Re: hacked



At 12:39 AM 10/12/2006, you wrote:
>I can delete everything in the 2 directories, and edit/change the
>php.php file to empty it out because it was a php script that allowed
>someone to do anything on the server they wanted, but I can not for
>the life of me delete them. I thought maybe they replaced the
>/bin/rm file, but it does not appear to be a hacked "rm".

Run lsattr on the files. You might have to use chattr to allow you to
delete them.

No clue on the other stuff.

Yep, that was it. The hacker had the u and i bits set. It wasn't on the files or the sub-directories. It was on the main directory that was just a space. Kind of weird that I could delete all of the other files that where under that directory.

Thanks
Steve

--
redhat-list mailing list
unsubscribe mailto:redhat-list-request@xxxxxxxxxx?subject=unsubscribe
https://www.redhat.com/mailman/listinfo/redhat-list



Relevant Pages

  • Re: hacked
    ... php.php file to empty it out because it was a php script that allowed ... someone to do anything on the server they wanted, ... \ / Ribbon Campaign ...
    (RedHat)
  • Re: write with cURL
    ... potential security risks from other users on the same server. ... as the global web server user and thus needs world write permissions ... Hence, any PHP script ran on another account, has the ... Correct, not the same as global write, just the same Apache group write. ...
    (alt.php)
  • Re: MX lookup results different depending on client application
    ... Well it looks to me like your system has correct DNS settings, but you really need to get the non-working system's ip configuration to diagnose this problem. ... The mail server shows these results... ...
    (microsoft.public.windows.server.dns)
  • what permissions are needed to let a php script call the "svn update" subversion command?
    ... If I log into my server as root, I can easily run this line: ... Just to be very, very clear, I mean the PHP script runs but shell_exec ... to commit their work to Subversion. ... Unfuddle instead of Springloops, ...
    (comp.unix.programmer)
  • Re: ISINTEG problem
    ... > machine has the working directory on C: which is 8GB, ... > to another Windows 2000 server which has a 100GB drive that is empty. ... > I selected the First Storage group and the utility started running. ...
    (microsoft.public.exchange2000.information.store)