we have disabled it again, because some of our websites did not work properly anymore with it
- Empty the mail queue and delete infected files
- Installing SFTP instead of FTP
- Block Root access via SSH
- Upgrade the server
- Restart the server
- And more
Is anyone experienced in this area? Or does anyone know how we can secure our server?
We would really appreciate your help

Sincerely,
Z0q
Last edited: