The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Suspicious process running under user cpanelhorde

Discussion in 'Security' started by popeye, May 13, 2014.

  1. popeye

    popeye Well-Known Member

    Joined:
    May 23, 2013
    Messages:
    313
    Likes Received:
    0
    Trophy Points:
    16
    Location:
    Texas
    cPanel Access Level:
    Root Administrator
    Hi today for the first time i had this email from the firewall lfd below, does anyone know what it means please.

    Suspicious process running under user cpanelhorde

    Executable:

    /usr/local/cpanel/3rdparty/php/54/bin/php-cgi
     
  2. cPanelMichael

    cPanelMichael Forums Analyst
    Staff Member

    Joined:
    Apr 11, 2011
    Messages:
    30,808
    Likes Received:
    667
    Trophy Points:
    113
    cPanel Access Level:
    Root Administrator
    Hello :)

    It's likely a false positive, but did you run "ps aux" or a similar command to review the process?

    Note that the LFD support forums are a good resource for issues directly related to CSF or LFD:

    ConfigServer - Support Forums

    Thank you.
     
  3. popeye

    popeye Well-Known Member

    Joined:
    May 23, 2013
    Messages:
    313
    Likes Received:
    0
    Trophy Points:
    16
    Location:
    Texas
    cPanel Access Level:
    Root Administrator
    Hi no i never run any command, and i don't use CSF forums because no one ever answers.
     
  4. Infopro

    Infopro cPanel Sr. Product Evangelist
    Staff Member

    Joined:
    May 20, 2003
    Messages:
    14,468
    Likes Received:
    196
    Trophy Points:
    63
    Location:
    Pennsylvania
    cPanel Access Level:
    Root Administrator
    Twitter:
    That's because most questions have been answered.

    Clearly chirpy is busier than others it seems and most likely dislikes replying to the same questions over and over.

    Server Administration takes more than just asking for help here on these forums, get a reply and go make a change.

    You need to actually read, and learn too.
     
  5. NixTree

    NixTree Well-Known Member

    Joined:
    Aug 19, 2010
    Messages:
    386
    Likes Received:
    1
    Trophy Points:
    18
    Location:
    Gods Own Country
    cPanel Access Level:
    Root Administrator
    That is a false positive and safe to ignore. Now whitelist the particular executable to avoid future alerts.

    1. open /etc/csf/csf.pignore using a file editor
    2. Append the following line to that fine
    exe:/usr/local/cpanel/3rdparty/php/54/bin/php-cgi
    3. Now restart LFD
    /etc/init.d/lfd restart
     
  6. popeye

    popeye Well-Known Member

    Joined:
    May 23, 2013
    Messages:
    313
    Likes Received:
    0
    Trophy Points:
    16
    Location:
    Texas
    cPanel Access Level:
    Root Administrator
    Thanks done this now from inside WHM
     
Loading...

Share This Page