Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 9 of 9
  1. #1
    Member
    Join Date
    Mar 2004
    Posts
    859

    Default simple security question?

    Hi,

    I found a backdoor binary in /tmp simply named "bds".

    How can I find out who put it there?

    Thanks!

  2. #2
    Member
    Join Date
    Nov 2006
    Location
    Houston, TX
    Posts
    300

    Default

    Since it is in /tmp, it was most likely put there by a php script of some kind. You could look through the access logs in /usr/local/apache/domlogs for 'bds' to see if you can find the site that was used to upload the file.

    Code:
    grep -i bds /usr/local/apache/domlogs/*
    -Todd Shipway

  3. #3
    Member brianoz's Avatar
    Join Date
    Mar 2004
    Location
    Melbourne, Australia
    Posts
    1,117
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    If you're asking this, you're probably not running suphp or phpsuexec; if you were running them, the file ownership would have told you who put it there.

    There's a slight performance hit and some issues if you have a lot of scripts installed already, but it is really worth looking at making the change. Tools such as CSF/APF help too.

  4. #4
    Member
    Join Date
    Mar 2004
    Posts
    859

    Default

    So, which is less disruptive to the hosted accounts when converting over, suphp or phpsuexec?

  5. #5
    cPanel Partner NOC cPanel Partner NOC Badge AndyReed's Avatar
    Join Date
    May 2004
    Location
    Minneapolis, MN
    Posts
    2,223

    Default

    Quote Originally Posted by jols View Post
    So, which is less disruptive to the hosted accounts when converting over, suphp or phpsuexec?
    This article might help: http://servertune.com/kbase/entry/46/
    Andy Reed
    RHCE and CCNA
    ServerTune.com

  6. #6
    Member brianoz's Avatar
    Join Date
    Mar 2004
    Location
    Melbourne, Australia
    Posts
    1,117
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Quote Originally Posted by jols View Post
    So, which is less disruptive to the hosted accounts when converting over, suphp or phpsuexec?
    I'd always go for suphp these days, phpsuexec has been end-of-lifed and isn't supported by cpanel any more from what I know. Suphp is a superior solution anyway.

  7. #7
    Member
    Join Date
    Mar 2004
    Posts
    859

    Default

    Is suphp the same as Suhosin?

  8. #8
    Member brianoz's Avatar
    Join Date
    Mar 2004
    Location
    Melbourne, Australia
    Posts
    1,117
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Not remotely. Spend a few minutes reading about them and you'll see (google is your friend!!). Suhosin = PHP hardening, cuts a lot of functionality out of PHP; suphp runs PHP as individual users.

  9. #9
    Technical Product Specialist cPanelDavidG's Avatar
    Join Date
    Nov 2006
    Location
    Houston, TX
    Posts
    11,189
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Quote Originally Posted by brianoz View Post
    I'd always go for suphp these days, phpsuexec has been end-of-lifed and isn't supported by cpanel any more from what I know. Suphp is a superior solution anyway.
    Correct, SuPHP has replaced phpSuExec in EasyApache 3.

Similar Threads & Tags
Similar threads

  1. Simple security question about mod-security rule sets.
    By jols in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 08-09-2007, 04:37 AM
  2. Simple question MX Record question...
    By redlorry919 in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 05-20-2005, 06:41 AM
  3. Please help! Simple question please
    By lexmark in forum cPanel and WHM Discussions
    Replies: 19
    Last Post: 02-02-2005, 08:32 PM
  4. Simple question
    By BuBa in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 01-08-2004, 03:07 PM
  5. A simple question...
    By manokiss in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 04-29-2003, 07:00 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube