My shared server account is zombied

Discussion in 'Site & Server Administration' started by Mister Tut, Nov 15, 2005.

  1. #1
    I have a site on a shared server at dreamhost. My email account has been turned into a zombie and is sending out thousands of emails daily. This, charmingly, coincides with a Good Morning America-induced traffic spike of humongous proportions. DreamHost is breathing down my neck pretty badly.

    Can anyone direct me to a source of info on steps I can take to resolve the problem-particularly written for someone who still needs to concentrate real hard just to successfully FTP?

    Thanks in advance fellow DPers!
     
    Mister Tut, Nov 15, 2005 IP
  2. just-4-teens

    just-4-teens Peon

    Messages:
    3,967
    Likes Received:
    168
    Best Answers:
    0
    Trophy Points:
    0
    #2
    first if its a virus sending the mail, disconnect from net and scan your own system and see if the problem is your end, might pay to ask dreamhost to do the same? (some cpanels now have virus checkers in them)

    or, you could always change your email details (password etc)
     
    just-4-teens, Nov 15, 2005 IP
  3. J.D.

    J.D. Peon

    Messages:
    1,198
    Likes Received:
    65
    Best Answers:
    0
    Trophy Points:
    0
    #3
    What kind of shared server is it? Can you upload and run programs on this server?
     
    J.D., Nov 15, 2005 IP
  4. Mister Tut

    Mister Tut Guest

    Messages:
    837
    Likes Received:
    42
    Best Answers:
    0
    Trophy Points:
    0
    #4
    J.D.- Debian Sarge. I can upload and run programs, but I have minimal expertise there. I can upload php and css files just fine, but my host installs my databases and mail app for me.

    Just-4-teens, I am on a mac with NAV, so I think I'm clean. I will look into changing my passwords.

    I have also noticed a script called "stealth" running on my account that is eating up a ton of CPU cycles, but I don't know if that script is something that should be there or not.
     
    Mister Tut, Nov 15, 2005 IP
  5. ozegreatdeals

    ozegreatdeals Peon

    Messages:
    326
    Likes Received:
    12
    Best Answers:
    0
    Trophy Points:
    0
    #5
    One of my websites is sending out alot of emails to all any name it can think of such as , , etc., etc.

    They all contain an attachment which is a virus, I simply delete all emails and run the virus scan provided in cPanel. I have contacted my host for this account as it is not hosted by myself and they said it is a virus which has been around for years and theres nothing you can do about it.

    Drew.
     
    ozegreatdeals, Nov 15, 2005 IP
  6. Mister Tut

    Mister Tut Guest

    Messages:
    837
    Likes Received:
    42
    Best Answers:
    0
    Trophy Points:
    0
    #6
    The emails going out from my site are all hawking an ebook on selling on ebay.
     
    Mister Tut, Nov 16, 2005 IP
  7. just-4-teens

    just-4-teens Peon

    Messages:
    3,967
    Likes Received:
    168
    Best Answers:
    0
    Trophy Points:
    0
    #7
    do you have access to that program "stealth"? download it, if its a virus NAV will pick it up, then ya know if thats the prob or not.
     
    just-4-teens, Nov 16, 2005 IP
  8. aqi32

    aqi32 Active Member

    Messages:
    225
    Likes Received:
    6
    Best Answers:
    0
    Trophy Points:
    58
    #8
    have you pointed out this "stealth" script to the host?

    do you have any form scripts that have been exploited?
     
    aqi32, Nov 16, 2005 IP
  9. J.D.

    J.D. Peon

    Messages:
    1,198
    Likes Received:
    65
    Best Answers:
    0
    Trophy Points:
    0
    #9
    This is the most idiotic and ridiculous response that a hosting company could've possibly come up with. It shows that they completely lost control over their environment and also means that you should switch to some other hosting cmpany whose personnel knows what they are doing.

    J.D.
     
    J.D., Nov 16, 2005 IP
  10. J.D.

    J.D. Peon

    Messages:
    1,198
    Likes Received:
    65
    Best Answers:
    0
    Trophy Points:
    0
    #10
    Run "sudo netstat -antp" to see which ports this stealth script is using.

    Is it a VPS or just a shared server? The reason I'm asking is that you need to figure out how whatever's doing it got on this machine. If you are the only user, then you need to check all your access logs (e.g. somebody may have copied this program over FTP and then launched it over ssh). If you are not, then chances are that your hosting company misconfigured this machine and let the thing in.

    J.D.
     
    J.D., Nov 16, 2005 IP
  11. Mister Tut

    Mister Tut Guest

    Messages:
    837
    Likes Received:
    42
    Best Answers:
    0
    Trophy Points:
    0
    #11
    Mister Tut, Nov 22, 2005 IP
  12. just-4-teens

    just-4-teens Peon

    Messages:
    3,967
    Likes Received:
    168
    Best Answers:
    0
    Trophy Points:
    0
    #12
    glad ya got it sorted :) best of luck
     
    just-4-teens, Nov 22, 2005 IP
  13. swoop

    swoop Active Member

    Messages:
    469
    Likes Received:
    6
    Best Answers:
    0
    Trophy Points:
    90
    #13
    I agree. To say that they cannot remove the malware from their own machine shows ignorance and/or disdain for their customers.
     
    swoop, Nov 23, 2005 IP