Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 10 of 10
  1. #1
    Member
    Join Date
    May 2007
    Posts
    12

    Default what is /usr/bin/perl -w hnc.cgi

    Hello,

    When i was running top -cd2 command following scripts are taking high cup uses on server. But when we are go home directory we didn't find any thing.

    24489 "User Name" 20 0 6732 5084 1164 S 8.0 0.2 11:00.69 /usr/bin/perl -w hnc.cgi
    26456 "User Name" 20 0 6876 5080 1164 S 8.0 0.2 7:23.47 /usr/bin/perl -w hnc.cgi
    32569 "User Name" 20 0 6748 5056 1164 S 7.5 0.2 8:57.30 /usr/bin/perl -w hnc.cgi

    Could you please update us why this script are running under some particular users and what the application of this script.

  2. #2
    Member rhenderson's Avatar
    Join Date
    Apr 2005
    Location
    Oklahoma
    Posts
    742

    Default

    SSH
    locate hnc.cgi
    and check it out!!

    Looks like it is a r57 shell hack, your server might be compromised.
    Google "/cgi-bin/hnc.cgi" (leave the quotes in the search) you will see what I mean.
    Last edited by rhenderson; 12-05-2008 at 10:50 AM.
    Regards,
    Randy
    Affordable Web Hosting
    _________________________

  3. #3
    Member
    Join Date
    May 2007
    Posts
    12

    Default

    Hello,

    I know how to locate this file, but i want what application of this script.

  4. #4
    Member
    Join Date
    Dec 2006
    Posts
    113

    Default

    Search these forums for: hnc.cgi

    and check my posts in the thread titled: Malicious Script hnc.cgi ?

  5. #5
    Member rhenderson's Avatar
    Join Date
    Apr 2005
    Location
    Oklahoma
    Posts
    742

    Default

    Quote Originally Posted by moinkhan31 View Post
    Hello,

    I know how to locate this file, but i want what application of this script.
    The application is a hacker file for spamming other systems, get rid of it before you get blacklisted!!
    Regards,
    Randy
    Affordable Web Hosting
    _________________________

  6. #6
    Member rhenderson's Avatar
    Join Date
    Apr 2005
    Location
    Oklahoma
    Posts
    742

    Default

    Quote Originally Posted by jpetersen View Post
    Search these forums for: hnc.cgi

    and check my posts in the thread titled: Malicious Script hnc.cgi ?
    Good post, gave you a reputation for that!!
    Regards,
    Randy
    Affordable Web Hosting
    _________________________

  7. #7
    Member
    Join Date
    Apr 2003
    Posts
    168
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Quote Originally Posted by moinkhan31 View Post
    Hello,

    When i was running top -cd2 command following scripts are taking high cup uses on server. But when we are go home directory we didn't find any thing.

    24489 "User Name" 20 0 6732 5084 1164 S 8.0 0.2 11:00.69 /usr/bin/perl -w hnc.cgi
    26456 "User Name" 20 0 6876 5080 1164 S 8.0 0.2 7:23.47 /usr/bin/perl -w hnc.cgi
    32569 "User Name" 20 0 6748 5056 1164 S 7.5 0.2 8:57.30 /usr/bin/perl -w hnc.cgi

    Could you please update us why this script are running under some particular users and what the application of this script.
    If you spot this type of behaviour again, what I suggest doing is checking out the process' environmental variables.
    eg. cat /proc/24489/environ | tr "\00" "\n"

    You are interested in the PWD section. This is how you can track it most malicious processes.
    Dylan Botha

  8. #8
    Member rhenderson's Avatar
    Join Date
    Apr 2005
    Location
    Oklahoma
    Posts
    742

    Default

    Quote Originally Posted by stdout View Post
    If you spot this type of behaviour again, what I suggest doing is checking out the process' environmental variables.
    eg. cat /proc/24489/environ | tr "\00" "\n"

    You are interested in the PWD section. This is how you can track it most malicious processes.
    Very nice I learn something in here everyday
    Regards,
    Randy
    Affordable Web Hosting
    _________________________

  9. #9
    Member
    Join Date
    Apr 2003
    Posts
    168
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Quote Originally Posted by rhenderson View Post
    Very nice I learn something in here everyday
    Glad you liked it. It's a useful way to track processes which are being sneaky -
    spoofed process name, ect.
    Dylan Botha

  10. #10
    Member
    Join Date
    May 2007
    Posts
    12

    Default

    Hello,

    Its really nice.

    Thank you

Similar Threads & Tags
Similar threads

  1. What is the correct permission to /usr/bin/perl ?
    By konrath in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 09-21-2009, 01:03 PM
  2. what is /usr/bin/perl -w hnc.cgi
    By moinkhan31 in forum cPanel and WHM Discussions
    Replies: 9
    Last Post: 12-06-2008, 09:13 AM
  3. Re:How to go to /usr/bin/perl
    By phpserver in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 11-27-2008, 05:13 PM
  4. Replies: 0
    Last Post: 02-26-2007, 04:19 PM
  5. cgi-bin vs. scgi-bin vs. perl
    By Boboss in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 10-21-2006, 11:27 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube