[QUOTE=unSpawn;4108919]In addition to that, I just don't know one by the name of "apache-init-server", could you please save data like this: '(/bin/ps axfwwwe; /usr/sbin/lsof -Pwln; /bin/ls -al /var/spool/cron; locate apache-init-server; netstat -antpe; lastlog; last; who -a) > /dev/shm/data.txt', scrub sensitive data if necessary and
attach the plain text "data.txt" file? After attaching I'd bring down the web server and mail daemon just in case. Checking system and daemon logs is a good thing to do. [\Quote]
I can't get the data.txt attached. It's too big for the forums max, but the netstat shows where these are coming from:
Active Internet connections (servers and established)
Proto Recv-Q Send-Q Local Address Foreign Address State User Inode PID/Program name
tcp 0 0 127.0.0.1:10024 0.0.0.0:* LISTEN 100 132951431 21813/amavisd (mast
tcp 0 0 127.0.0.1:10025 0.0.0.0:* LISTEN 0 132951797 21874/master
tcp 0 0 0.0.0.0:3306 0.0.0.0:* LISTEN 27 132951128 21701/mysqld
tcp 0 0 127.0.0.1:3310 0.0.0.0:* LISTEN 101 132950955 21613/clamd
tcp 0 0 0.0.0.0:40404 0.0.0.0:* LISTEN 48 132955866 22398/apache-init-s
tcp 0 0 127.0.0.1:631 0.0.0.0:* LISTEN 0 132950654 21535/cupsd
tcp 0 0 127.0.0.1:25 0.0.0.0:* LISTEN 0 132951679 21874/master
tcp 0 0 my.host.ip:25 0.0.0.0:* LISTEN 0 132951678 21874/master
tcp 0 1 my.host.ip:40945 200.229.199.198:25 LAST_ACK 0 0 -
tcp 0 0 127.0.0.1:10025 127.0.0.1:59516 ESTABLISHED 89 132963212 27905/smtpd
tcp 0 0 my.host.ip:59358 217.124.183.2:25 ESTABLISHED 89 132970149 21896/smtp
tcp 49 0 127.0.0.1:41139 127.0.0.1:10025 CLOSE_WAIT 100 132953245 21947/amavisd (ch1-
tcp 0 0 127.0.0.1:10025 127.0.0.1:41139 FIN_WAIT2 0 0 -
tcp 0 0 127.0.0.1:59516 127.0.0.1:10025 ESTABLISHED 100 132963199 21948/amavisd (ch1-
tcp 0 0 my.host.ip:51049 212.85.64.68:6667 ESTABLISHED 48 132971146 28018/apache-init-s
tcp 0 1 my.host.ip:57129 212.85.64.68:6667 SYN_SENT 48 132978931 28670/apache-init-s
tcp 0 1 my.host.ip:53922 212.85.64.68:6667 SYN_SENT 48 132978886 30339/apache-init-s
tcp 0 0 my.host.ip:47071 212.85.64.68:6667 ESTABLISHED 48 132978975 28406/apache-init-s
tcp 0 1 my.host.ip:40452 212.85.64.68:6667 SYN_SENT 48 132978820 32015/apache-init-s
tcp 0 0 my.host.ip:38295 212.85.64.68:6667 ESTABLISHED 48 132976381 22398/apache-init-s
tcp 0 0 :::143 :::* LISTEN 0 132951218 21743/dovecot
tcp 0 0 :::80 :::* LISTEN 0 132954239 22000/httpd
tcp 0 0 :::21 :::* LISTEN 99 132954044 21988/proftpd: (acc
tcp 0 0 :::22 :::* LISTEN 0 132950607 21526/sshd
tcp 0 0 :::993 :::* LISTEN 0 132951219 21743/dovecot
tcp 0 0 ::ffff:my.host.ip:22 ::ffff:my.home.ip:1284 ESTABLISHED 0 132950830 21591/0
No idea what these's IP's are. They trace to Swiss IP's.
I could not locate apache-init-server anywhere on the machine.
I can't bring down the server, it's my only webserver at the moment.
Quote:
Originally Posted by unSpawn
Also please tell us what forum, web log, admin tool, web-based panel, etc, etc, you run, possibly with versions.
|
I am running Swiftpanel 1.6 (Gameserver control panel)
Here is the full data.txt:
https://docs.google.com/document/edi...thkey=CLir4MYI