Please whitelist cPanel in your adblocker so that you’re able to see our version release promotions, thanks!

The Community Forums

Interact with an entire community of cPanel & WHM users!

One of my accounts is using more then 70% of the recources

Discussion in 'Security' started by gadalf, Jun 22, 2014.

  1. gadalf

    gadalf Well-Known Member

    Joined:
    Jun 8, 2014
    Messages:
    50
    Likes Received:
    0
    Trophy Points:
    6
    cPanel Access Level:
    Root Administrator
    One of my accounts is using more then 70% of the resources

    I go to Current Running Processes and get this for this account:

    I go to public_html/modules/mod_feed for this account and dont find 1.sh file.

    Any suggestion?
     
  2. gadalf

    gadalf Well-Known Member

    Joined:
    Jun 8, 2014
    Messages:
    50
    Likes Received:
    0
    Trophy Points:
    6
    cPanel Access Level:
    Root Administrator
    and from the process manager for this account /usr/bin/host
     
  3. Infopro

    Infopro cPanel Sr. Product Evangelist
    Staff Member

    Joined:
    May 20, 2003
    Messages:
    16,574
    Likes Received:
    439
    Trophy Points:
    583
    Location:
    Pennsylvania
    cPanel Access Level:
    Root Administrator
    Twitter:
    You might want to suspend that account until you've had a closer look, or hired a professional to look for you.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  4. gadalf

    gadalf Well-Known Member

    Joined:
    Jun 8, 2014
    Messages:
    50
    Likes Received:
    0
    Trophy Points:
    6
    cPanel Access Level:
    Root Administrator
    If that is an abuse and i kill the process will it be stopped?
     
  5. Infopro

    Infopro cPanel Sr. Product Evangelist
    Staff Member

    Joined:
    May 20, 2003
    Messages:
    16,574
    Likes Received:
    439
    Trophy Points:
    583
    Location:
    Pennsylvania
    cPanel Access Level:
    Root Administrator
    Twitter:
    Maybe. If its got a cron setup to restart it if stopped it may not.

    Personally, I'm a shoot first (suspend the account right away) and ask questions (look closer at the account and these files) later. Leaving a customers website up while I investigate is not an option.

    If you have CSF installed, it should have alerted you to this issue and hopefully automagically killed the process as well. If you don't have it installed and configured to do that, you should.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  6. SS-Maddy

    SS-Maddy Well-Known Member

    Joined:
    Mar 28, 2009
    Messages:
    117
    Likes Received:
    10
    Trophy Points:
    68
    cPanel Access Level:
    Root Administrator
    I would suggest you to perform a malware scan on the account. In majority of the cases the account would be compromised due poorly managed applications such as WP plugins. maldet appears to be a good tool.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
Loading...

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice