Help - Search - Members - Calendar
Full Version: is this a hacker or spam?
The Planet Forums > Security > General Security
ns1
Suddenly my ping is going wild. Warning, critical, then OK, and so on throughout the day.
So I took a look at the server status and saw that Server load is high. I checked Mysql-Apache usage and one site was using about 70% of CPU! It was marked red of course.

So I checked raw access log for that user and got this:

CODE
78.47.208.242 - - [12/Aug/2009:14:37:40 +0200] "POST /are.na.php HTTP/1.1" 200 6 "-" "Mozilla/3.0 (compatible; TALWinHttpClient)"
78.47.208.242 - - [12/Aug/2009:14:37:45 +0200] "POST /are.na.php HTTP/1.1" 200 6 "-" "Mozilla/3.0 (compatible; TALWinHttpClient)"
78.47.208.242 - - [12/Aug/2009:14:37:53 +0200] "POST /are.na.php HTTP/1.1" 200 6 "-" "Mozilla/3.0 (compatible; TALWinHttpClient)"
78.47.208.242 - - [12/Aug/2009:14:38:14 +0200] "POST /are.na.php HTTP/1.1" 200 6 "-" "Mozilla/3.0 (compatible; TALWinHttpClient)"
78.47.208.242 - - [12/Aug/2009:14:38:21 +0200] "POST /are.na.php HTTP/1.1" 200 6 "-" "Mozilla/3.0 (compatible; TALWinHttpClient)"
78.47.208.242 - - [12/Aug/2009:14:38:27 +0200] "POST /are.na.php HTTP/1.1" 200 6 "-" "Mozilla/3.0 (compatible; TALWinHttpClient)"
78.47.208.242 - - [12/Aug/2009:14:38:39 +0200] "POST /are.na.php HTTP/1.1" 200 6 "-" "Mozilla/3.0 (compatible; TALWinHttpClient)"
78.47.208.242 - - [12/Aug/2009:14:38:40 +0200] "POST /are.na.php HTTP/1.1" 200 6 "-" "Mozilla/3.0 (compatible; TALWinHttpClient)"
78.47.208.242 - - [12/Aug/2009:14:38:58 +0200] "POST /are.na.php HTTP/1.1" 200 6 "-" "Mozilla/3.0 (compatible; TALWinHttpClient)"
78.47.208.242 - - [12/Aug/2009:14:39:03 +0200] "POST /are.na.php HTTP/1.1" 200 6 "-" "Mozilla/3.0 (compatible; TALWinHttpClient)"
78.47.208.242 - - [12/Aug/2009:14:39:08 +0200] "POST /are.na.php HTTP/1.1" 200 6 "-" "Mozilla/3.0 (compatible; TALWinHttpClient)"
78.47.208.242 - - [12/Aug/2009:14:39:23 +0200] "POST /are.na.php HTTP/1.1" 200 6 "-" "Mozilla/3.0 (compatible; TALWinHttpClient)"
78.47.208.242 - - [12/Aug/2009:14:39:29 +0200] "POST /are.na.php HTTP/1.1" 200 6 "-" "Mozilla/3.0 (compatible; TALWinHttpClient)"
78.47.208.242 - - [12/Aug/2009:14:39:41 +0200] "POST /are.na.php HTTP/1.1" 200 6 "-" "Mozilla/3.0 (compatible; TALWinHttpClient)"
93.174.93.58 - - [12/Aug/2009:14:39:16 +0200] "POST /index.php HTTP/1.1" 200 141369


I assume that this is some script doing but how do I locate it and stop it?
Tomy Durden
The requests are coming from a host in Germany. It's possible that it could be a brute force attempt if there's a login script on that page.

Do you happen to have a calendar on that page?
ns1
yes, there si a calendar as a joomla component

i also found these files as last accesed:
are.na.php
cool.php
eizlwicrmu.cgi
rmad1pkgwt.cgi

the php files seem to look like a contact script, but as far as I can see it is not used by site.
and cgi files are empty (0 bytes).
Tomy Durden
QUOTE (ns1 @ Aug 12 2009, 09:29 AM) *
yes, there si a calendar as a joomla component

Poorly written bots will often get stuck on Calendars as it keeps following the next/previous month links. Try temporarily removing it from the page for a couple minutes or so and see if the requests keep coming.
ns1
In CPU/Memory/MySQL Usage I have this:

CODE
User    Domain    %CPU    %MEM    MySQL Processes
[b]optikehr    optike.hr    72.67    4.06    0.0[/b]
Top Process    %CPU 14.4    httpd [optike.hr] [/obrazovanje/tehnicka-skola-rudera-boskovica/pdf.php]
Top Process    %CPU 12.0    httpd [optike.hr] [/index.php]
Top Process    %CPU 11.0    /usr/bin/perl -w kgi.cgi


I have disabled the calendar but CPU usage is still high.. see above..
ns1
Also I have noticed that in Exim Mail Queue I have currently 57891 messages in the mail queue.

Is that normal? There are about 100 hosting packages.....
James Jhurani
QUOTE (ns1 @ Aug 12 2009, 11:02 AM) *
Also I have noticed that in Exim Mail Queue I have currently 57891 messages in the mail queue.

Is that normal? There are about 100 hosting packages.....


do "exim -bp" and use:

exim -Mvh $email_id_goes_here to view the email headers
exim -Mvb $email_id_goes_here to view the email body

The email id is the weird string listed with "exim -bp".

It is possible they are abusing the calendar to spool spam email. If you're not using the calendar, maybe try renaming the file to something obscure. If your mail queue starts to clear up after that, I believe you have your answer.
ns1
it seems that it is spam being sent from my server... I just got ticketed about it...
ns1
I have asked Totalserversolutions for help and they have managed to put a stop to it.

Now everything is back at normal... more or less icon_smile.gif
Zion21
QUOTE (ns1 @ Aug 14 2009, 04:07 AM) *
I have asked Totalserversolutions for help and they have managed to put a stop to it.

Now everything is back at normal... more or less


That definitely was weird traffic, thats for sure. Glad you got everything sorted out.
ichsie
QUOTE (ns1 @ Aug 14 2009, 04:07 AM) *
I have asked Totalserversolutions for help and they have managed to put a stop to it.

Now everything is back at normal... more or less icon_smile.gif


Is this the one who helped you? http://www.totalserversolutions.com/index.html

I guess it's commercial help?

Anyway you should always get to know how the mess comes around in the first place than just clearing up the mess itself. If they have helped you with this, do ask for the source of this problem and prevent it from happening next time. Or you will keep having those headaches.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.