Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Results 1 to 5 of 5
  1. #1
    Member
    Join Date
    Jul 2005
    Location
    Belgium
    Posts
    78

    Smile suspicious files in /tmp hack ?

    hi folks,

    In my server's /tmp directory i found three suspicious files with verry weird names.

    vb5une5x
    vbEHwo3v
    vbiQi8Ze
    I whas verry suspicious about them and run the nobody_check security tool from webhostgear.com and it reported this

    DETECTION: Process 3878 with name entropychat and path /usr/bin/perl.#prelink#
    And WHM whas complaining to me i should disable compilers.I am 99% sure i did that as i use csf provided by chirpy here.So the question is
    • who enabled compilers ?
    • who started that mailicious process ?

    so far i killed that process and entropychat is disabled.My server is also cronned to run the nobody_check tool every 5 minutes.It is not a root comprimize otherwise the damage would been much larger can't find anything about entropychat in my logs either

    some advice will be appriciated


  2. #2
    Member serversphere's Avatar
    Join Date
    Jan 2004
    Posts
    658

    Default

    Quote Originally Posted by cpanllover View Post
    It is not a root comprimize otherwise the damage would been much larger
    It's never good to assume you weren't rooted. Especially if compilers were active after you de-activated them and you didn't do it. That throws up a red flag for me.

    Run RKhunter and Chkrootkit to see if they find anything. Grab a port and/or process monitor (check out rfxnetworks.com) to make sure nothing is opening ports or running without you knowing about it. Use nmap and netstat to check over ports as well, make sure no one has a back door open. Grep your logs to see if you can see a point of entry or anything else that might indicate they have root. Watch for high load periods, you could install a load monitoring script as well that reports what's driving up load.

    Hope that helps!
    Darren Benfer | SS-Darren | AIM: serversphere
    www.serversphere.com
    Dedicated Server Solutions Have Come Full Circle

  3. #3
    Member
    Join Date
    Mar 2006
    Location
    Brno, Czech Republic
    Posts
    507

    Default

    vb5une5x
    vbEHwo3v
    vbiQi8Ze

    usually are temporary php files. entropychat should be disabled. dunno why cpanel doesnt pull it out.

    you're not hacked.
    Not everything that is counted counts and not everything that counts can be counted

  4. #4
    Member serversphere's Avatar
    Join Date
    Jan 2004
    Posts
    658

    Default

    Quote Originally Posted by katmai View Post
    vb5une5x
    vbEHwo3v
    vbiQi8Ze

    usually are temporary php files. entropychat should be disabled. dunno why cpanel doesnt pull it out.

    you're not hacked.
    Thought OP said entropy had already been disabled, and the compilers suddenly being wr again is puzzling. If this is the case, still throws up red flags in my mind and I would still run the scans to be certain. Never hurts to be cautious.

  5. #5
    Member
    Join Date
    Jul 2005
    Location
    Belgium
    Posts
    78

    Default

    Quote Originally Posted by serversphere View Post
    It's never good to assume you weren't rooted. Especially if compilers were active after you de-activated them and you didn't do it. That throws up a red flag for me.

    Run RKhunter and Chkrootkit to see if they find anything. Grab a port and/or process monitor (check out rfxnetworks.com) to make sure nothing is opening ports or running without you knowing about it. Use nmap and netstat to check over ports as well, make sure no one has a back door open. Grep your logs to see if you can see a point of entry or anything else that might indicate they have root. Watch for high load periods, you could install a load monitoring script as well that reports what's driving up load.

    Hope that helps!
    yes i did compilers are not active this happend after i got notified about the new csf release (i am subscrided to there blog)and upgraded that's when things got suspicious it seems to be all normal again after i killed the process .I do have rkhunter and ChkRootKit but they didn't find anything.Open ports do not show me anything suspicious but i'm still watching .....

    thanks folks for the help ....

Similar Threads & Tags
Similar threads

  1. Replies: 3
    Last Post: 03-08-2011, 08:16 AM
  2. Suspicious File Alert /tmp/.wapi
    By wp11b in forum cPanel and WHM Discussions
    Replies: 5
    Last Post: 06-22-2009, 07:44 AM
  3. CHKROOTKIT suspicious files (newbie)
    By Lammypie in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 09-19-2006, 11:06 AM
  4. bandwidth to the roof: suspicious files in tmp
    By Secret Agent in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 06-07-2006, 10:35 AM
  5. tmp shm hack
    By Michael-MS in forum cPanel and WHM Discussions
    Replies: 7
    Last Post: 03-01-2005, 07:36 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube