部署代码的时候发现服务器cpu占用一直100%,还以为代码有bug给服务器干垮了,结果给服务停了发现cpu还是100%,坏了,这是被搞了,记录一下排查过程
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45
|
vim /etc/rc.d/rc.local
iptables -A INPUT -s 185.196.8.123 -j DROP iptables -A OUTPUT -d 185.196.8.123 -j DROP
vim /etc/rc.d/rc.local
ps -ef | grep logrotate kill -9 5009 rm -rf /root/.config/logrotate
systemctl list-unit-files |grep logrotate.service systemctl disable logrotate.service find / -name logrotate.service rm -rf 上一句文件位置,有多个就删多次
find / -name logrotate.service
lsattr /etc/hosts
chattr -ai /etc/cron.hourly/logrotate; chattr -ai /etc/cron.daily/logrotate; chattr -ai /etc/cron.weekly/logrotate; chattr -ai /etc/cron.monthly/logrotate; chattr -ai /etc/cron.yearly/logrotate; rm -rf /etc/cron.hourly/logrotate; rm -rf /etc/cron.daily/logrotate; rm -rf /etc/cron.weekly/logrotate; rm -rf /etc/cron.monthly/logrotate; rm -rf /etc/cron.yearly/logrotate;
echo $HOME
|
可能是由于一直开着远程调试导致的,JDWP调试接口RCE漏洞介绍
https://forum.butian.net/share/1232
参考文章:
阿里云处理挖矿程序最佳实践:
https://www.alibabacloud.com/help/zh/security-center/use-cases/best-practices-for-handling-mining-programs#section-xgd-9mh-f0e
5月服务器遭遇logrotate病毒的查杀过程:
https://juejin.cn/post/7365933616743219209
记一次服务器被入侵(木马,挖矿)的排查过程:
https://blog.csdn.net/qq32933432/article/details/135408156