Sponsor:

Server and Web Integrator
Link:
Kloxo-MR logo
6.5.0 or 7.0.0
Click for "How to install"
Donation/Sponsorship:
Kloxo-MR is open-source.
Donate and or Sponsorship always welcome.
Click to:
Click Here
Please login or register. 2024-05-18, 01:12:50

Author Topic: unknown_html_RFI_php, mohon bantuannya?  (Read 5771 times)

0 Members and 1 Guest are viewing this topic.

Offline riomukti21

  • Junior Member
  • *
  • Posts: 5
  • Karma: +0/-0
    • View Profile
unknown_html_RFI_php, mohon bantuannya?
« on: 2015-03-28, 16:46:02 »
Selamat malam pak, saya bener-bener belum pernah menjumpai yang seperti ini. Jadi ceritanya saya tiba-tiba dapat email dari Digital Ocean yang isinya sebagai berikut:

Please review the following abuse complaint and provide us with a resolution:

******************************
Dear abuse team,

please have a look on these perhaps offending viruses sites(1) so far.

Notice: We do NOT urge you to shutdown your customer, but to inform him about a possible infection/misbehavior !

status: As of 2015-03-28 13:29:25 CET

Please preserve on any reply our Subject: [clean-mx-viruses-62792394](104.131.26.87)-->(abuse@digitalocean.com) viruses sites (1 so far) within your network, please close them! status: As of 2015-03-28 13:29:25 CET

http://support.clean-mx.de/clean-mx/viruses.php?email=abuse@digitalocean.com&response=alive

(for full uri, please scroll to the right end ...

This information has been generated out of our comprehensive real time database, tracking worldwide viruses URI's

If your review this list of offending site(s), please do this carefully, pay attention for redirects also!
Also, please consider this particular machines may have a root kit installed !
So simply deleting some files or dirs or disabling cgi may not really solve the issue !

Advice: The appearance of a Virus Site on a server means that
someone intruded into the system. The server's owner should
disconnect and not return the system into service until an
audit is performed to ensure no data was lost, that all OS and
internet software is up to date with the latest security fixes,
and that any backdoors and other exploits left by the intruders
are closed. Logs should be preserved and analyzed and, perhaps,
the appropriate law enforcement agencies notified.

DO NOT JUST DELETE THE FILES. IF YOU DO NOT FIX THE SECURITY
PROBLEM, THEY WILL BE BACK!

You may forward my information to law enforcement, CERTs,
other responsible admins, or similar agencies.

+-----------------------------------------------------------------------------------------------

|date   |id   |virusname   |ip   |domain   |Url|
+-----------------------------------------------------------------------------------------------

+-----------------------------------------------------------------------------------------------

Your email address has been pulled out of whois concerning this offending network block(s).
If you are not concerned with anti-fraud measurements, please forward this mail to the next responsible desk available...

If you just close(d) these incident(s) please give us a feedback, our automatic walker process may not detect a closed case

explanation of virusnames:
==========================
unknown_html_RFI_php   not yet detected by scanners as RFI, but pure php code for injection
unknown_html_RFI_perl   not yet detected by scanners as RFI, but pure perl code for injection
unknown_html_RFI_eval   not yet detected by scanners as RFI, but suspect javascript obfuscationg evals
unknown_html_RFI   not yet detected by scanners as RFI, but trapped by our honeypots as remote-code-injection
unknown_html   not yet detected by scanners as RFI, but suspious, may be in rare case false positive
unknown_exe   not yet detected by scanners as malware, but high risk!
all other names   malwarename detected by scanners
==========================

yours

Gerhard W. Recher
(CTO)

net4sec UG (haftungsbeschraenkt)

Leitenweg 6
D-86929 Penzing

GSM: ++49 171 4802507

Geschaeftsfuehrer: Martina Recher
Handelsregister Augsburg: HRB 27139
EG-Identnr: DE283762194

w3: http://www.clean-mx.de
e-Mail: mailto:abuse@clean-mx.de
PGP-KEY: Fingerprint: A4E317B6DC6494DCC9616366A75AB34CDD0CE552 id: 0xDD0CE552
Location: http://www.clean-mx.de/downloads/abuse-at-clean-mx.de.pub.asc

******************************

Please note that generating multiple abuse complaints in a short period of time may lead to your account being suspended.

Jujur saya bingung dan belum pernah mengalami ini sebelumnya sejak pertama menggunakan kloxo. Mohon bantuannya pak. Terima kasih.

Offline MRatWork

  • Administrator
  • The Elite
  • *****
  • Posts: 15,807
  • Karma: +119/-11
  • Gender: Male
    • View Profile
    • MRatWork Forum
Re: unknown_html_RFI_php, mohon bantuannya?
« Reply #1 on: 2015-03-28, 17:06:33 »
Anda pakai Kloxo atau Kloxo-MR?. Kloxo-MR ada solusi untuk tangani masalah seperti ini (ada website yang kirim spam).

Infokan saja 'sh /script/sysinfo'.
..:: MRatWork (Mustafa Ramadhan Projects) ::..
-- Server/Web-integrator - Web Hosting (Kloxo-MR READY!) --

Offline riomukti21

  • Junior Member
  • *
  • Posts: 5
  • Karma: +0/-0
    • View Profile
Re: unknown_html_RFI_php, mohon bantuannya?
« Reply #2 on: 2015-03-28, 23:55:29 »
Selamat pagi pak Mus, maaf baru pagi ini saya balas sysinfonya. Berikut pak,,,

A. Kloxo-MR: 7.0.0.b-2014110701

B. OS: CentOS release 6.6 (Final) i686

C. Apps:
   1. MySQL: mysql55-5.5.40-1.ius.el6.i686
   2. PHP: php53u-5.3.29-1.ius.el6.i686
   3. Httpd: httpd-2.2.29-1.mr.el6.i386
   4. Lighttpd: --uninstalled--
   5. Hiawatha: hiawatha-9.8.0-f.2.mr.el6.i386
   6. Nginx: nginx-1.7.7-1.el6.ngx.i386
   7. Cache: --uninstalled--
   8. Dns: bind-9.9.5-1.el6.i686
   9. Qmail: qmail-toaster-1.03-1.3.38.mr.el6.i386
      - with: courier-imap-toaster-4.1.2-1.3.16.mr.el6.i386

D. Php-type (for Httpd/proxy): php-fpm_event

E. Memory:
                total       used       free     shared    buffers     cached
   Mem:          1006        917         88          2         86        458
   -/+ buffers/cache:        372        634
   Swap:            0          0          0

Offline MRatWork

  • Administrator
  • The Elite
  • *****
  • Posts: 15,807
  • Karma: +119/-11
  • Gender: Male
    • View Profile
    • MRatWork Forum
Re: unknown_html_RFI_php, mohon bantuannya?
« Reply #3 on: 2015-03-29, 00:34:11 »
COba periksa dengan 'cat /var/log/maillog|grep sendmail'. Apa yang paling sering. Jika jumlah tidak wajar maka kemungkin bagian ini (PWD) yang melakukan spam.
..:: MRatWork (Mustafa Ramadhan Projects) ::..
-- Server/Web-integrator - Web Hosting (Kloxo-MR READY!) --

Offline riomukti21

  • Junior Member
  • *
  • Posts: 5
  • Karma: +0/-0
    • View Profile
Re: unknown_html_RFI_php, mohon bantuannya?
« Reply #4 on: 2015-03-29, 00:46:13 »
Sudah coba saya cek pak menggunakan perintah "cat /var/log/maillog|grep sendmail" tapi kok keluarnya No such file or directory ya pak? Maaf itu ngeceknya bener menggunakan putty?

Offline MRatWork

  • Administrator
  • The Elite
  • *****
  • Posts: 15,807
  • Karma: +119/-11
  • Gender: Male
    • View Profile
    • MRatWork Forum
Re: unknown_html_RFI_php, mohon bantuannya?
« Reply #5 on: 2015-03-29, 01:02:30 »
Sudah coba saya cek pak menggunakan perintah "cat /var/log/maillog|grep sendmail" tapi kok keluarnya No such file or directory ya pak? Maaf itu ngeceknya bener menggunakan putty?
Coba perlihatkan 'dir -l /var/log/maillog*'
..:: MRatWork (Mustafa Ramadhan Projects) ::..
-- Server/Web-integrator - Web Hosting (Kloxo-MR READY!) --

Offline riomukti21

  • Junior Member
  • *
  • Posts: 5
  • Karma: +0/-0
    • View Profile
Re: unknown_html_RFI_php, mohon bantuannya?
« Reply #6 on: 2015-03-29, 03:09:50 »
"dir: cannot access /var/log/maillog*: No such file or directory" munculnya begini pak?
« Last Edit: 2015-03-29, 03:11:42 by riomukti21 »

Offline MRatWork

  • Administrator
  • The Elite
  • *****
  • Posts: 15,807
  • Karma: +119/-11
  • Gender: Male
    • View Profile
    • MRatWork Forum
Re: unknown_html_RFI_php, mohon bantuannya?
« Reply #7 on: 2015-03-29, 03:22:34 »
Wah. Coba 'dir -l /var/log'.
..:: MRatWork (Mustafa Ramadhan Projects) ::..
-- Server/Web-integrator - Web Hosting (Kloxo-MR READY!) --

Offline riomukti21

  • Junior Member
  • *
  • Posts: 5
  • Karma: +0/-0
    • View Profile
Re: unknown_html_RFI_php, mohon bantuannya?
« Reply #8 on: 2015-03-29, 03:34:36 »
total 319796
drwxr-x---  2 root   root        4096 Mar 27 18:50 audit
-rw-------  1 root   utmp   214945152 Mar 28 21:21 btmp
-rw-------  1 root   root      160362 Mar 28 21:01 cron
drwxr-xr-x  2 root   root        4096 Oct 10 23:10 hiawatha
drwxr-xr-x  3 root   root        4096 Mar 22 03:40 httpd
-rw-------  1 root   root     3600435 Mar 28 20:31 messages
drwxrwxrwx  2 root   root        4096 Mar 26 22:12 named
drwxr-xr-x  2 root   root        4096 Mar 28 03:42 nginx
-rw-r--r--  1 root   root     6756577 Mar 28 21:34 php53s-error.log
drwxrwx---  2 apache apache      4096 Mar 22 03:40 php-fpm
-rw-------  1 root   root           0 Mar 24 13:25 pureftpd.log
drwxr-x--- 11 qmaill qmail       4096 Oct 10 23:05 qmail
drwxr-xr-x  2 root   root        4096 Mar 22 03:40 rkhunter
-rw-------  1 root   root   101728531 Mar 28 21:21 secure
-rw-------  1 root   root           0 Mar 28 18:53 yum.log

 


Top 10 Social Networking:    Facebook    Twitter    LinkedIn    Pinterest    Google Plus    Tumblr    Instagram    VK    Flickr    Vine
Click Here

Page created in 0.082 seconds with 22 queries.

web stats analysis