Results 1 to 11 of 11

Thread: eggdrop

  1. #1
    Member
    Join Date
    Mar 2002
    Posts
    248

    Default eggdrop

    10165 (eggdrop) /tmp/.shp/.dat/eggdrop-1.6. /tmp/.shp/.dat
    /usr/local/apache/sbin/httpd-DSSL
    -m bin.txt

    --------------------------------------------------------------------------------
    10336 (eggdrop) /tmp/.sho/.dat/eggdrop-1.6. /tmp/.sho/.dat
    /usr/local/apache/sbin/httpd-DSSL
    -m bin.txt


    what are those? am i hack?

    In my tmp,

    drwxr-xr-x 3 nobody nobody 4096 Apr 21 22:54 .shc/
    drwxr-xr-x 3 nobody nobody 4096 Apr 17 19:00 .shh/
    drwxr-xr-x 3 nobody nobody 4096 Apr 24 08:37 .sho/
    drwxr-xr-x 3 nobody nobody 4096 Apr 24 08:35 .shp/
    drwxr-xr-x 3 nobody nobody 4096 Apr 21 22:56 .shw/
    drwxr-xr-x 3 nobody nobody 4096 Apr 17 18:55 .ssh/

  2. #2
    Member
    Join Date
    Jan 2004
    Posts
    227

    Default

    I am almost willing to bet you use cpanel... so many exploits, I see eggdrops go up all over the place... to be honest I am sorry I use it some times! In most cases (That I know of) they get in threw a demo account.

    Most people set them up in /tmp, so.. yeah, you got "0wn3d"

    Just remove it and secure your box better.

  3. #3
    Member
    Join Date
    Oct 2003
    Posts
    1,020

    Default

    Originally posted by nybble
    I am almost willing to bet you use cpanel...
    What gives you that idea?

  4. #4
    Member
    Join Date
    Jan 2004
    Posts
    227

    Default

    Cause just about every cpanel box with a public demo ends up with an eggdrop on it...

  5. #5
    Member
    Join Date
    Oct 2003
    Posts
    1,020

    Default

    Oh I thought it was something a little more pedestrian such as the fact that he posted in a cpanel support forum

  6. #6
    Member
    Join Date
    Mar 2002
    Posts
    248

    Default

    I did not enable demo for the server.

    And this hacker is able to restart my server.

    How he can do so via openssl?

  7. #7
    Member
    Join Date
    Jan 2004
    Posts
    227

    Default

    Um... I am no security expert, but A. Are you running cpanel? B. do you have users on this server?

    In some cases just being a user and having cpanel access can be a bad thing... anyway, best of luck!

  8. #8
    Member
    Join Date
    Jan 2002
    Location
    UK
    Posts
    248

    Default

    Look at who owns the files - 'nobody'. This means they were created by CGI (if you dont run suexec) or PHP (if you dont run phpsuexec).

    Probably some outdated code for which there's a vulnerability been released - PHP forums/bloggers/CMS's are favourites.

    Mount your temporary space noexec, make sure you're patched up to the eyeballs and consider other avenues such as open basedir restrictons.

    You have not necessarily been "0wn3d" but simple someone has managed to execute code as your apache user 'nobody'. Nevertheless, I'd recommend you at least find the problem code and run chkrootkit for peace of mind.

  9. #9
    Member
    Join Date
    Mar 2002
    Posts
    248

    Default

    I went to execute command to secure my /tmp now.

    /scripts/securetmp

  10. #10
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Dec 2003
    Location
    Athens/GREECE
    Posts
    193
    cPanel/WHM Access Level

    DataCenter Provider

    Default

    Originally posted by goal
    Look at who owns the files - 'nobody'. This means they were created by CGI (if you dont run suexec) or PHP (if you dont run phpsuexec).
    Hello,

    I've enabled suexec through WHM but I can't find how to enable phpsuexec. Any help?
    Sincerely,

    George Vardikos
    HyperHosting Internet Services

  11. #11
    Member
    Join Date
    Nov 2002
    Posts
    1,782
    cPanel/WHM Access Level

    DataCenter Provider

    Default

    Originally posted by gvard
    Hello,

    I've enabled suexec through WHM but I can't find how to enable phpsuexec. Any help?
    You would need to recompile php for that. The best would be either from whm or shell run the apache compile. Earlier php 4.3.7 was released so you could meanwhile compiling update your php to the latest.

    In WHM -> Software -> Update Apache

    Select all you need and compile away.

    If you prefer shell, as root run:

    /scripts/easyapache

    Select all you need and compile away

    If you don't know what to select you could choose the 1-5 options presented by easyapache script. At times they help you to achieve whats required and later learn on what to include or exclude from the compile.
    :: Anand ::

    ssh root@
    who the hell is root ???

    Cpanelappz Support Forums are up now. Register Today
    http://forums.cpanelappz.com

    WHM/cPanel API : http://whmapi.cpanelappz.com
    Cpanel Login Script : www.cpanelappz.com/cpanel-login-script.htm
    Exiscan+Clam+Exim Auto Installer : www.cpanelappz.com

Similar Threads

  1. trusted user still having eggdrop killed at 12:35 everynight
    By fizz in forum cPanel & WHM Discussions
    Replies: 3
    Last Post: 04-15-2009, 03:45 PM
  2. eggdrop / maxed outbound traffic
    By Secret Agent in forum cPanel & WHM Discussions
    Replies: 1
    Last Post: 11-14-2005, 12:26 AM
  3. weird eggdrop problem
    By Snowman30 in forum cPanel & WHM Discussions
    Replies: 2
    Last Post: 08-22-2005, 09:26 PM
  4. major problem with eggdrop / crontab maybe
    By chadi in forum cPanel & WHM Discussions
    Replies: 37
    Last Post: 01-02-2005, 06:39 PM
  5. EggDrop
    By aingaranweb in forum cPanel & WHM Discussions
    Replies: 1
    Last Post: 07-27-2004, 09:54 AM