It appears you have not registered with our community. To register please click here ...

Author Topic: Suspicious process in top - "perl dor.pl"  (Read 1680 times)

dynaweb

  • <b>Canine Deamon</b>
  • Administrator
  • Sr. Member
  • *****
  • Posts: 493
  • Karma: +10/-0
  • Generic personal text here ...
    • MSN Messenger - danno_d_manno@yahoo.com
    • View Profile
    • DynaWeb Designs
    • Email
Suspicious process in top - "perl dor.pl"
« on: October 02, 2005, 09:44:49 PM »
On one of my servers, I am noticing two suspicious process in my top list.  They are sucking cpu :(
 
============================
 3955 nobody    25   0   876  552   384 R    23.0  0.0 370:20   0 perl dor.pl 202.152.162.197
 4342 nobody    25   0   880  688   384 R    21.0  0.0 380:41   0 perl dor.pl 200.202.206.247
============================
 
I kill them but they come back.  Any idea what they could be?
Those who cannot learn from history are doomed to repeat it. -- Linux learns.

dynaweb

  • <b>Canine Deamon</b>
  • Administrator
  • Sr. Member
  • *****
  • Posts: 493
  • Karma: +10/-0
  • Generic personal text here ...
    • MSN Messenger - danno_d_manno@yahoo.com
    • View Profile
    • DynaWeb Designs
    • Email
Suspicious process in top - "perl dor.pl"
« Reply #1 on: October 02, 2005, 09:49:38 PM »
Maybe an IRC relay?  Will conttinue investigation...
Those who cannot learn from history are doomed to repeat it. -- Linux learns.

dynaweb

  • <b>Canine Deamon</b>
  • Administrator
  • Sr. Member
  • *****
  • Posts: 493
  • Karma: +10/-0
  • Generic personal text here ...
    • MSN Messenger - danno_d_manno@yahoo.com
    • View Profile
    • DynaWeb Designs
    • Email
Suspicious process in top - "perl dor.pl"
« Reply #2 on: October 02, 2005, 10:30:39 PM »
Yes, I updated the slocate database and found psybnc, eggdrop, and other parasite bot servers running in 777ed folders. They\'re dead now. For good practice guys, run the following from time to time...


[indent]locate irc

locate eggdrop
locate bnc
locate BNC
locate ptlink
locate *****X
locate guardservices
locate psyBNC
locate .rhosts

[/indent]
Those who cannot learn from history are doomed to repeat it. -- Linux learns.

 

Related Topics

  Subject / Started by Replies Last post
9 Replies
3778 Views
Last post October 04, 2005, 08:38:25 AM
by adb22791
9 Replies
1721 Views
Last post August 10, 2005, 04:04:44 PM
by zelo
1 Replies
1710 Views
Last post September 26, 2006, 08:28:14 AM
by dynaweb
0 Replies
1454 Views
Last post February 01, 2007, 10:44:08 AM
by dynaweb
0 Replies
2291 Views
Last post April 19, 2007, 09:55:55 AM
by dynaweb