Fedora Linux Support Community & Resources Center

Go Back   FedoraForum.org > Fedora 17/18 > Using Fedora
FedoraForum Search

Forgot Password? Join Us!

Using Fedora General support for current versions. Ask questions about Fedora and it's software that do not belong in any other forum.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 26th December 2004, 04:00 AM
Secret Agent Offline
Registered User
 
Join Date: Nov 2004
Posts: 199
phpbb worm affecting another server

I received an email from anonymous...

"A worm using a phpbb vulnerability is trying to infect my system coming from IP xx...."

Well, I ran rkhunter and chkrootkit and both came back fine. Are there any others I can run to check for such a worm?

Specs:
RHE 3.3
Cpanel 9.9.9 R-14
PHP v 4.3.1.0


I believe the worm is running as nobody. I did notice a high load in server status for nobody user.

Code:
User Domain %CPU %MEM Mysql Processes 
nobody  95.24 14.34 0.0 
Top Process %CPU 96.3 /hsphere/shared/apache/bin/httpd -DSSL 
Top Process %CPU 96.2 /hsphere/shared/apache/bin/httpd -DSSL 
Top Process %CPU 96.0 /hsphere/shared/apache/bin/httpd -DSSL
Kernel Info:
Linux server.myserver.com 2.4.21-4.0.1.ELsmp #1 SMP Thu Oct 23 01:27:36 EDT 2003 i686 i686 i386 GNU/Linux
Please give me a hand here.
Reply With Quote
  #2  
Old 26th December 2004, 04:27 AM
Woad_Warrior's Avatar
Woad_Warrior Offline
Registered User
 
Join Date: Dec 2004
Location: Harmony, PA
Posts: 457
http://www.phpbb.com/phpBB/viewtopic.php?t=248046
they're basically reccomending updating your php software to latest version and checking to make sure someone isn't hacking you.
Reply With Quote
  #3  
Old 26th December 2004, 04:28 AM
Secret Agent Offline
Registered User
 
Join Date: Nov 2004
Posts: 199
My CPU load is going insane because of this

the process is:
/hsphere/shared/apache/bin/httpd -DSSL

running as nobody

how do I stop this?
Reply With Quote
  #4  
Old 26th December 2004, 04:33 AM
Woad_Warrior's Avatar
Woad_Warrior Offline
Registered User
 
Join Date: Dec 2004
Location: Harmony, PA
Posts: 457
well, for starters, until you resolve the issue, i'd shut down the phpbb.
Reply With Quote
  #5  
Old 26th December 2004, 04:35 AM
Secret Agent Offline
Registered User
 
Join Date: Nov 2004
Posts: 199
I don't think you comprehend what is happening here. Read my first and second post.

The process is running as nobody and it does not say phpbb in anyway. I only mentioned that "someone" sent me the email. I am checking to see if it is phpbb or not and what is causing the spikes in CPU usage. I cannot shut down phbb because obviously i have no idea who is running it nor proof that phpbb is causing it.
Reply With Quote
  #6  
Old 26th December 2004, 04:46 AM
Woad_Warrior's Avatar
Woad_Warrior Offline
Registered User
 
Join Date: Dec 2004
Location: Harmony, PA
Posts: 457
sorry. my mistake. what ver apache and hsphere you running?
Reply With Quote
Reply

Tags
affecting, phpbb, server, worm

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Global Crisis affecting Fedora's... Nokia Wibble 2 8th January 2009 11:53 PM
sound affecting game performance? Spensers Using Fedora 4 4th March 2008 08:23 AM
Xine affecting system volume buntz Using Fedora 2 19th January 2007 12:46 AM
AC affecting Bootup? mrlinuxnewb Using Fedora 0 31st October 2006 08:26 PM
Can't connect to mysql server from phpbb :[ dashdanw Servers & Networking 1 8th October 2006 10:52 PM


Current GMT-time: 04:21 (Sunday, 19-05-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat