----- Original Message ----- From: "Tanya Muluw" <[email protected]>
To: <[email protected]> Sent: Thursday, April 23, 2009 11:24 PM Subject: [tanya-jawab] dmesg
Dear Linuxer Gentoo saya hang, setelah reboot, saya coba cek dmesg ada seperti ini : About to compile this: "/default\.ida\?nnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnn%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u9090%u8190%u00c3%u0003%u8b00%u531b%u53ff%u0078%u0000%u00=a" About to compile this: "get (/scripts/root\.exe\?/c\+dir|/msadc/root\.exe\?/c\+dir|/c/winnt/system32/cmd\.exe\?/c\+dir|/d/winnt/system32/cmd\.exe\?/c\+dir|/scripts/\.\.%5c\.\./winnt/system32/cmd\.exe\?/c\+dir|/_vti_bin/\.\.%5c\.\./\.\.%5c\.\./\.\.%5c\.\./winnt/system32/cmd\.exe\?/c\+dir|/_mem_bin/\.\.%5c\.\./\.\.%5c\.\./\.\.%5c\.\./winnt/system32/cmd\.exe\?/c\+dir|/msadc/\.\.%5c\.\./\.\.%5c\.\./\.\.%5c/\.\.Á\.\./\.\.Á\.\./\.\.Á\.\./winnt/system32/cmd\.exe\?/c\+dir|/scripts/\.\.Á\.\./winnt/system32/cmd\.exe\?/c\+dir|/scripts/\.\.À/\.\./winnt/system32/cmd\.exe\?/c\+dir|/scripts/\.\.À¯\.\./winnt/system32/cmd\.exe\?/c\+dir|/scripts/\.\.Áo\.\./winnt/system32/cmd\.exe\?/c\+dir|/scripts/\.\.%35c\.\./winnt/system32/cmd\.exe\?/c\+dir|/scripts/\.\.%35c\.\./winnt/system32/cmd\.exe\?/c\+dir|/scripts/\.\.%5c\.\./winnt/system32/cmd\.exe\?/c\+dir|/scripts/\.\.%2f\.\./winnt/system32/cmd\.exe\?/c\+dir)" About to compile this: "^ " About to compile this: "^ajprot " About to compile this: "^[]z].?.?$" About to compile this: "bittorrent protocol|d1:ad2:id20:|'7p\)[rp]|^azver$|^get /scrape?info_hash=" About to compile this: "^(\$mynick |\$lock |\$key )" About to compile this: "^[ÅÔã-å].?.?.?.?([ !234...@abcfghijklmnopqrstuvwx[`,'"--~Ts>oz ¡¢£¤]|y................?[ -~]|-....$)" About to compile this: "^get (/.download/[ -~]*|/.supernode[ -~]|/.status[ -~]|/.network[ -~]*|/.files|/.hash=[0-9a-f]*/[ -~]*) http/1.1|user-agent: kazaa|x-kazaa(-username|-network|-ip|-supernodeip|-xferid|-xferuid|tag)|^give [0-9][0-9][0-9][0-9][0-9][0-9][0-9][0-9]?[0-9]?[0-9]?" About to compile this: "^[ ][]" About to compile this: "gnuclear connect/[ - -~]*user-agent: gnucleus [ - -~]*lan:" About to compile this: "^(gnd[]?.?.?|gnutella connect/[012]\.[0-9] |get /uri-res/n2r\?urn:sha1:|get /.*user-agent: (gtk-gnutella|bearshare|mactella|gnucleus|gnotella|limewire|imesh)|get /.*content-type: application/x-gnutella-packets|giv [0-9]*:[0-9a-f]*/|queue [0-9a-f]* [1-9][0-9]?[0-9]?\.[1-9][0-9]?[0-9]?\.[1-9][0-9]?[0-9]?\.[1-9][0-9]?[0-9]?:[1-9][0-9]?[0-9]?[0-9]?|gnutella.*content-type: application/x-gnutella|...................?lime)" About to compile this: "<peerplat>|^get /getfilebyhash\.cgi\?|^get /queue_register\.cgi\?|^get /getupdowninfo\.cgi\?" About to compile this: "^....................trtphotl" About to compile this: "^(post[ - -~]*<passwordhash>................................</passwordhash><clientver>|4???üÿ|get[ - -~]*host:imsh\.download-prod\.musicnet\.com|(|)f.?.?.?.?.?.?.?.?.?.?.?.?.?.?.?.?.?.?.?.?.?.?.?.?.?.?.?.?(|)f)"About to compile this: "^1..Z"About to compile this: "^(public|aes)key: [0-9a-f]*end(public|aes)key$"About to compile this: "^(.[][!-~]+ [!-~]+ [0-9][0-9]?[0-9]?[0-9]?[0-9]?"[ - -~]+" ([0-9]|10)|1(send|get)[!-~]+ "[ - -~]+")"About to compile this: "x-openftalias: [-)(0-9a-z ~.]"About to compile this: "^?"....z"About to compile this: "^getmp3filename|^.?.?.?(q:\+|q2:)|^[-][-].?.?.?.?$"About to compile this: "^(..?|..[ -~]+f..?.?.?.?.?.?.?)$"About to compile this: "s?"111\.00 beta |â<ié"About to compile this: "^tni.?[-]?t[-]s[](glob|who are you$|query data)"About to compile this: "^[()]...?.?.?(reg|get|query)"About to compile this: "user-agent: da [678]\.[0-9]"About to compile this: "^(e_ÐÕ|e_.*0.60(6|8)w)"Itu apa ya, apakah ada hubungannya dengan han g ?++ kalo ngelihat log diatas sepertinya server di serang worm tuh, bisa jadiresourcenya jadi low saat proses itu terjadi(CMIIW)-rianu- -- FAQ milis di http://wiki.linux.or.id/FAQ_milis_tanya-jawab Unsubscribe: kirim email ke [email protected] Arsip dan info milis selengkapnya di http://linux.or.id/milis
