PDA

View Full Version : bots ..etc



stepanhluchan
04-23-2007, 02:31 PM
Hi...not sure if this is the right place to ask, but I don't know where else to post this. I'm having trouble with some of the users accounts probably being insecure, as I'm finding weird stuff in my /tmp directory every now and then. Today there was a .z1 file..when I opened it, I could clearly see that it was a bot script put there this afternoon... My question(s) ;

1) How can I trace back how the file got there and through which account?

2) how can I prevent this to happen? the users are using phpBB boards, I warned them so they updated the whole thing and secured it as much as possible..but still these things are happening.

3) what is best to use to scan the system every day for such files...and for example files that are used for phishing (had to deal with that as well) and have them put in quarantaine or delete them?

Any tips would be very appreciated.

thanks

stepan

dreamfox
05-02-2007, 01:17 PM
Any luck?
I have same problem

stepanhluchan
05-02-2007, 02:10 PM
nope...I'm gonna try rack911.com or some other service to solve this....

smtalk
05-02-2007, 02:12 PM
Hi...not sure if this is the right place to ask, but I don't know where else to post this. I'm having trouble with some of the users accounts probably being insecure, as I'm finding weird stuff in my /tmp directory every now and then. Today there was a .z1 file..when I opened it, I could clearly see that it was a bot script put there this afternoon... My question(s) ;

1) How can I trace back how the file got there and through which account?

2) how can I prevent this to happen? the users are using phpBB boards, I warned them so they updated the whole thing and secured it as much as possible..but still these things are happening.

3) what is best to use to scan the system every day for such files...and for example files that are used for phishing (had to deal with that as well) and have them put in quarantaine or delete them?

Any tips would be very appreciated.

thanks

stepan

Use ELS for your server security.

dreamfox
05-02-2007, 02:15 PM
What's ELS?

smtalk
05-02-2007, 02:22 PM
http://www.directadmin.com/forum/showthread.php?t=17070

dreamfox
05-02-2007, 02:25 PM
i use freebsd

smtalk
05-02-2007, 02:34 PM
Ah.. Then try to read something like eth0.us etc. :) For how-to secure /tmp directory etc.