Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 10 of 10
  1. #1
    Member
    Join Date
    Jan 2005
    Posts
    8

    Default Extremely high server load - BDflush running very high- possible hack

    Hi guys, I have quite a problem and after seacrching for a long time I have not found anything to help. I had an E-mail from my host a few days ago, saying my server carried out an attack on another IP and that my server may have been compromised, I changed passwords on all accounts etc, but I have little experience and was not able to install the APF Firewall.

    Now my Server load is always above 4-5 and goes to 10 sometimes. My sites all work fast as usual which is really odd, but in my Current CPU usage it shows a bdflush command sucking up all my CPU, never seen this before and killing it does nothing. Can anyone offer any help and is this a possible hack?


    Pid Owner Priority Cpu % Mem % Command
    6093 nobody 0 29.4 0.5 [bdflush]
    6091 nobody 0 28.6 0.5 [bdflush]
    6103 nobody 0 28.6 0.5 [bdflush]

    User Domain %CPU %MEM Mysql Processes
    nobody 96.62 3.82 0.0
    Top Process %CPU 82.2 /usr/local/apache/bin/httpd -DSSL
    Top Process %CPU 77.7 [bdflush]
    Top Process %CPU 76.9 [bdflush]

    I could really do with some help here, a bit worried about the server.

    Thanks

  2. #2
    Registered User
    Join Date
    Jan 2004
    Posts
    4

    Default

    I'm seeing the same thing but can't figure out what's happening. Ideas? Anyone else seeing tihs?

    FYI:
    I'm running RH Enterprice 3. WHM 10.1.0 cPanel 10.2.0-R82

    Thanks,
    Last edited by bchughes; 07-20-2005 at 04:52 PM.

  3. #3
    Member
    Join Date
    Oct 2003
    Posts
    37

    Default

    I am also having this problem.

    It's very hard to locate where it's coming from...

    I've tried everything... I may even have to look at all 100 domain's logs on the server.

    Keep us posted.

  4. #4
    Member
    Join Date
    Jan 2005
    Posts
    8

    Default

    Not since you changed to Pure FTP is it? Has happened since then to me.

  5. #5
    Registered User
    Join Date
    Jan 2004
    Posts
    4

    Default

    I switched to PureFTP quite awhile ago. Interesting thing is at around 5 today, the load went away. Everything seems fine.

  6. #6
    Member
    Join Date
    Oct 2003
    Posts
    37

    Default

    I have always used Pure-FTPd.

    As it is a Perl script being executed by nobody, surely it must be via http. I've been trying to search through logs to find exploited phpBB's but it's proving difficult.

    Also for me, it has stopped... I was hoping for it to come back soon so I could catch it out with this method - http://forum.ev1servers.net/showthread.php?t=52811

  7. #7
    Member
    Join Date
    Jan 2005
    Posts
    8

    Default

    According to my host eximstats caused it, have disabled it and server has worked fine.

  8. #8
    Member
    Join Date
    Jun 2004
    Posts
    7

    Default

    We used Access Control Lists to disable execution of alike programs by user nobody. I am not sure if this is an exploit or a bug.

  9. #9
    Registered User
    Join Date
    Jan 2004
    Posts
    4

    Default

    It's back again. Anyone else seeing this?

  10. #10
    Member
    Join Date
    Oct 2003
    Posts
    37

    Default

    Same here... I thought I had got rid of it by correcting a security hole in phpBB 2.0.15

Similar Threads & Tags
Similar threads

  1. Server Slow - Extremely High CPU Usage
    By ralbano in forum cPanel and WHM Discussions
    Replies: 7
    Last Post: 01-03-2009, 08:56 AM
  2. *please* help...server load extremely high
    By Secret Agent in forum cPanel and WHM Discussions
    Replies: 24
    Last Post: 04-27-2006, 10:41 AM
  3. Extremely High Server Load... Out of the blue
    By Glasswalker in forum New User Questions
    Replies: 4
    Last Post: 11-19-2005, 09:32 AM
  4. Extremely high server load!
    By limneos in forum cPanel and WHM Discussions
    Replies: 7
    Last Post: 09-10-2005, 03:25 PM
  5. High server load and high memory use?
    By Squeeze a Snack in forum New User Questions
    Replies: 1
    Last Post: 05-23-2005, 03:49 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube