Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 13 of 13
  1. #1
    Member
    Join Date
    Sep 2003
    Posts
    199

    Default Cron <root@static> chown root:root && chmod 4755 && rm -rf /etc/cron.d/core && kil

    Cron <root@static> chown root:root && chmod 4755 && rm -rf /etc/cron.d/core && kill -USR1 25xxx

    I keep receiving emails about 10 every 2 minutes. The subjuect is

    Cron <root@static> chown root:root && chmod 4755 && rm -rf /etc/cron.d/core && kill -USR1 25xxx


    Email:
    chown: too few arguments
    Try `chown --help' for more information.

    How do I go about fixing this? Is this an exploit?

  2. #2
    Member serversphere's Avatar
    Join Date
    Jan 2004
    Posts
    658

    Default

    Smells like the cron.d core exploit, what kernel are you running? I would lock down the box and check it out...

  3. #3
    Member
    Join Date
    Sep 2003
    Posts
    199

    Default

    How do I find out the kernel I am running?

  4. #4
    Member
    Join Date
    Sep 2003
    Posts
    199

    Default

    2.6.10-1.771_FC2smp #1 SMP Mon Mar 28 01:10:51 EST 2005 i686 i686 i386 GNU/Linux

  5. #5
    Member
    Join Date
    May 2006
    Posts
    62

    Default

    in ssh it types uname -a

  6. #6
    Member
    Join Date
    Sep 2003
    Posts
    199

    Default

    Now that I had found out the version is there a fix and if so how do I get it and apply it?

  7. #7
    Member
    Join Date
    Sep 2003
    Posts
    199

    Default

    Anyone have a fix for this?

  8. #8
    Member
    Join Date
    Sep 2003
    Posts
    199

    Default

    anyone? I am running Fedora Core 2... anyone please help resolve this issue...

  9. #9
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    You need to find out how the hackers are getting into the server to resolve the issue. You'll also need to clean up that cron job by checking through /etc/cron.* and in /var/spool/cron/*
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  10. #10
    Member
    Join Date
    Jan 2005
    Posts
    1,880

    Default

    It looks very much like an exploit - an example of it is given at http://www.milw0rm.com/exploits/2005.

    Your only option is to get a professional to take a look at things for you.

  11. #11
    Member
    Join Date
    Sep 2003
    Posts
    199

    Default

    So who can I get to take a look at it for me? Please send some recommendations for some services... thanks for your help...

  12. #12
    Member
    Join Date
    Jan 2005
    Posts
    1,880

    Default

    I'd give Chirpy a go..

  13. #13
    Member
    Join Date
    Jun 2003
    Location
    NC, USA
    Posts
    94

    Default

    Btw, you are in fact being hit by that exploit mentioned. The CVE for this exploit is: http://cve.mitre.org/cgi-bin/cvename...=CVE-2006-2451

    You can check there for the fixes for each of the distros (Red Hat, Ubuntu, suse, etc).

    I was hit by this bug on 2 of my rhel4 boxes because I didn't stay on top of kernel upgrades. Red Hat had already released the fixed kernel when I was hit. I would suggest to do a re-install as soon as possible. There's no clue what was ccompromised. A linux tech could go in and do bandaid fixes, but this exploit can provide a root shell, with which the user could have done anything to your system.

    With the 2 compromised servers, one hacker replaced all index files with his own. Luckily, on the ohter server he didn't do any damage. So you never know.

Similar Threads & Tags
Similar threads

  1. Replies: 4
    Last Post: 05-21-2010, 10:10 AM
  2. Exim & PHP & Domains & Ip's & /etc/mailips
    By NemoXP in forum E-mail Discussions
    Replies: 2
    Last Post: 05-13-2010, 12:37 AM
  3. Exim & PHP & Domains & Ip's & /etc/mailips
    By NemoXP in forum New User Questions
    Replies: 0
    Last Post: 05-12-2010, 08:41 AM
  4. Replies: 3
    Last Post: 03-10-2008, 09:33 PM
  5. Replies: 2
    Last Post: 07-04-2007, 08:12 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube