Re: FreeBSD 6.3 installation hacked

2009-09-22 Thread Leandro Quibem Magnabosco
Aflatoon Aflatooni escreveu: I found a script in /tmp directory which could have been uploaded using php or Java. How would they execute the code in /tmp directory? Thanks You can execute files from scripts or from apache itself when they are scripts. There are several programming/scriptin

Re: FreeBSD 6.3 installation hacked

2009-09-22 Thread Aflatoon Aflatooni
Sent: Tuesday, September 22, 2009 8:51:05 AM Subject: Re: FreeBSD 6.3 installation hacked Aflatoon Aflatooni escreveu: > My server installation of FreeBSD 6.3 is hacked and I am trying to find out > how they managed to get into my Apache 2.0.61. > This is what I see in my http error

Re: FreeBSD 6.3 installation hacked

2009-09-22 Thread Brian Seklecki
On Tue, 2009-09-22 at 05:01 -0700, Aflatoon Aflatooni wrote: > My server installation of FreeBSD 6.3 is hacked and I am trying to find out > how they managed to get into my Apache 2.0.61. > > This is what I see in my http error log: > > [Mon Sep 21 02:00:01 2009] [notice] caught SIGTERM, shutti

Re: FreeBSD 6.3 installation hacked

2009-09-22 Thread Leandro Quibem Magnabosco
Aflatoon Aflatooni escreveu: My server installation of FreeBSD 6.3 is hacked and I am trying to find out how they managed to get into my Apache 2.0.61. This is what I see in my http error log: [Mon Sep 21 02:00:01 2009] [notice] caught SIGTERM, shutting down [Mon Sep 21 02:00:14 2009] [notice]

FreeBSD 6.3 installation hacked

2009-09-22 Thread Aflatoon Aflatooni
My server installation of FreeBSD 6.3 is hacked and I am trying to find out how they managed to get into my Apache 2.0.61. This is what I see in my http error log: [Mon Sep 21 02:00:01 2009] [notice] caught SIGTERM, shutting down [Mon Sep 21 02:00:14 2009] [notice] Apache/2.0.61 (FreeBSD) PHP/5