ntpd eating all CPUs (!)

General support questions
hunter86_bg
Posts: 2019
Joined: 2015/02/17 15:14:33
Location: Bulgaria
Contact:

Re: ntpd eating all CPUs (!)

Post by hunter86_bg » 2018/09/25 17:01:34

As you have been hit by crypto miner, you should consider wiping the machine and start from scratch.

User avatar
TrevorH
Site Admin
Posts: 33219
Joined: 2009/09/24 10:40:56
Location: Brighton, UK

Re: ntpd eating all CPUs (!)

Post by TrevorH » 2018/09/25 18:48:06

There doesn't appear to have been a root compromise here unless those ls outputs were from /etc.

When re-enabling selinux on a system where it's been disabled, first set it to permissive in /etc/sysconfig/selinux, then touch /.autorelabel and reboot to relabel everything and then you can flip it to enforcing.
The future appears to be RHEL or Debian. I think I'm going Debian.
Info for USB installs on http://wiki.centos.org/HowTos/InstallFromUSBkey
CentOS 5 and 6 are deadest, do not use them.
Use the FAQ Luke

Post Reply