linux-admin.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* deleted perl hacks in /tmp
@ 2010-04-15 21:36 Chris
  2010-04-16  1:42 ` Dwight Hubbard
  2010-04-16  9:28 ` terry white
  0 siblings, 2 replies; 8+ messages in thread
From: Chris @ 2010-04-15 21:36 UTC (permalink / raw)
  To: linux-admin

I have some web servers which occasionally have hacks that are uploaded that
change their name to look like apache and somehow get apache to send requests
to them.  The result is that people somewhat randomly get pages advertising
self enhancing drugs etc.  The hacks are perl scripts, but they are run from
/tmp and then deleted.  Trying to get anything out of /proc/pid/fd/whatever
just yields an empty file.  Anyone have any ideas on how to recover the
original script?  Right now I just have a process checking for them and
whacking them when I see them, but I'd like to know more about them to actually
prevent them from happening.

Any thoughts would be appreciated!

Chris

^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2010-05-01 19:27 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2010-04-15 21:36 deleted perl hacks in /tmp Chris
2010-04-16  1:42 ` Dwight Hubbard
2010-04-16  4:43   ` Alex
2010-04-16  9:28 ` terry white
2010-04-16 15:45   ` Chris
2010-04-16 20:38     ` Herta Van den Eynde
2010-04-16 21:27       ` Chris
2010-05-01 19:27         ` Alex

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).