А я смотрю это свежачёк))) прочитал ваши посты и сопоставил со своими исследованими логов FreeBsd и циски))
Короче так)))
сначало в логах и еррорах Апатча появляется
62.149.226.66 - - [12/Dec/2010:01:42:35 +0000] "GET /doesnotexist.hax HTTP/1.1" 404 214 "-" "crimscan/1.2"
184.168.117.234 - - [12/Dec/2010:01:53:40 +0000] "GET /doesnotexist.hax HTTP/1.1" 404 214 "-" "crimscan/1.2"
[Sun Dec 12 01:42:35 2010] [error] [client 62.149.226.66] File does not exist: /usr/home/illusion/public_html/doesnotexist.hax
[Sun Dec 12 01:53:40 2010] [error] [client 184.168.117.234] File does not exist: /usr/home/illusion/public_html/doesnotexist.hax
затем через несколько сикунд в ETC создаются эти странные файлы:
-rwxrwxrwx 1 root wheel 23267 Dec 12 01:54 hyfrsywhowagmhg
-rwxrwxrwx 1 root wheel 23267 Dec 12 01:54 oaayusejjghapdr
-rwxrwxrwx 1 root wheel 23267 Dec 12 01:43 odckuxcuudcsfng
-rwxrwxrwx 1 root wheel 23267 Dec 12 01:43 uuvsnjutntkdjul
Потом валится proftp (я его кстати тоже впервую очередь завалил чтобы больше он не валился:) ) со словами:
Dec 12 01:42:38 spider
proftpd[98750]: spider (host66-226-149-62.serverdedicati.aruba.it[::ffff:62.149.226.66]) -
ProFTPD terminating (signal 11)
Dec 12 01:42:42 spider
proftpd[98751]: spider (host66-226-149-62.serverdedicati.aruba.it[::ffff:62.149.226.66]) -
ProFTPD terminating (signal 11)
Dec 12 01:42:45 spider
proftpd[98752]: spider (host66-226-149-62.serverdedicati.aruba.it[::ffff:62.149.226.66]) -
ProFTPD terminating (signal 11)
Dec 12 01:42:48 spider
proftpd[98753]: spider (host66-226-149-62.serverdedicati.aruba.it[::ffff:62.149.226.66]) -
ProFTPD terminating (signal 11)
Dec 12 01:42:51 spider
proftpd[98755]: spider (host66-226-149-62.serverdedicati.aruba.it[::ffff:62.149.226.66]) -
ProFTPD terminating (signal 11)
Dec 12 01:43:13 spider
proftpd[98756]: spider (host66-226-149-62.serverdedicati.aruba.it[::ffff:62.149.226.66]) -
ProFTPD terminating (signal 11)
Dec 12 01:43:16 spider
proftpd[98757]: spider (host66-226-149-62.serverdedicati.aruba.it[::ffff:62.149.226.66]) -
ProFTPD terminating (signal 11)
Dec 12 01:43:19 spider
proftpd[98758]: spider (host66-226-149-62.serverdedicati.aruba.it[::ffff:62.149.226.66]) -
ProFTPD terminating (signal 11)
Dec 12 01:43:22 spider
proftpd[98759]: spider (host66-226-149-62.serverdedicati.aruba.it[::ffff:62.149.226.66]) -
ProFTPD terminating (signal 11)
Dec 12 01:43:22 spider
proftpd[98759]: spider (host66-226-149-62.serverdedicati.aruba.it[::ffff:62.149.226.66]) -
ProFTPD terminating (signal 11)
Dec 12 01:43:26 spider
proftpd[98760]: spider (host66-226-149-62.serverdedicati.aruba.it[::ffff:62.149.226.66]) -
ProFTPD terminating (signal 11)
Dec 12 01:43:29 spider
proftpd[98761]: spider (host66-226-149-62.serverdedicati.aruba.it[::ffff:62.149.226.66]) -
ProFTPD terminating (signal 11)
Dec 12 01:43:32 spider
proftpd[98762]: spider (host66-226-149-62.serverdedicati.aruba.it[::ffff:62.149.226.66]) -
ProFTPD terminating (signal 11)
Dec 12 01:43:36 spider
proftpd[98763]: spider (host66-226-149-62.serverdedicati.aruba.it[::ffff:62.149.226.66]) -
ProFTPD terminating (signal 11)
Dec 12 01:43:45 spider
proftpd[98792]: spider (host66-226-149-62.serverdedicati.aruba.it[::ffff:62.149.226.66]) -
ProFTPD terminating (signal 11)
Dec 12 01:43:49 spider
proftpd[98817]: spider (host66-226-149-62.serverdedicati.aruba.it[::ffff:62.149.226.66]) -
ProFTPD terminating (signal 11)
Dec 12 01:43:52 spider
proftpd[98818]: spider (host66-226-149-62.serverdedicati.aruba.it[::ffff:62.149.226.66]) -
ProFTPD terminating (signal 11)
Dec 12 01:43:55 spider
proftpd[98819]: spider (host66-226-149-62.serverdedicati.aruba.it[::ffff:62.149.226.66]) -
ProFTPD terminating (signal 11)
Dec 12 01:43:58 spider
proftpd[98820]: spider (host66-226-149-62.serverdedicati.aruba.it[::ffff:62.149.226.66]) -
ProFTPD terminating (signal 11)
Dec 12 01:44:05 spider
proftpd[98822]: spider (host66-226-149-62.serverdedicati.aruba.it[::ffff:62.149.226.66]) -
ProFTPD terminating (signal 11)
Dec 12 01:44:08 spider
proftpd[98954]: spider (host66-226-149-62.serverdedicati.aruba.it[::ffff:62.149.226.66]) -
ProFTPD terminating (signal 11)
Dec 12 01:44:15 spider
proftpd[98955]: spider (host66-226-149-62.serverdedicati.aruba.it[::ffff:62.149.226.66]) -
ProFTPD terminating (signal 11)
Dec 12 01:44:18 spider
proftpd[98956]: spider (host66-226-149-62.serverdedicati.aruba.it[::ffff:62.149.226.66]) -
ProFTPD terminating (signal 11)
Dec 12 01:44:21 spider
proftpd[98957]: spider (host66-226-149-62.serverdedicati.aruba.it[::ffff:62.149.226.66]) -
ProFTPD terminating (signal 11)
Dec 12 01:44:31 spider
proftpd[98958]: spider (host66-226-149-62.serverdedicati.aruba.it[::ffff:62.149.226.66]) -
ProFTPD terminating (signal 11)
Dec 12 01:44:34 spider
proftpd[98959]: spider (host66-226-149-62.serverdedicati.aruba.it[::ffff:62.149.226.66]) -
ProFTPD terminating (signal 11)
Dec 12 01:44:37 spider
proftpd[98960]: spider (host66-226-149-62.serverdedicati.aruba.it[::ffff:62.149.226.66]) -
ProFTPD terminating (signal 11)
Dec 12 01:44:44 spider
proftpd[98961]: spider (host66-226-149-62.serverdedicati.aruba.it[::ffff:62.149.226.66]) -
ProFTPD terminating (signal 11)
Dec 12 01:44:47 spider
proftpd[98962]: spider (host66-226-149-62.serverdedicati.aruba.it[::ffff:62.149.226.66]) -
ProFTPD terminating (signal 11)
Dec 12 01:44:50 spider
proftpd[98963]: spider (host66-226-149-62.serverdedicati.aruba.it[::ffff:62.149.226.66]) -
ProFTPD terminating (signal 11)
Dec 12 01:44:57 spider
proftpd[98964]: spider (host66-226-149-62.serverdedicati.aruba.it[::ffff:62.149.226.66]) -
ProFTPD terminating (signal 11)
Dec 12 01:53:41 spider
proftpd[99164]: spider (ip-184-168-117-234.ip.secureserver.net[::ffff:184.168.117.234]) -
ProFTPD terminating (signal 11)
Dec 12 01:53:45 spider
proftpd[99165]: spider (ip-184-168-117-234.ip.secureserver.net[::ffff:184.168.117.234]) -
ProFTPD terminating (signal 11)
Dec 12 01:53:51 spider
proftpd[99166]: spider (ip-184-168-117-234.ip.secureserver.net[::ffff:184.168.117.234]) -
ProFTPD terminating (signal 11)
Dec 12 01:53:55 spider
proftpd[99167]: spider (ip-184-168-117-234.ip.secureserver.net[::ffff:184.168.117.234]) -
ProFTPD terminating (signal 11)
Dec 12 01:53:58 spider
proftpd[99168]: spider (ip-184-168-117-234.ip.secureserver.net[::ffff:184.168.117.234]) -
ProFTPD terminating (signal 11)
Dec 12 01:54:01 spider
proftpd[99169]: spider (ip-184-168-117-234.ip.secureserver.net[::ffff:184.168.117.234]) -
ProFTPD terminating (signal 11)
Dec 12 01:54:08 spider
proftpd[99223]: spider (ip-184-168-117-234.ip.secureserver.net[::ffff:184.168.117.234]) -
ProFTPD terminating (signal 11)
Dec 12 01:54:11 spider
proftpd[99289]: spider (ip-184-168-117-234.ip.secureserver.net[::ffff:184.168.117.234]) -
ProFTPD terminating (signal 11)
Dec 12 01:54:15 spider
proftpd[99290]: spider (ip-184-168-117-234.ip.secureserver.net[::ffff:184.168.117.234]) -
ProFTPD terminating (signal 11)
Dec 12 01:54:15 spider
proftpd[99290]: spider (ip-184-168-117-234.ip.secureserver.net[::ffff:184.168.117.234]) -
ProFTPD terminating (signal 11)
Dec 12 01:54:21 spider
proftpd[99291]: spider (ip-184-168-117-234.ip.secureserver.net[::ffff:184.168.117.234]) -
ProFTPD terminating (signal 11)
Dec 12 01:54:31 spider
proftpd[99292]: spider (ip-184-168-117-234.ip.secureserver.net[::ffff:184.168.117.234]) -
ProFTPD terminating (signal 11)
Dec 12 01:54:41 spider
proftpd[99294]: spider (ip-184-168-117-234.ip.secureserver.net[::ffff:184.168.117.234]) -
ProFTPD terminating (signal 11)
Dec 12 01:54:44 spider
proftpd[99295]: spider (ip-184-168-117-234.ip.secureserver.net[::ffff:184.168.117.234]) -
ProFTPD terminating (signal 11)
Dec 12 01:55:04 spider
proftpd[99324]: spider (ip-184-168-117-234.ip.secureserver.net[::ffff:184.168.117.234]) -
ProFTPD terminating (signal 11)
Dec 12 01:55:08 spider
proftpd[99383]: spider (ip-184-168-117-234.ip.secureserver.net[::ffff:184.168.117.234]) -
ProFTPD terminating (signal 11)
Dec 12 01:55:14 spider
proftpd[99384]: spider (ip-184-168-117-234.ip.secureserver.net[::ffff:184.168.117.234]) -
ProFTPD terminating (signal 11)
Dec 12 01:55:18 spider
proftpd[99385]: spider (ip-184-168-117-234.ip.secureserver.net[::ffff:184.168.117.234]) -
ProFTPD terminating (signal 11)
Dec 12 01:55:24 spider
proftpd[99386]: spider (ip-184-168-117-234.ip.secureserver.net[::ffff:184.168.117.234]) -
ProFTPD terminating (signal 11)
Dec 12 01:55:28 spider
proftpd[99387]: spider (ip-184-168-117-234.ip.secureserver.net[::ffff:184.168.117.234]) -
ProFTPD terminating (signal 11)
Dec 12 01:55:34 spider
proftpd[99388]: spider (ip-184-168-117-234.ip.secureserver.net[::ffff:184.168.117.234]) -
ProFTPD terminating (signal 11)
Dec 12 01:55:38 spider
proftpd[99389]: spider (ip-184-168-117-234.ip.secureserver.net[::ffff:184.168.117.234]) -
ProFTPD terminating (signal 11)
Dec 12 01:55:44 spider
proftpd[99391]: spider (ip-184-168-117-234.ip.secureserver.net[::ffff:184.168.117.234]) -
ProFTPD terminating (signal 11)
Dec 12 01:55:48 spider
proftpd[99392]: spider (ip-184-168-117-234.ip.secureserver.net[::ffff:184.168.117.234]) -
ProFTPD terminating (signal 11)
Dec 12 01:55:54 spider
proftpd[99393]: spider (ip-184-168-117-234.ip.secureserver.net[::ffff:184.168.117.234]) -
ProFTPD terminating (signal 11)
Dec 12 01:55:58 spider
proftpd[99394]: spider (ip-184-168-117-234.ip.secureserver.net[::ffff:184.168.117.234]) -
ProFTPD terminating (signal 11)
Dec 12 01:56:04 spider
proftpd[99395]: spider (ip-184-168-117-234.ip.secureserver.net[::ffff:184.168.117.234]) -
ProFTPD terminating (signal 11)
Dec 12 01:56:08 spider
proftpd[99396]: spider (ip-184-168-117-234.ip.secureserver.net[::ffff:184.168.117.234]) -
ProFTPD terminating (signal 11)
Dec 12 01:56:14 spider
proftpd[99397]: spider (ip-184-168-117-234.ip.secureserver.net[::ffff:184.168.117.234]) -
ProFTPD terminating (signal 11)
Dec 12 01:56:18 spider
proftpd[99398]: spider (ip-184-168-117-234.ip.secureserver.net[::ffff:184.168.117.234]) -
ProFTPD terminating (signal 11)
Dec 12 01:56:24 spider
proftpd[99399]: spider (ip-184-168-117-234.ip.secureserver.net[::ffff:184.168.117.234]) -
ProFTPD terminating (signal 11)
Dec 12 02:27:54 spider
proftpd[713]: spider -
ProFTPD killed (signal 15)
Dec 12 02:27:54 spider
proftpd[713]: spider -
ProFTPD 1.3.2 standalone mode SHUTDOWN
потом значит происходит следущее! эти файлики слушают 21 порт(вместо proFTP)
sockstat | grep 21
root oaayusejjg 99348 0 tcp4 192.168.111.100:21 184.168.117.234:48814
root hyfrsywhow 99322 0 tcp4 192.168.111.100:21 184.168.117.234:36683
root uuvsnjutnt 98816 0 tcp4 192.168.111.100:21 62.149.226.66:37237
root odckuxcuud 98790 0 tcp4 192.168.111.100:21 62.149.226.66:58649
и по очереди коннектят на хост 184.171.166.162:40808
root hyfrsywhow 99322 2 tcp4 192.168.111.100:61389 184.171.166.162:40808
*Dec 12 12:00:29.746: %SEC-6-IPACCESSLOGP: list Vlan192_In denied tcp 192.168.111.100(49788) -> 184.171.166.162(40808), 1 packet
*Dec 12 12:00:32.130: %SEC-6-IPACCESSLOGP: list Vlan192_In denied tcp 192.168.111.100(58016) -> 184.171.166.162(40808), 1 packet
*Dec 12 12:00:34.746: %SEC-6-IPACCESSLOGP: list Vlan192_In denied tcp 192.168.111.100(60996) -> 184.171.166.162(40808), 1 packet
*Dec 12 12:00:37.130: %SEC-6-IPACCESSLOGP: list Vlan192_In denied tcp 192.168.111.100(60749) -> 184.171.166.162(40808), 1 packet
*Dec 12 12:00:39.746: %SEC-6-IPACCESSLOGP: list Vlan192_In denied tcp 192.168.111.100(56784) -> 184.171.166.162(40808), 1 packet
*Dec 12 12:00:42.130: %SEC-6-IPACCESSLOGP: list Vlan192_In denied tcp 192.168.111.100(57868) -> 184.171.166.162(40808), 1 packet
*Dec 12 12:00:44.746: %SEC-6-IPACCESSLOGP: list Vlan192_In denied tcp 192.168.111.100(51558) -> 184.171.166.162(40808), 1 packet
*Dec 12 12:00:47.130: %SEC-6-IPACCESSLOGP: list Vlan192_In denied tcp 192.168.111.100(62296) -> 184.171.166.162(40808), 1 packet
Кстати можно попробовать самим телнеткнуться туда и там действительно что то отвечает(
В обще вот так!!! перекрыл вчера на циске все исходящие соединения а после того как всё повторилось сегодня вырубил proftp! сталось вырубить Апатч и вырубить серв)))
FreeBSD spider.liannet.ru 7.2-RELEASE FreeBSD 7.2-RELEASE #0: Tue Dec 29 16:40:15 UTC 2009
sid@spider.liannet.ru:/usr/obj/usr/src/sys/SPIDER i386
ProFTP 1.3.2
apache-2.2.14_5