Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 4 of 4
  1. #1
    Member
    Join Date
    Jan 2005
    Posts
    5

    Thumbs down Folding@Home (fah) - trojan?

    Hi - we noticed a script running on our CPanel box this morning called:

    FahCore_a0.exe

    It was decompressed into the /tmp folder and executed by the nobody user.

    There are really only two ways this could happen - i) CPanel executed the program or ii) a user exploited the CPanel server, uploaded, extracted and executed the program.

    I don't like either scenario - does anyone know anything about it?

    Folding@Home appears to be a stanford university project using distributed computing to perform computationally intensive protein folding algorithms...

  2. #2
    Member
    Join Date
    Jun 2005
    Location
    Den Haag
    Posts
    120

    Default

    I think option 2, because i don't see a reason for cPanel to participate in the FAH project.
    Did you know that cPanel doesn't count ftp traffic from and to an users account? Do you want it fixed? Vote for this bug http://bugzilla.cpanel.net/show_bug.cgi?id=6463

  3. #3
    Member
    Join Date
    Oct 2004
    Posts
    45

    Default

    Now a quick guess - someone is trying to use exploited machines - such as yours to run FAH so they can get the best bragging rights for the amount of units processed. Somewhere, there will be a config file that links this to a fah user. If you use that info and go back to the FAH project you will certainly get a lot of info on the person/s responsible.

    You did make a copy of everything didn't you?

  4. #4
    Member
    Join Date
    Sep 2004
    Posts
    422

    Default

    It was decompressed into the /tmp folder and executed by the nobody user.

    There are really only two ways this could happen - i) CPanel executed the program or ii) a user exploited the CPanel server, uploaded, extracted and executed the program.
    Wrong.. try looking at your customers or your php scripts and update them, the running as 'nobody' gives this away.

Similar Threads & Tags
Similar threads

  1. Replies: 1
    Last Post: 03-17-2011, 07:13 PM
  2. Trojan or what ?
    By 5416339 in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 03-03-2011, 12:22 PM
  3. Help With Home Server Home Page
    By WebDummie in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 06-14-2010, 04:21 PM
  4. Trojan?
    By hifi_ninja in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 02-10-2007, 07:40 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube