Wednesday, May 8, 2013

lfd on xxxx :Suspicious process running under user


Apakah pernah menerima email notify seperti dibwh yang sering hampir setiap 3 jam ??

---------kutipan---------
Time:    Wed May  8 10:47:48 2013 +0700
PID:     7147
Account: baind
Uptime:  68 seconds

Executable:

/usr/local/cpanel/3rdparty/bin/php-cgi

Command Line (often faked in exploits):

/usr/local/cpanel/3rdparty/bin/php-cgi /usr/local/cpanel/base/3rdparty/squirrelmail/src/download.php
---------end---------

Notify yg dikirim oleh lfd (Login Failure Daemon) jika anda install plugin ConfigServer Security & Firewall dlm cpanel. Untuk mendisablenya langkahnya tambahkan dalam file csf.pignore baris perintah exe:/usr/local/cpanel/3rdparty/bin/php-cgi
kemudian restart lfd.

-----selesai----- 

No comments: