Index: [Article Count Order] [Thread]

Date:  Sun, 26 Mar 2006 11:41:17 -1000
From:  MuntadaNet Webmaster <webmaster (at mark) muntada.com>
Subject:  [coba-e:04366] Re: Monitoring Ports, Processes
To:  coba-e (at mark) bluequartz.org
Message-Id:  <7.0.0.16.2.20060326113809.05061fa8 (at mark) muntada.com>
In-Reply-To:  <f76f5d3e0603261256i455e91c2w69ec28062c7f9cae (at mark) mail.gmail.co m>
References:  <200603251503203.SM00400 (at mark) virus> <002801c65033$a1094010$2f427dd1 (at mark) chrism> <7.0.0.16.2.20060326095022.055d8928 (at mark) muntada.com> <f76f5d3e0603261256i455e91c2w69ec28062c7f9cae (at mark) mail.gmail.com>
X-Mail-Count: 04366

<html>
<body>
It appears as if some IRC bot is able to get uploaded.&nbsp; Yes, it
appears to be occurring near 9 PM HST but that is not always the
case.&nbsp; It has happened at other times before.&nbsp; However the late
evening appears to be the pattern the past few days.<br><br>
Shell access...I don't think so.&nbsp; I check the auth logs and other
logs that I can figure and don't see any evidence of someone logging in
with admin, root, or root-admin from anything other than the IP addresses
of known systems.&nbsp; I also checked instances of su and it doesn't
appear anything illigitimate there.&nbsp; What we suspect is that they
are finding a hole in the web apps and uploading their IRC bot to the
/tmp directory and then running their deal their.&nbsp; The bandwidth
goes crazy and effectively we have a DOS.<br><br>
-Rashid<br><br>
<br>
At 10:56 AM 3/26/2006, you wrote:<br>
<blockquote type=cite class=cite cite="">&gt;&nbsp; A client has a
website that uses PERL and PHP.&nbsp; The site keeps getting<br>
&gt; compromised.<br><br>
What do you mean by &quot;compromised&quot; ? Is someone able to get
shell<br>
access to the server? Are they defacing the website somehow
(replacing<br>
content)? Using the server to send spam?&nbsp; Does it seem to happen
at<br>
certain times of the day?</blockquote>
<x-sigsep><p></x-sigsep>
***************************************************************** <br>
MuntadaNet Web Hosting and Web Design Services<br>
<font color="#0000FF"><u>
<a href="http://www.muntada.com/" eudora="autourl">
http://www.muntada.com<br><br>
</a></u></font>Sales - sales (at mark) muntada.com <br>
Support - support (at mark) muntada.com <br>
Billing - billing (at mark) muntada.com<br><br>
Main Office - 808-689-6092<br>
Fax - (808) 356-0279<br>
*****************************************************************<br><br>
</body>
</html>