当前位置:网站首页>Early in the morning, pay Bora SMS to say that you won the "prize"? Dealing with server mining virus - kthreaddi
Early in the morning, pay Bora SMS to say that you won the "prize"? Dealing with server mining virus - kthreaddi
2022-07-28 16:27:00 【Sun Fendou】
Deal with server mining virus - kthreaddi
- When your server has the following symptoms , Congratulations on winning the prize


I opened the server early this morning and found that the card was not good , So using top The order was checked , Sure enough , The server has been mined , Here is a complete solution !

Due to the soaring of bitcoin , It may drive the production of other mining viruses , This virus can not only occupy crazily cpu Resources can also attack other servers through the port of the server , It can be said that it is harmful to others but not beneficial to oneself , Very vicious !!!
Have a look first kthreaddi Ugly face
Use ll /proc/3436 have a look Where does it run 
When you see it, it appears in www The following documents are and [kthreaddi] The process user is www That may be through web Way to inject , Excluded my first idea through Redis Port entry , Then switch to this file 
It doesn't show its original shape !
There is a link to open such an advertisement of a foreign man !
【 kthreaddi 】 It's a mining virus Constantly write scheduled tasks Perform the operation
Do you think it will be solved when you find it ?
First, top Command to check the occupied process PID 3436 Kill directly But after a period of time, it will automatically establish the process , Think about it, it's someone else who came in with his ability. How can he say to leave
This kind of immortality is not tenacious , But there is a task that keeps running
Use the view scheduled task command crontab -e Sure enough, there is a scheduled task , What's more annoying is that I can't find this file
Then only Delete all scheduled tasks , That's easy to say , Would rather kill a thousand by mistake , We can't let one go ( Too reckless , It is recommended to back up the files of scheduled tasks first )
So the world is quiet !
边栏推荐
- mysql 查看事件状态语句和修改办法
- Telecommuting can be easily realized in only three steps
- PHP获取小程序码,小程序带参数跳转
- A good start
- 解决uniapp等富文本图片宽度溢出
- 五舅的思考
- 跳表的实现
- R language uses ggpairs function of ggally package to visualize pairwise relationship graph of grouping multivariable, set alpha parameter to change image transparency, diagonal continuous variable de
- Redis series 4: sentinel (sentinel mode) with high availability
- Why do most people who learn programming go to Shenzhen and Beijing?
猜你喜欢
随机推荐
Abaqus GUI界面解决中文乱码问题(插件中文乱码也适用)
优化Hypermesh脚本性能的几点建议
Ffmpeg get the first frame
为什么学编程的人大多数都去了深圳和北京?
JS array (summary)
Two special functions (arrow function and method)
食品安全 | 这两类瓜果宜改善便秘 孕妇人群尤其建议
R语言使用fs包的file_delete函数删除指定文件夹下的指定文件、举一反三、dir_delete函数、link_delete函数可以用来删除文件夹和超链接
Leetcode topic
Notes on October 22, 2021
魏建军骑宝马也追不上李书福
正大杯黑客马拉松数据解析竞赛
Detectron2 installation and testing
QT打包
Automatic conversion and cast
Telecommuting can be easily realized in only three steps
CoDeSys realizes bubble sorting
Dynamic programming -- digital statistics DP
HyperMesh自动保存(增强版)插件使用说明
小程序中的分页查询








