Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 5 of 5
  1. #1
    Member
    Join Date
    Jun 2004
    Posts
    29

    Exclamation What kind of hack is this...???

    I have found some files on /tmp named like /tmp/dos-xxx.xxx.xxx.xxx where xxx.xxx.xxx.xxx is an out ip. In these files is just a number, I think a counted value. I think this is ip of a victim, that has been attacked by our box, but how?

    I have suexec & phpsuexec installed, then owner of all files on /tmp is defined. But how can an script use nobody to execute? I think it is impossible with phpsuexec, except direct code executing throught browser. I wonder how? maybe a phpBB exploit or so? ok, but how can I prevent this to repeat again?

    I have not found any log to show me that how these files created and accessed.
    If be fair, I dont know how exactly use egrep to find a record related to this issue.

    Any idea may help me & others to find a solution for this issue.

    Thanks.
    Last edited by bhznat; 11-02-2005 at 01:54 PM.

  2. #2
    Moderator cPanel Partner NOC Badge dgbaker's Avatar
    Join Date
    Sep 2002
    Location
    Toronto, Ontario Canada
    Posts
    2,773

    Default

    Those are actually IP's that have been found by the apache module dos-evasive to be potentially trying to DOS your server. dos-evasive blocks the IP temporarily to try to avoid the DOS from happening.

    http://nanoweb.si.kz/manual/mod_dosevasive.html
    Regards,
    David
    Forum Moderator

  3. #3
    Member
    Join Date
    Jun 2004
    Posts
    29

    Default

    WOW, nice.
    For this I must say thank you so much, David.

    I think this is not documented any where, becuase I found nothing with googling this.

    Regards,

  4. #4
    Member sh4ka's Avatar
    Join Date
    May 2005
    Posts
    434

    Default

    is there a problem if the main server IP is included in one of those files ?

  5. #5
    Moderator cPanel Partner NOC Badge dgbaker's Avatar
    Join Date
    Sep 2002
    Location
    Toronto, Ontario Canada
    Posts
    2,773

    Default

    Potentially yes, that can occur if you have something monitoring locally and it is hitting the webserver too often and too fast.

    BTW - The name has been changed to mod_evasive. http://www.nuclearelephant.com/projects/mod_evasive/
    Regards,
    David
    Forum Moderator

Similar Threads & Tags
Similar threads

  1. Server has disappeared... kind of.... maybe....
    By schwim in forum cPanel and WHM Discussions
    Replies: 6
    Last Post: 12-13-2007, 08:35 AM
  2. New kind of spam ?
    By benito in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 08-30-2007, 07:42 AM
  3. new kind of spammer?
    By luis in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 07-02-2006, 05:50 AM
  4. What kind of an error is this?
    By NetCafe in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 05-25-2006, 06:13 AM
  5. Plone - a (kind of) HOWTO
    By trakwebster in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 12-01-2003, 01:12 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube