Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 4 of 4
  1. #1
    Member
    Join Date
    Jan 2002
    Posts
    74

    Default Trojan Horses Detected by (WHM)... ?

    We're starting to see this from one of our servers...

    Hidden Pid detected! [pid 334]
    hidden from ps: [yes]
    hidden from kernel: [yes]
    binary location: [/sbin/init2.4.18 (deleted)]


    chkrootkit reports nothing other than the standard Port 465 error due to PortSentry. Is there something we should be looking for? Has anyone run into this before?

    Thanks - Brian

  2. #2
    Moderator cPanel Partner NOC Badge dgbaker's Avatar
    Join Date
    Sep 2002
    Location
    Toronto, Ontario Canada
    Posts
    2,773

    Default

    Try this. In ssh type init

    You should this, Usage: init 0123456SsQqAaBbCcUu

    If you see other wise the system has been comprimised. The init file you'll probably end up seeing will have an option to unhide pids etc...

    Check there first.

    Also another really simple way to catch the kiddie hackers, is to grep through /usr/bin /usr/sbin /bin /sbin lookinf for the work "****************" all in caps. That is one of the strings found in a lot of hackers programs.

    That would be the start.
    Regards,
    David
    Forum Moderator

  3. #3
    Moderator cPanel Partner NOC Badge dgbaker's Avatar
    Join Date
    Sep 2002
    Location
    Toronto, Ontario Canada
    Posts
    2,773

    Default

    Also check in /usr/man for a hidden directory, I think it was called .sman
    Regards,
    David
    Forum Moderator

  4. #4
    Member
    Join Date
    Jan 2002
    Posts
    74

    Default

    Originally posted by dgbaker
    Also check in /usr/man for a hidden directory, I think it was called .sman
    No hidden directories, at least not there. I also looked in /dev - as I've seen script kiddies use that folder too.

    Also, init produces the correct output when run, and no hidden processes...

    I wonder if this could be a CPanel bug or something?

    Thanks - Brian

Similar Threads & Tags
Similar threads

  1. 'Trojan Horses Detected by WHM' - Real or Not
    By metal_cd in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 12-18-2007, 08:53 AM
  2. HELP,HELP Trojan Horses Detected by (WHM)
    By xxgchappy in forum cPanel and WHM Discussions
    Replies: 7
    Last Post: 06-12-2004, 10:38 AM
  3. Trojan Horses Detected by (WHM)
    By rasilva in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 04-16-2004, 08:39 PM
  4. Trojan Horses Detected by (WHM)
    By stevo in forum cPanel and WHM Discussions
    Replies: 10
    Last Post: 02-07-2004, 01:27 PM
  5. Trojan Horses Detected by (WHM)
    By Ronny in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 01-24-2004, 09:42 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube