Find Jobs
Hire Freelancers

Detect and fix what is this weird PHP process: /usr/local/bin/php -d safe_mode=off -r eval(base54_decode

$10-30 USD

已关闭
已发布超过 8 年前

$10-30 USD

货到付款
Im checking my processes via htop and I noticed a weird process which consumes quite good % of the cpu: Seems to be /usr/local/bin/php -d safe_mode=off -r eval(base64_decode and a huge base64 code string I want to know: 1) What is it? If its a hack or what? 2) How to fix this? 3) How it got there
项目 ID: 8459440

关于此项目

15提案
远程项目
活跃9 年前

想赚点钱吗?

在Freelancer上竞价的好处

设定您的预算和时间范围
为您的工作获得报酬
简要概述您的提案
免费注册和竞标工作
15威客以平均价$41 USD来参与此工作竞价
用户头像
Hello. I would like to help you with php proc identified. I have a lot of experience with linux many years. Thank you.
$30 USD 在1天之内
4.9 (1239条评论)
7.8
7.8
用户头像
It's most likely virus/spamming code, where do you see this process running and can't you stop it? If you give me access to the server I'll try to find from where it gets started
$30 USD 在1天之内
5.0 (81条评论)
7.0
7.0
用户头像
1) What is it? If its a hack or what? Yes 2) How to fix this? Order me 3) How it got there Your server is unsecured ***************************************************************************
$150 USD 在5天之内
4.8 (253条评论)
7.1
7.1
用户头像
I can help you. Do you have root access to your server?. I'm looking forwards to your response. Thank you.
$30 USD 在1天之内
5.0 (184条评论)
6.5
6.5
用户头像
Nie złożono jeszcze oferty.
$55 USD 在3天之内
5.0 (70条评论)
5.2
5.2
用户头像
I will have to look into the server. Can fix in few hours time. Again you will have to provide ssh access to your server for me to be able to finish this job
$55 USD 在1天之内
4.9 (6条评论)
4.8
4.8
用户头像
Hi, I am expert in PHP. Seems you have been hacked. Can you give me base64 code string? Regards, Andrew .
$25 USD 在0天之内
4.8 (29条评论)
4.9
4.9
用户头像
Dear sir, As a pentester and security researcher, I think this is a hack. We can cleary see PHP is started without safe_mode with enables dangerous functions such as shell_exec. The only reason behind encoding with base64 and eval the function is to obfuscate what's running. Can you paste the full base64 string so I reverse it and see what code is beinng eval'ed ? As this is showing in htop, it seem to be a really low skilled hacker as someone skilled would have hidden this from the process list. But maybe he's working on making it stealth right now so you should really not wait and speed up before something bad happens. It might be a cryptoPHP infection. Please paste me the base64 string this is the most important and it's missing from your description, but this is is clearly a hack. You should kill this process and make a crontab if it runs automatically again. Please PM, I would really like to find out what it is and identify what strain of malware lies behind this base64 string. You might be part of a DDOS or spam botnet. I hope for you it's not some kind of crypotPHP infection. Make sure you have backups of all your files and DONT delete them, it surely started to infect other scripts and a backdoor might have already been put on your server in case you find out this (which you did). You must find out what was done ASAP. Regards,
$30 USD 在3天之内
5.0 (39条评论)
4.6
4.6
用户头像
From how you've described it, this is potentially malicious code that has made its way onto your server via yourself or some outside party. I can figure out exactly what this code is doing and take the proper direction from there on what to do.
$25 USD 在1天之内
4.9 (25条评论)
4.2
4.2
用户头像
A proposal has not yet been provided
$35 USD 在1天之内
5.0 (9条评论)
3.6
3.6
用户头像
I can find the base64 that is being executed in PHP and decode it to find exactly what is happening. I am free to start immediately.
$25 USD 在0天之内
5.0 (19条评论)
3.5
3.5
用户头像
It's certainly a hacked process. It is running some php commands which is encoded in base64 so that you don't know what task is done by it. But i think you understand what it means? (illegal)
$55 USD 在1天之内
4.9 (14条评论)
3.3
3.3
用户头像
Dear Sir/Madam, please let me introduce myself briefly. Fifteen years dealing with information technology, I am mostly familiar with fields of web development and system and network operations. Based on your description this is definitely a hack. I work with PHP and webservers on a daily basis, so I can easily check your server for security issues. I can change your settings so no more harmful code will be executed. As I'm new here, please give me a chance to get some good ratings, it'd really help me get other jobs. :) Having any questions please don't hesitate to contact me, I'll be glad to answer them. I'm looking forward to work with you. Kind regards, Robert.
$10 USD 在1天之内
4.0 (1条评论)
1.5
1.5

关于客户

MEXICO的国旗
Durango, Mexico
5.0
116
会员自8月 14, 2009起

客户认证

谢谢!我们已通过电子邮件向您发送了索取免费积分的链接。
发送电子邮件时出现问题。请再试一次。
已注册用户 发布工作总数
Freelancer ® is a registered Trademark of Freelancer Technology Pty Limited (ACN 142 189 759)
Copyright © 2024 Freelancer Technology Pty Limited (ACN 142 189 759)
加载预览
授予地理位置权限。
您的登录会话已过期而且您已经登出,请再次登录。