Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 6 of 6
  1. #1
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Feb 2005
    Posts
    8

    Default how can i kill all process nobody?

    i have alot problem.i have 10 server i use trustix,redhat 9,redhat enterprise,centOS,fedora and freebsd.i think no OS can protect tmp.i found bot.txt worm.txt phpbb worm udb.pl.

    i find perl process in tmp alway.i want to how can i protect it and what command about kill all process nobody.

    i have suggest from ev1 but i don't know how can i do?i ask cpanel but cpanel suggest me i must be find customer run it.

    i try to search in this forum.i found this command for find customer have problem.

    grep "wget" /usr/local/apache/domlogs/*

    ev1 suggest me for this problem about udb.pl

    -------------------------------------------------------
    Our investigation found that your server was only exploited. No rootkits were installed. Nor was root access achieved. None of you local user accounts had started the attack sript either.

    Simply put, the hacker exploited the system, most likely via an apache/website script, achieved a terminal shell connection simular to ssh and telnet, then proceeded to launched an outbound attack.

    Some of the best ways to secure the server are: Have apache run under it's own user name (apache or httpd). Have the 'user' account for apache be unable to execute files located in /tmp and /var/tmp directories. Also have the user account 'nobody' should have these execution rights removed also. Nor should apache have access to execute any other applications beyond php/cgi/perl/ect to prevent future exploitation.

    Then you want to comb thru the httpd and other logs under /var/log/ and see if you can identify the means with which the hacker exploited the system to gain access. (IE did they use a buffer overflow exploit on apache? Or did they take advantage of some security hole on a website's perl/cgi/php/ect script ? Was the ftp service exploited? Once the security hole that they came in on has been identified, you can set out to secure the server so that it's not exploited once more via that hole.
    -------------------------------------------------------

    whoever can tell me how can i do?

    Thank you so much
    Best Regards
    eLife

  2. #2
    cPanel Partner NOC cPanel Partner NOC Badge AndyReed's Avatar
    Join Date
    May 2004
    Location
    Minneapolis, MN
    Posts
    2,223

    Default

    I suggest you protect and secure your servers. Running a couple of commands to kill some processes won't solve the issue. If you don't wish to hire a sys admin to secure your server(s), you need to search these forums. The security issue you're dealing with has been discusses many time.
    Andy Reed
    RHCE and CCNA
    ServerTune.com

  3. #3
    Member rpmws's Avatar
    Join Date
    Aug 2001
    Location
    back woods of NC, USA
    Posts
    1,858

    Default

    Quote Originally Posted by eLifeCP
    i have alot problem.i have 10 server i use trustix,redhat 9,redhat enterprise,centOS,fedora and freebsd.i think no OS can protect tmp.i found bot.txt worm.txt phpbb worm udb.pl.

    i find perl process in tmp alway.i want to how can i protect it and what command about kill all process nobody.

    i have suggest from ev1 but i don't know how can i do?i ask cpanel but cpanel suggest me i must be find customer run it.

    i try to search in this forum.i found this command for find customer have problem.

    grep "wget" /usr/local/apache/domlogs/*

    ev1 suggest me for this problem about udb.pl

    -------------------------------------------------------
    Our investigation found that your server was only exploited. No rootkits were installed. Nor was root access achieved. None of you local user accounts had started the attack sript either.

    Simply put, the hacker exploited the system, most likely via an apache/website script, achieved a terminal shell connection simular to ssh and telnet, then proceeded to launched an outbound attack.

    Some of the best ways to secure the server are: Have apache run under it's own user name (apache or httpd). Have the 'user' account for apache be unable to execute files located in /tmp and /var/tmp directories. Also have the user account 'nobody' should have these execution rights removed also. Nor should apache have access to execute any other applications beyond php/cgi/perl/ect to prevent future exploitation.

    Then you want to comb thru the httpd and other logs under /var/log/ and see if you can identify the means with which the hacker exploited the system to gain access. (IE did they use a buffer overflow exploit on apache? Or did they take advantage of some security hole on a website's perl/cgi/php/ect script ? Was the ftp service exploited? Once the security hole that they came in on has been identified, you can set out to secure the server so that it's not exploited once more via that hole.
    -------------------------------------------------------

    whoever can tell me how can i do?

    Thank you so much
    Best Regards
    eLife
    searching logs for wget will get you started on what site was used. find all the old phpBB installs and fix that ..mod_security helps some. But if you have no clue what this all means .. get an admin that does.
    Just keeping my "eye" on things....
    R. Paul Mathews
    RPMWS - diehard cPanel Nutcase

  4. #4
    Member
    Join Date
    Oct 2003
    Posts
    173

    Default

    www.cplicensing.net.
    Download their check phpBB version script to look for bad phpBB's. Also check for Wordpress Versions less than 1.5.2.

    Pay chirpy to secure your servers !
    www.configservers.com
    He does a great job!

  5. #5
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Feb 2005
    Posts
    8

    Default

    Thank you so much i find phpBB old version but when i find nobody perl process.i have alot process.i need command about killall process nobody for kill it and fix later.Whoever help me for command.

    Thank you so much

  6. #6
    Member
    Join Date
    Mar 2004
    Posts
    710

    Default

    For someone who is NOT a server admin, you can kill all the processes (but it probably will not do much good as they might just start all over again with the exploit) by simply rebooting.

    No hard commands, no searching and killing processes, just reboot.

    (BTW - the command for that from ssh is "reboot" - without the qoutes. It may take 15 minutes before all services are restarted, so be aware of that.)
    Lloyd F Tennison

Similar Threads & Tags
Similar threads

  1. FastCGI not kill process
    By cesarlwh in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 05-16-2011, 07:55 AM
  2. Can't kill process eating 98%. What is it doing?
    By pingo in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 01-04-2004, 09:27 AM
  3. Can't kill Mysqld process !!!!!!!!!!!!!!!!
    By azrael in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 12-04-2003, 11:25 PM
  4. how to kill this process?
    By katz_global in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 10-20-2003, 01:31 AM
  5. Kill process
    By efeito in forum cPanel and WHM Discussions
    Replies: 10
    Last Post: 10-03-2003, 09:14 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube