LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-03-2011, 09:14 AM   #1
ssri06
LQ Newbie
 
Registered: Aug 2011
Posts: 3

Rep: Reputation: Disabled
php.cmdshell.cih.210 -- how serious?


php.cmdshell.cih.210

What kind of malware is this? ?How serious and how do I remove it?

I need help..
Thank in advance
 
Old 08-03-2011, 10:47 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by ssri06 View Post
What kind of malware is this?
It's a PHP shell. It allows the attacker to upload and download files, enable backdoors, query the database, send e-mail, bounce connections and whatever else as the web server user.


Quote:
Originally Posted by ssri06 View Post
How serious
If it's any good and if it's used for a prolonged period of time w/o the server owner knowing and if the host isn't protected well it could allow the attacker to gain access to the system.


Quote:
Originally Posted by ssri06 View Post
and how do I remove it?
This file is just a symptom: on removing it may reappear as easily. You need to address the cause: find out who uploaded it and how.
- Please tell us when this started.
- Please post output from running 'stat' on the file and in which directory it resides.
- List open files, processes, network connections and users:
Code:
'( /usr/sbin/lsof -Pwln 2>&1; /bin/ps acxfwwwe 2>&1; /bin/netstat -anpe 2>&1; /usr/bin/lastlog 2>&1; /usr/bin/last 2>&1; /usr/bin/who -a 2>&1; ) > /path/to/log.txt
- Check your web servers logs for anomalies:
Code:
logwatch.pl --numeric --detail 5 --service all --range All --archives --print 2>&1 >> /path/to/logwatch.txt
* Post anything else worth remarking including OS, distribution, release, software that runs in your web stack (that is: on top of the web server, database and interpreted languages) like bulletin board, web log, shoping cart, statistics or web-based management panel software.

Last edited by unSpawn; 08-03-2011 at 10:50 AM. Reason: //More *is* more
 
Old 08-04-2011, 06:04 AM   #3
ssri06
LQ Newbie
 
Registered: Aug 2011
Posts: 3

Original Poster
Rep: Reputation: Disabled
Thanks a ton for the info!
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
distro for iPAQ 210 cupsn Linux - Mobile 1 11-08-2009 06:42 PM
BT Voyager 210 and ADSL K Torode Linux - Newbie 3 12-13-2006 04:45 PM
Linux on a 210 MB Mini CD-R njdube Linux - Distributions 1 04-05-2006 04:42 AM
TP-Link 210+ and 250+ T-Dob Linux - Wireless Networking 0 05-29-2004 01:17 AM
clam antivirus CIH?? crashmeister Linux - Security 7 08-15-2002 04:48 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:27 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration