• Introducing WebPros Cloud - a fully managed infrastructure platform purpose-built to simplify the deployment of WebPros products !  WebPros Cloud enables you to easily deliver WebPros solutions — without the complexity of managing the infrastructure.
    Join the pilot program today!
  • Support for BIND DNS has been removed from Plesk for Windows due to security and maintenance risks.
    If a Plesk for Windows server is still using BIND, the upgrade to Plesk Obsidian 18.0.70 will be unavailable until the administrator switches the DNS server to Microsoft DNS.

Suspicious directory - /tmp/.state help!

humpy

Basic Pleskian
Hi I am running LFD and CSF, and have suddenly started receiving warning emails

Time: Sun Mar 24 05:38:24 2013 +0000
File: /tmp/.state
Reason: Suspicious directory
Owner: apache:apache (502:503)
Action: No action taken

inside /tmp/.state is an empty 04 dir, and a /server directory, containing files..

d--------- 2 apache apache 4096 Mar 24 02:44 .
d--------- 4 apache apache 4096 Mar 24 02:44 ..
---------- 1 apache apache 0 Mar 24 02:44 application.dir
---------- 1 apache apache 0 Mar 24 02:44 application.lock
---------- 1 apache apache 0 Mar 24 02:44 application.pag
---------- 1 apache apache 0 Mar 24 02:44 internal.dir
---------- 1 apache apache 0 Mar 24 02:44 internal.lock
---------- 1 apache apache 1024 Mar 24 02:44 internal.pag

Have googled, and grepped apache access_logs for /.state, , but cannot find anything..

should I be worried about a rogue script or hacking ? or is this legitimate part of plesk accessing the .tmp?


thanks
Will
 
What about checking system with rkhunter or chkrootkit?
 
Back
Top