These forums are locked and archived, but all topics have been migrated to the new forum. You can search for this topic on the new forum: Search for my server seems to be doing some attacking: on the new forum.
hello - i received a nasty-gram about my server hacking from a German server that provided me with the following information (below). in order to understand the German stuff, i was forced to watch several episodes of "Hogans Heroes".
the (supposed) offending programs were:
virtue-now.net/cgi-bin/php5.cgi bayern-polen.info/cgi-bin/php5.cgi
which neither domain name is on my server.
since the offending programs were php5.cgi, i assume this is virtualmin?
files sent to me: were 199-231-184-26.txt and report.txt (both attached)
any suggestions?? thank you!
sorry attachment option not working for me today. here is what i am seeing:
report.txt:
Howdy,
The php5.cgi script is how PHP scripts are executed. That is running the PHP as CGI or FCGID.
That likely means that there is a malicious PHP script within your website that is being used to attack the other server.
My suggestion would be to review the PHP scripts within that domain to make sure you don't see any that are abnormal.
I would also recommend making sure that any web apps you have installed are fully up to date, as older versions of web apps can contain security vulnerabilities.
-Eric