icon Get the most out of Surmunity, read our tips here! Need an interesting blog to read? You've got to read the Surpass Blog! | Welcome! Please register to access all of our features.

» Surpass Web Hosting Forums » Discussions » Private Hosting » my server Stolen!!!

Private Hosting Questions about VPS, dedicated servers and colocation.

Reply
 
LinkBack Thread Tools Search this Thread
Old May 8th, 2006, 4:03 PM   #19 (permalink)
Yabadabadoo
Super #1
 
Geoff's Avatar
 
Joined in Nov 2004
Lives in B.C., Canada
Hosted on Dedicated
1,013 posts
Gave thanks: 7
Thanked 28 times
ya that list is just a *may* be infected. Guess they are commonly exploited, or key programs/scripts.
__________________
Geoff Ellis - Surpass Dedicated Server Customer
www.adepttechs.net
Geoff is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old May 8th, 2006, 4:37 PM   #20 (permalink)
says GIMME SOME MORE!
Resident.
 
David's Avatar
 
Joined in Mar 2004
Lives in fear of Obama.
Hosted on Pass 7
13,092 posts
Gave thanks: 8
Thanked 34 times
Yeah, I get the same list when I run that on mine, too. It even tells you that it's going to find stuff that isn't what it's looking for.
__________________
David is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old May 8th, 2006, 5:55 PM   #21 (permalink)
Surpass Fan
Comfy Contributor
 
Joined in May 2004
125 posts
Gave thanks: 0
Thanked 0 times
i find this after the server last down time, but it is not the repeated issue
Quote:
Top Process %CPU 99.9 /usr/libexec/gcc/i386-redhat-linux/3.4.5/cc1 -quiet -Iext/standard/ -I/home/cpapachebuild/buildapache/php-4.4.1/ext/standard/ -I/home/cpapachebuild/buildapache/php-4.4.1/include -I/home/cpapachebuild/buildapache/php-4.4.1/main -I/home/cpapachebuild/buildapache/php-4.4.1 -I/usr/kerberos/include -I/usr/include/libxml2 -I/usr/X11R6/include -I/usr/include/freetype2 -I/home/cpapachebuild/buildapache/php-4.4.1/ext/mbstring/mbregex -I/home/cpapachebuild/buildapache/php-4.4.1/ext/mbstring/libmbfl -I/home/cpapachebuild/buildapache/php-4.4.1/ext/mbstring/libmbfl/mbfl -I/usr/include/mysql -I/home/cpapachebuild/buildapache/php-4.4.1/ext/xml/expat -I/home/cpapachebuild/buildapache/php-4.4.1/TSRM -I/home/cpapachebuild/buildapache/php-4.4.1/Zend -DPHP_ATOM_INC /home/cpapachebuild/buildapache/php-4.4.1/ext/standard/array.c -quiet -dumpbase array.c -auxbase-strip ext/standard/array.lo -g -O2 -o /tmp/ccuPQukf.s

Top Process %CPU 92.9 /usr/libexec/gcc/i386-redhat-linux/3.4.5/cc1 -quiet -I. -I. -I.. -I/usr/include/python2.3 -I../include -I../include -I../python -MD libxml2-py.d -MF .deps/libxml2-py.Tpo -MP -MT libxml2-py.lo -MQ libxml2-py.o -DHAVE_CONFIG_H libxml2-py.c -quiet -dumpbase libxml2-py.c -auxbase-strip libxml2-py.o -g -O2 -pedantic -W -Wformat -Wunused -Wimplicit -Wreturn-type -Wswitch -Wcomment -Wtrigraphs -Wformat -Wchar-subscripts -Wuninitialized -Wparentheses -Wshadow -Wpointer-arith -Wcast-align -Wwrite-strings -Waggregate-return -Wstrict-prototypes -Wmissing-prototypes -Wnested-externs -Winline -Wredundant-decls -o /tmp/cc51Qe3G.s
Top Process %CPU 92.6 /usr/libexec/gcc/i386-redhat-linux/3.4.5/cc1 -quiet -I. -I. -I. -I./include -I./include -MD legacy.d -MF .deps/legacy.Tpo -MP -MT legacy.lo -MQ legacy.o -DHAVE_CONFIG_H -D_REENTRANT legacy.c -quiet -dumpbase legacy.c -auxbase-strip legacy.o -g -O2 -pedantic -W -Wformat -Wunused -Wimplicit -Wreturn-type -Wswitch -Wcomment -Wtrigraphs -Wformat -Wchar-subscripts -Wuninitialized -Wparentheses -Wshadow -Wpointer-arith -Wcast-align -Wwrite-strings -Waggregate-return -Wstrict-prototypes -Wmissing-prototypes -Wnested-externs -Winline -Wredundant-decls -o /tmp/ccssdM0S.s
2-do you think that celeron are weak in DDOS or haking?

