LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-30-2006, 02:34 AM   #1
smshuja
LQ Newbie
 
Registered: Dec 2005
Posts: 4

Rep: Reputation: 0
Slow server & Mysterious files in /tmp


Hi All,
I have noticed that our server has become quite slow. I also noticed that as soon as i restart apache some encrypted files are generated in /tmp , with file names such as php3Gqkez, all of different sizes, and sometimes gets deleted automatically. but when i check the server load from WebHostManager everything seems normal

is there anyway i can find out which script is creating these files?

Many thanks
Shuja

Last edited by smshuja; 05-30-2006 at 02:36 AM.
 
Old 05-30-2006, 07:27 AM   #2
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
Who owns those files? Verify the integrity of the Apache binary itself. If you have a rpm-based system you can use rpm -V <path_to_apache>, otherwise md5sum and compare the hash versus a known good version. Also, make sure that the running version of apache is the actual one and not an alternate trojaned copy by checking the execution path with pstree or ps auxf and verify that the proper apache binary is running.

I'd also go through all of the apache logs and look for anything that looks suspicious, especially anything with shell commands in it (like wget, cd, etc). It would also be a good idea to download and install chkrootkit or rkhunter on the system and run a scan.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Mysterious System processes SGR-A SUSE / openSUSE 7 05-17-2006 12:23 AM
file:/tmp - mysterious contents. Rm, or not rm? linuxfond Linux - Newbie 5 06-12-2004 02:00 PM
HTTPD running multiple processes jjustin01 Linux - Software 1 03-04-2004 07:16 AM
Numerous scb_*.tmp files in /tmp dburk Programming 3 08-18-2003 04:28 PM
5 httpd processes running on an idle box? J_Szucs Linux - Networking 2 04-07-2003 08:58 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:26 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration