Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
PostPosted: Thu Dec 29, 2011 7:12 pm 
Offline

Joined: Thu Apr 21, 2011 11:40 am
Posts: 1
It happens once a day that a process named ./stealth (running as my apache user www-data), which is unknown to me and I cannot find on my Lucid 10.04 system via locate, consumes over 90% cpu. What could this be? Network bandwidth peaks to 15mbit/sec, is this a dos attack?

Any help on how to investigate this would be much appreciated!

Best,
Tim


Top
   
 Post subject:
PostPosted: Thu Dec 29, 2011 7:23 pm 
Offline
Junior Member

Joined: Sun Jan 02, 2011 4:38 pm
Posts: 23
On IRC:

EugeneKay>: Ubuntu Forums suggest it's a standard issue combination keylogger, irc bot, DDoS client, all that jazz.
@heckman>: It compromises ALL THE THINGS


Top
   
 Post subject:
PostPosted: Thu Dec 29, 2011 7:29 pm 
Offline
Sysop

Joined: Sat Nov 27, 2010 3:32 am
Posts: 180
Website: https://blog.timheckman.net/
Location: San Francisco, CA
AviMarcus wrote:
On IRC:

EugeneKay>: Ubuntu Forums suggest it's a standard issue combination keylogger, irc bot, DDoS client, all that jazz.
@heckman>: It compromises ALL THE THINGS


Running this command may help you track it down:

Code:
    ps auxf


However, you should consider this Linode compromised and that it's no longer safe to store any data or use it for anything. Your best option is to back up your data and redeploy.

One way to do this would be to shrink your disk images and deploy a new distro alongside. You can then copy the files over and delete the old disk image.

I would also recommend trying to determine how the compromise happened in the process of moving data to prevent it from happening again.

-Tim

Edit: Make sure you only copy files over that you know where not the root of the problem. Here's more conversation from IRC:

Quote:
Dec29 18:31:18 < EugeneKay> The forum post I read traced it down to something called Zen
Dec29 18:31:29 < rnowak> the shopping cart?
Dec29 18:31:29 < EugeneKay> Which is any of a dozen PHP packages
Dec29 18:31:40 < EugeneKay> Didn't say.
Dec29 18:31:46 < EugeneKay> But probably


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group