The reapeted issue is:-
3-i can diagnose the issue as the following
A-the server load is under 1 or 2 all the time

B-suddnly in a random unkown time the server load is jumbed to 10 and after 1 second to load 13 and afrer 1 second to load 16 and after 1 second to load 20 ..and so on up to server load 40 or 60!., then the server go down then cpanel and SSH are offline with me and i can not know what i shoud do after this point.

C-during the server load jumbing over server load 5 or 10, which i do is ----> loginng via SSH and typing "mysqladmin proc stat" if i find this line
unauthenticated user | localhost |
then i type via SSH "tail -500 /usr/local/apache/logs/access_log"
when i see the log i should find the IP that have many correntions lines, some time is see IP that repeated 2~7 times, then i type via SSH "apf -d 66.220.**.***" which block this IP, 60% of the times the server load go downgrading from server load 40 and after 1 sercond to 35 and after 1 sercond to 30 and so on untill the normal server load., the issue is 40% or %50% of the attacks times i find that after blocking the first 1~3 Ip(s) i find that after typing "tail -500 /usr/local/apache/logs/access_log" again i find another IP(s), so i need to be all the time neer the server checking and blocking IP(s), i'am really do not know if this steps is the right way or i'am not blocking the correct attacker IP(s), and is it easy to anyone to make the server load go from 1 to 90 while the server have a scripts that should protect this activity(the support telling me many times that thay have installed scripts that protect this but after 1 or 2 days the attack start again and the server load start jumping again).
__________________
Gool
gool is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old May 10th, 2006, 2:01 AM   #22 (permalink)
minor deity
Super #1
 
Bigjohn's Avatar
 
Joined in Apr 2004
Lives in Georgia
Hosted on XEON
7,387 posts
Gave thanks: 28
Thanked 94 times
use an off-site system like housecall.trendmicro.com too. if you have trouble running that on an XP machine, it's because the XP machine is likely compromised.

John
__________________
Proud to be a Surmunity Mod!
XEON PASS60 PASS61
Make a fundamental difference!
My Sites:
Curious about Brewing Beer? Join the community!
>>>>> Some Change is GOOD! Keep your paycheck! Support the Fair Tax
Get into an Art museum
Victorian London
It's your brain -ON WEB - mybrainhost.com (under development)
What SHOULD Government do? Much Less than it Does!
Bigjohn is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old May 10th, 2006, 2:22 AM   #23 (permalink)
says GIMME SOME MORE!
Resident.
 
David's Avatar
 
Joined in Mar 2004
Lives in fear of Obama.
Hosted on Pass 7
13,092 posts
Gave thanks: 8
Thanked 34 times
Quote:
Originally Posted by Bigjohn
use an off-site system like housecall.trendmicro.com too. if you have trouble running that on an XP machine, it's because the XP machine is likely compromised.

John
I use Bitdefender as an online scanner now-a-days. It found stuff the others didn't, which was nice of it.
__________________
David is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old May 10th, 2006, 2:37 AM   #24 (permalink)
Marketing Maven
Surpass Staff
 
Kayla's Avatar
 
Joined in May 2003
Lives in Orlando
24,749 posts
Gave thanks: 946
Thanked 806 times
Bitdefender:



Oddly enough, pixel art using Paint.
http://en.wikipedia.org/wiki/Image:The_Gunk.png
__________________
Follow Surpass on Twitter and Facebook
Check out the Surpass Blog



Kayla is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old May 10th, 2006, 2:55 AM   #25 (permalink)
says GIMME SOME MORE!
Resident.
 
David's Avatar
 
Joined in Mar 2004
Lives in fear of Obama.
Hosted on Pass 7
13,092 posts
Gave thanks: 8
Thanked 34 times
i now have my next avatar
__________________
David is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On