P r o f e s s i o n a l — M a n a g e m e n t — S o l u t i o n s
RSS icon Email icon Home icon
  • Found suspicious scripts in /tmp directory

    Posted on July 23rd, 2008 Admin 1 comment

    Sometimes its very frustating to find how the suspicious files are stored in /tmp directory.  How can I find out who put it there? Since this file is in /tmp directory, it was most likely put there by a vulnerable Php script.

    Look into the access log file(s) in /usr/local/apache/domlogs directory for the file “psync.txt” and see if you can find the site that was used to upload the file to your server .

    Use the following command at the prompt:

      grep -i psync.txt /usr/local/apache/domlogs/* 

    OR

      grep -i psync.txtPATH_TO_APACHE_domlogs/*

    Share/Save/Bookmark


    1 Trackbacks / Pingbacks

    Leave a reply

    You must be logged in to post a comment.