Gentoo Archives: gentoo-user

From: Nilesh Govindarajan <contact@××××××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Re: Rootkit?
Date: Thu, 06 Oct 2011 16:56:46
Message-Id: 4E8DDD8C.3080004@nileshgr.com
In Reply to: [gentoo-user] Re: Rootkit? by Alberto Luaces
1 On Thu 06 Oct 2011 09:06:06 PM IST, Alberto Luaces wrote:
2 > Nilesh Govindarajan writes:
3 >
4 >> One of the servers I manage has a strange problem.
5 >>
6 >> Every 24h, someone starts a process shows up as perl in the list, but
7 >> launching command is /usr/sbin/httpd.
8 >> It shows just one process, but when I run something like this:
9 >>
10 >> ps -C perl -o cmd,pid
11 >>
12 >> I get some 5-6 processes alternatively with cmd as /usr/sbin/httpd or
13 >> /usr/bin/perl.
14 >>
15 >> The even more interesting thing is, /usr/sbin/httpd does not exist.
16 >> I suspect a rootkit, but chkrootkit & rkhunter reported nothing.
17 >>
18 >> Also, I found a mysterious file: /tmp/ips.txt with following content:
19 >> xxx.xxx.xxx.xxx
20 >> 127.0.0.1
21 >> addr:xxx.xxx.xxx.xxx
22 >> addr:
23 >> addr:127.0.0.1
24 >> addr:
25 >>
26 >> Somebody is aware of a malware/rootkit which creates such files?
27 >
28 > I had some of that recently. The attacker used a instance of phpmyadmin
29 > to inject into its URL a wget command to download a perl script from
30 > another site. Look for `wget' into apache logs.
31 >
32
33 @all
34 Apache was never installed & I don't see any reason to install it
35 because nginx satisfies my needs. I grepped for the string wget in all
36 logs and php files, found some, but they were for libssh2 in wordpress
37 code.
38 @Michael,
39 I thought of doing that, but before I discovered the file, I'd already
40 killed the processes. Will check later when the process is relaunched
41 sometime later.
42
43 --
44 Nilesh Govindarajan
45 http://nileshgr.com

Replies

Subject Author
Re: [gentoo-user] Re: Rootkit? Michael Mol <mikemol@×××××.com>