Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 5 of 5
  1. #1
    Member Fakher's Avatar
    Join Date
    Sep 2010
    Location
    Pakistan
    Posts
    8

    Default Suspicious File Alert - /tmp/backs

    Hi all,

    I have started to receive emails from my server like a week ago about suspicious file running on my server. This is an example email sent to me by CSF.

    lfd on Phoenix.offshoredns.net: Suspicious File Alert

    Time: Sun Oct 10 14:10:47 2010 +0400
    File: /tmp/bds
    Reason: Binary executable
    Owner: hostingp:hostingp (937:933)
    Action: No action taken

    Time: Sun Oct 10 15:11:01 2010 +0400
    File: /tmp/backs
    Reason: Script, starts with #!
    Owner: hostingp:hostingp (937:933)
    Action: No action taken



    Its a trojan i tried to delete it but it comes back again...
    what to do?

    Please advise....

    Regards
    Fakher

  2. #2
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Oct 2003
    Posts
    1,931

    Default

    one of your users has a vulnerable php script

    if you are running suphp see what user it ls


    ls -l /tmp/bds
    Lowest Host/Empire Technology LLC
    Affordable hosting solutions http://empire-hosting.net
    List Your hosting site FREE in http://hostgeneration.com

  3. #3
    Member Fakher's Avatar
    Join Date
    Sep 2010
    Location
    Pakistan
    Posts
    8

    Default

    i have terminated the user....
    still getting alerts....

    File: /tmp/bds
    Reason: Binary executable
    - Hide quoted text -
    Owner: : (937:933)
    Action: No action taken
    how to remove these things now?

    Regards
    Fakher

  4. #4
    Member Fakher's Avatar
    Join Date
    Sep 2010
    Location
    Pakistan
    Posts
    8

    Default

    how to fix this now as the account was removed from the server....

  5. #5
    cPanel Staff cPanelTristan's Avatar
    Join Date
    Oct 2010
    Location
    somewhere over the rainbow
    Posts
    6,305
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Hello Fakher,

    If you've already removed all files in /tmp that was owned by hostingp, then you might want to see if there are any processes still running for that user on the system:

    Code:
    ps aux|grep hostingp
    Otherwise, run a find for any files and folders still owned by that user, although it would be strange for the user to own anything if they are terminated:

    Code:
    find / -user hostingp
    Please note that a find of this nature is going to take a long time to process.

    Please do check the user is actually terminated:

    Code:
    grep hostingp /etc/passwd
    grep hostingp /etc/group
    cPResources: Support Options | More Support Options | Forums Search | cPanel.net Site Search | Mailing Lists(Alt) | Docs
    -- Tristan, Forums Technical Analyst, cPanel Tech Support

    Submit a ticket | Check an existing ticket

Similar Threads & Tags
Similar threads

  1. lfd on yourserver.com: Suspicious File Alert
    By polkocholo in forum Security
    Replies: 3
    Last Post: 07-07-2011, 04:44 PM
  2. Suspicious File Alert /tmp/.wapi
    By wp11b in forum cPanel and WHM Discussions
    Replies: 5
    Last Post: 06-22-2009, 06:44 AM
  3. SECURITY ALERT: Horde arbitrary file inclusion vulnerability
    By ericgregory in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 03-06-2008, 11:10 PM
  4. SECURITY ALERT: Horde arbitrary file inclusion vulnerability
    By ericgregory in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 03-06-2008, 11:10 PM
  5. Suspicious
    By madan.cpanelnet in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 01-07-2007, 09:24 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube