On Thu, 25 May 2017 22:48:41 +0000, Kaz Kylheku wrote:
On 2017-05-25, Lost in the Future <[email protected]> wrote:
About 2 weeks ago, they informed me that the server was running a DOS attack again and had been taken off the net.
They included this log:
List of malicious processes:===============================
wwwrun 56545 0.0 0.0 23012 4204 ? S Apr26 00:05:13 /usr/local/apache/bin/httpd -DSSL
[ ... ]
Is wwwrun a user on my machine?
Not unless "they" who included "this log" have an account on your
machine and got the log from there.
Why would ISP people be sending you logs from your own machine?
It's a virtual server. It could even be that it's running on some giant
piece of hardware somewhere, with hundreds of others.
The ISP doesn't have an "account" but "plesk" is apparently the
virtualization software, which apparently gives them considerable access
(I can't see it from inside the machine, though).
As can be seen from the posting, they sent me what they said was the "FULL PROCESS LIST" (from my machine, presumably),
although it's hard to imagine that it would ever run with so few
processes. Either it ain't true that it's the "FULL PROCESS LIST", or the virus actually rebooted my machine to do it's evil work and then rebooted
it again with the normal configuration when it was done.
I'm sure they'd say that they got the tcpdump from the combined stream of
all virtual servers to their internet feed. I'm asking myself - how do
they know it was my box - even though it was my address - which, of
course, can be faked.
--- SoupGate-Win32 v1.05
* Origin: fsxNet Usenet Gateway (21:1/5)