当前位置:网站首页>Record Alibaba cloud server mining program processing
Record Alibaba cloud server mining program processing
2022-04-23 12:55:00 【WENHUI012】
Preface
Suddenly, I received a text message from alicloud , Said the server appeared a malicious mining program , Fortunately, there are test servers on this one , I also did data backup before , You can take care of it , But you still have to be careful. Remember to backup it before serious operation
Treatment process
1、 Check the server load against CPU utilization , Determine the progress of the mining process
- Carry out orders :
top
, Pictured : Found a network01 Things occupied by cup Reached 87%, But I'm in the server root tmp I didn't see this thing
- It is confirmed from the above that PID Process number , Check the directory where you're going . Carry out orders , There's no clear location , You can see the executable link
ll /proc/ process ID
- And then directly adopt find / -name network01 Found the following location , When I came to the location directory, I found network01
-
Force to kill the mining process , Delete the mining program executable network01, If you're afraid to delete it wrong, you can back it up ( Leave a regret medicine );
kill -9 1459261
After killing the process ,
top
Command view CPU It's down and back to normal
2、 Check the presence of the miner's address in your server's firewall and remove the malicious address
iptables -L -n
3、 Check whether the port security status is abnormal
netstat -aulntp
Starting to wonder about this IP Of 133.11.244.74 What is it , After inquiry, it is your own public network ip
Check your own public network IP Domestic website :http://ip138.com
4、 Check whether the server's timed tasks have been added by attackers , Processing suspicious timing task files , Prevent a second invasion
crontab -l
And
cat /etc/crontab
5、 Check whether there are suspicious programs in the server startup key to ensure that there is no problem after the server restarts
cd /etc/init.d
cat /etc/rc.d/rc.local
6、 Checked linux Whether the system user is added with other root Level administrator users
cat /etc/passwd # user name : password : User ID : Group identification number : Annotative description : Home directory : Sign in Shell
7、 Check the server root Whether to turn on remote permissions , Servers in the production environment PermitRootLogin
Should be set no
cat /etc/ssh/sshd_config
8、 Check SSH Whether there is a mining virus in the public key , To prevent continuous backdoors
cat /root/.ssh/authorized_keys
9、 The port security policy configured by alicloud server security group , Yes 80 port , as well as 443 Ports open , The rest SSH Port to proceed IP release , When you need to log in to the server, you can add the released ones in the alicloud background IP, Try to prevent the server from being maliciously logged in
10、 Regularly check the server for mining behavior , Check if there is webshell back door , Regular upgrade and bug fix for system version , System background login for secondary password verification , Prevent the existence of the system sql Inject holes . Prevent mining virus from infecting other servers in Intranet repeatedly
You can also refer to Alibaba cloud's mining procedure practice document : https://www.alibabacloud.com/help/zh/doc-detail/161236.htm
Conclusion
This mining procedure has deleted the mining procedure execution document , Forced killing of the mining process , Timing task 、 The startup and other items didn't find anything suspicious , It could be the hacker. OK ...... The general return said that the service security guard must do well to prevent the server malicious attack , Finally, I hope it will be helpful for you to refer to this article !
版权声明
本文为[WENHUI012]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/04/202204230616046528.html
边栏推荐
- Customize the shortcut options in El date picker, and dynamically set the disabled date
- 基于卷积神经网络的遥感影像分类识别系统
- 网站首页文件被攻击篡改的形式有哪些
- Number of nodes of complete binary tree
- Analysis of InnoDB execution process in MySQL
- 标签与路径
- Common problems of unity (1)
- [wechat applet] Z-index is invalid
- ZigBee CC2530 minimum system and register configuration (1)
- 云原生KubeSphere部署Redis
猜你喜欢
CVPR 2022 & ntire 2022 | the first transformer for hyperspectral image reconstruction
Synchronously update the newly added and edited data to the list
标签与路径
CVPR 2022&NTIRE 2022|首个用于高光谱图像重建的 Transformer
云原生KubeSphere部署Mysql
Remote access to raspberry pie at home (Part 1)
Van uploader upload picture implementation process, using native input to upload pictures
Teach you to quickly develop a werewolf killing wechat applet (with source code)
将新增和编辑的数据同步更新到列表
Mysql8 installation
随机推荐
如何实现点击一下物体播放一次动画
Introduction to servlet listener & filter
Aviation core technology sharing | overview of safety characteristics of acm32 MCU
【每日一题】棋盘问题
bert-base-chinese下载(智取)
Deploying MySQL in cloud native kubesphere
mysql8安装
Recommended website for drawing result map
Fashion cloud learning - input attribute summary
Van uploader upload picture implementation process, using native input to upload pictures
Luogu p3236 [hnoi2014] picture frame solution
Customize the shortcut options in El date picker, and dynamically set the disabled date
STM32工程移植:不同型号芯片工程之间的移植:ZE到C8
RT-thread中关键词解释及部分API
After the data of El table is updated, the data in the page is not updated this$ Forceupdate() has no effect
The quill editor image zooms, multiple rich text boxes are used on one page, and the quill editor upload image address is the server address
世界读书日:我想推荐这几本书
Source code analysis of synchronousqueue
21 天学习MongoDB笔记
只是不断地建构平台,不断地收拢流量,并不能够做好产业互联网