My cpanel server running :
WHM 10.8.0 cPanel 10.8.1-R113
Fedora i686 - WHM X v3.1.0
has been hacked into. On boot I get this inetd service that loads up and hogs most of the cpu/ram. After time it will spawn other inetd processess run as user nobody. I am unable to locate the source of where this is started from. These are the processes:
24668 nobody 0 26.1 0.2 inetd
24963 nobody 0 25.5 0.2 inetd
25017 nobody 0 25.2 0.2 inetd
23896 nobody 0 22.9 0.2 /var/sbin/whos
23999 nobody 0 19.9 0.2 /var/tmp/whos
17984 nobody 0 19.6 0.2 inetd
18311 nobody 0 19.6 0.2 inetd
18641 nobody 0 19.3 0.2 inetd
26543 nobody 0 19.3 0.2 inetd
Running netstat I see this:
tcp 0 80 cpanel.binghamXXX.XXX:36689 ircd-188.buy-a-shell.n:ircd ESTA BLISHED
tcp 0 80 cpanel.binghamXXX.XXX:36690 ircd-188.buy-a-shell.n:ircd ESTA
I am not running any IRC server's on this machine so I know something is wrong here. I would like to be able to locate where this fake inetd starts from and kill it. Thanks in advance for any help.
WHM 10.8.0 cPanel 10.8.1-R113
Fedora i686 - WHM X v3.1.0
has been hacked into. On boot I get this inetd service that loads up and hogs most of the cpu/ram. After time it will spawn other inetd processess run as user nobody. I am unable to locate the source of where this is started from. These are the processes:
24668 nobody 0 26.1 0.2 inetd
24963 nobody 0 25.5 0.2 inetd
25017 nobody 0 25.2 0.2 inetd
23896 nobody 0 22.9 0.2 /var/sbin/whos
23999 nobody 0 19.9 0.2 /var/tmp/whos
17984 nobody 0 19.6 0.2 inetd
18311 nobody 0 19.6 0.2 inetd
18641 nobody 0 19.3 0.2 inetd
26543 nobody 0 19.3 0.2 inetd
Running netstat I see this:
tcp 0 80 cpanel.binghamXXX.XXX:36689 ircd-188.buy-a-shell.n:ircd ESTA BLISHED
tcp 0 80 cpanel.binghamXXX.XXX:36690 ircd-188.buy-a-shell.n:ircd ESTA
I am not running any IRC server's on this machine so I know something is wrong here. I would like to be able to locate where this fake inetd starts from and kill it. Thanks in advance for any help.