Noticed a huge spike in my inbound traffic recently and noticed that it was the ip of my shared cPanel server. Looking at my lanalyzer it showed a lot of dns queries and then a lot of queries to port 80 on all kinds of websites from the IP of my cPanel server.
I ran Top utility to see if I can find anything and the only thing I saw was a cpanel user who was running 'phpize' for several hours.
It appears to me that something is on my system that is looking for vulnerabilities on other servers.
Not sure where to start looking for something like this. I looked at the logs of the user that was running this phpize and don't see anything error_logs
I ran Top utility to see if I can find anything and the only thing I saw was a cpanel user who was running 'phpize' for several hours.
It appears to me that something is on my system that is looking for vulnerabilities on other servers.
Not sure where to start looking for something like this. I looked at the logs of the user that was running this phpize and don't see anything error_logs
Attachments
-
24.4 KB Views: 22