• Introducing WebPros Cloud - a fully managed infrastructure platform purpose-built to simplify the deployment of WebPros products !  WebPros Cloud enables you to easily deliver WebPros solutions — without the complexity of managing the infrastructure.
    Join the pilot program today!
  • Support for BIND DNS has been removed from Plesk for Windows due to security and maintenance risks.
    If a Plesk for Windows server is still using BIND, the upgrade to Plesk Obsidian 18.0.70 will be unavailable until the administrator switches the DNS server to Microsoft DNS.

domain hacked?

A

ACID25

Guest
Hi

on one of ouer servers we saw today ther load average is higher then normal. So we checked how could it happen and figure out that one domain must have a security hole
Code:
  748 ?        S      0:00 sh -c (sleep 99999999999999;killall -9 udp) & CONSOLE=/dev/console SELINUX_INIT=YES MYSQL_UNIX_PORT=/var/lib/mysql/mysql.sock TERM=linux 
PERL5LIB=/usr/local/psa/lib/perl5/site_perl/5.8.3:/usr/local/psa/lib/perl5/site_perl/5.8.3/i386-linux-thread-multi OLDPWD
=/var/www/vhosts/sfachim.de/httpdocs INIT_VERSION=sysvinit-2.85 PATH=/sbin:/usr/sbin:/bin:/usr/bin:/usr/X11R6/bin runlevel=3 RUNLEVEL=3 PWD=/tmp 
LANG=en_US.UTF-8 previous=N PREVLEVEL=N PSA_RUN_MODE=1 SHLVL=7 OPENSSL_CONF=/usr/local/psa/admin/conf/openssl.cnf _=/usr/bin/perl
but we could not excalty figure out how it works....maybe anybody can explain we what happens there and how could we close this???

THX and best regards
ACID25
 
Hi


yes the domain was hacked through a unsecure php script...

regards
ACID25

thread can be closed!
 
Back
Top