Problem with intruder. Outgoing bandwidth on port 8 too high

Support for security such as Firewalls and securing linux
Post Reply
endritshehu
Posts: 1
Joined: 2015/11/28 00:48:41

Problem with intruder. Outgoing bandwidth on port 8 too high

Post by endritshehu » 2015/11/28 01:04:06

Hello
I have a problem. My outgoing bandwidth on 80 port is too high last month. I had an intruder.
What to do?
I have attached the proccess tree.
Thank you
Attachments
process2.PNG
process2.PNG (11.93 KiB) Viewed 1665 times
Process Top
Process Top
process.PNG (31.8 KiB) Viewed 1665 times

Whoever
Posts: 1361
Joined: 2013/09/06 03:12:10

Re: Problem with intruder. Outgoing bandwidth on port 8 too

Post by Whoever » 2015/11/28 04:38:01

endritshehu wrote:Hello
I have a problem. My outgoing bandwidth on 80 port is too high last month. I had an intruder.
What to do?
I have attached the proccess tree.
Thank you
If you really believe that you had an intruder in your system, then you need to wipe it and reinstall from scratch.

User avatar
TrevorH
Site Admin
Posts: 33218
Joined: 2009/09/24 10:40:56
Location: Brighton, UK

Re: Problem with intruder. Outgoing bandwidth on port 8 too

Post by TrevorH » 2015/11/28 11:15:45

In addition you have processes running there called cwpsrv and these sound like they probably belong to something called CentOS Web Panel which has nothing whatsoever to do with the CentOS project apart from having hijacked its name without authorisation. You need to seek support from CWP if so.
The future appears to be RHEL or Debian. I think I'm going Debian.
Info for USB installs on http://wiki.centos.org/HowTos/InstallFromUSBkey
CentOS 5 and 6 are deadest, do not use them.
Use the FAQ Luke

aks
Posts: 3073
Joined: 2014/09/20 11:22:14

Re: Problem with intruder. Outgoing bandwidth on port 8 too

Post by aks » 2015/11/28 18:25:46

Instead of listing processes using CPU memory, etc. how about what is using port 80 (probably httpd process) and having a look in it's logs.
BTW, mysql should be using a "big" (resource-wise) consumer. The maldet process is (apparently) a malware detector (see https://www.rfxn.com/projects/linux-malware-detect/) - so if you installed it, it's probably doing what it should be doing.
You havemn't posted anything to do with the reported problem (bandwidth) and if you are using cpanel, ask them.

Post Reply