3 Apaches Down
By NullMind on September 7, 2003 |
Print This Post
this morning while checking the helpdesk I got a suprise .. 3 different servers for the same client had apache down, a manual restart would not bring it back to live, and worst .. no errors on the log.
upon further investigation I found this on rc.local
/etc/rc.d/init.d/.incsshd -p 31221
/sbin/insmod /etc/.incrl.o
unfortunately on of my techs also found it and deleted it .. seems the system was compromised .. but the other two .. no indication of any breaches.
the kernels are 2.4.18’s .. so I know they have the ptrace exploit .. time to do some recompiling
Null
Popularity: 17% [?]
comment
Posted in: Computers / Internet
Did you like it? Click here to subscribe for free.
Share and Save
adsense ad?
No comments.
Quick Look
- john mcdermott: agreed
- NullMind: Lol, heya John, long time no see
.. what can I say, a face only a mother or a blind wife could love
- john mcdermott:
i remember this face ! - NullMind: LOL, thank you
- Mr Tee: Well, what can I say
Welcome to my side of the office
- Books / Movies (7)
- Computers / Internet (107)
- Cooking Recipes (2)
- Family (36)
- Featured (4)
- General (74)
- Photography (9)
- RC (65)
- Short Rants (5)
- Toonz (20)
- Trips / Places (26)
- Voicemails (1)
- Work (27)
8IGHT-T
8T
Berg
Blade
Blog
Broken In
BT
Couch
Earth Hour
fieldrunnerd
Fioroni
gherkin
Google
Hirobo
Hosting365
iJaiBreak
Internet
iPhone
Jailbreak
london
Losi
MAC
MacBook Pro
MLST
Neo08
NNRC
OFNA
OSX
Parallels
Purple Fever
RC
RC NUT
Relio
Robbed
Rock Crawling
Server
SMD
snrc
Team Losi
UK2
Valentine
Virtuozzo
VPS
WebHosting
Wordpress

Post a Comment
Answer a question or login: