Is our Linux server compromised?
May 15, 2007 8:51 AM
Subscribe
CracketyCrack? Is our Linux server compromised? (Strange high-load Perl processes spawned by apache.)
Our Linux web server is continually bogged down by multiple high-load Perl processes spawn by the apache user.
The server is a dedicated host that only myself and friends use.
For regular cgi scripts "top" and "ps" report the script's filename as the command. However, these mystery processes are identified only as "perl".
There's at least one of these processes running at all times, and sometimes up to 15+ (consuming 70% of cpu). When killed they are re-spawned.
Could this be a botnet script (perhaps a spam mailer)?
Is there anyway to determine what script Perl is interpreting? Or how/why these processes are being spawned?
Distribution: Red Hat w/ 2.6.9-041221 kernel
Apache: v2.0.51 (Fedora)
Perl: v5.8.3
posted by stungeye to computers & internet (17 comments total)
3 users marked this as a favorite
posted by togdon at 8:53 AM on May 15, 2007