/srv/irclogs.ubuntu.com/2013/12/31/#ubuntu-server.txt

TJ-knoxy: pastebin the output of "env"00:01
knoxyLD_PRELOAD=/lib/lib__mdma.so.100:02
knoxyI just need to remove the entries from grub... I can remove the files *3.8.0* from /boot and run update-grub ?00:03
markthomasstetho: I just did this successfully: rsync -v rsync://us.archive.ubuntu.com/ubuntu/pool/main/g/gdb/gdb_7.4-2012.04.orig.tar.bz2 .00:03
TJ-knoxy: Have you recently edited a bashrc script, either /etc/profile or /root/.bashrc or similar? Because that error is usually caused by having a bash variable definition that has spaces either side of the "="00:03
knoxy# some more ls aliases00:04
knoxyalias ll='ls -alF'00:04
knoxyalias la='ls -A'00:04
knoxyalias l='ls -CF'00:04
knoxy?00:04
knoxyno00:04
TJ-knoxy: show us a pastebin of "env" please00:05
knoxyhttp://paste.ubuntu.com/6665794/00:10
markthomasknoxy: looking...00:18
TJ-knoxy: What is this "lib__mdma.so.1" ? Is it a custom library you've built?00:19
knoxyTJ-, no, this is a "unknown" library00:26
knoxyif I move this library to another folder, for example, all commands stops (ls, pwd, ps, and more)00:26
knoxywhen I move this file to another folder, I can restore the machine using SCP to move from target folder to previous folder...00:27
knoxybecause all commands (includes mv) stop to work00:28
knoxyI dont know what is lib__mdma.so.100:29
knoxywhen I run "ls" in /lib... I can't see this file00:29
knoxywhen I run ls -l, so I see this file00:30
TJ-knoxy: I can't find any references to it on the 'net ... I suspect it could be part of a rootkit00:30
knoxydu -sh /lib/lib__mdma.so.1 - access denied00:30
knoxyTJ- I talked several times about this file here00:31
knoxyTJ- no one could tell me what is00:32
knoxyTJ- I already suspected it was part of a rootkit00:32
knoxyTJ- to disable this file, I can disable from "env" variables?00:32
TJ-knoxy: Seriously, you need to rebuild that machine and secure it! make sure no other systems are re-infecting it, ensure your local PC isn't part of the problem00:32
TJ-knoxy: I would guess if it is a root-kit that other files have been compromised. You need to do a clean rebuild.00:33
knoxyTJ- I checked all process, users, folders, rkhunter runs, and I cant see the rootkit and other similar problem00:33
knoxyTJ- Yes, this server will be reinstalled, but all files (my php application) need to be migrated00:34
TJ-Can you do "objdump -t /lib/lib__mdma.so.1" and show the output to us via a pastebin?00:35
knoxyTJ- yes, but the datacenter is migrating this server to another rack, please wait00:36
knoxyI'm waiting the reply00:36
knoxyTJ- on my Zimbra ZCS server (ubuntu) in this week, I find 3 files in /var/tmp00:38
knoxyTJ- because a 0day remote exploit for Zimbra has published00:39
knoxyI remove the files and block the 7071 port for Zimbra Admin00:39
=== gfrog_afk is now known as gfrog
knoxythe files:00:40
knoxyroot@srv001:~/exploits# ls00:40
knoxymeep.pl  minerd32  minerd6400:40
knoxyanyone knows these files?00:40
=== gfrog_afk is now known as gfrog
knoxy?00:41
knoxyminerd64 and minerd32 is used for bitcoin?!00:44
bekksknoxy: Someone is using your server for bitcoin mining.00:44
knoxybekks, this files I found in my Zimbra ZCS server01:00
knoxybekks, the url for 0day exploit is http://www.exploit-db.com/exploits/30085/01:00
knoxybekks, I dont know if the server is used to more things01:01
bekksknoxy: Yeah. Someone is exploiting your server. Backup important data, reinstall your server from scratch.01:01
knoxybekks, I've other servers and will find other exploits and dangerous files01:02
bekksOr get the datacenter guys to investigate further, for jurisdical actions.01:02
knoxybekks, my contract is restrict just to use the infra of DC01:02
knoxybekks, datacenter guys dont have access to my servers01:03
=== gfrog is now known as gfrog_afk
=== TDog_ is now known as TDog
=== gfrog_afk is now known as gfrog
=== gfrog is now known as gfrog_afk
=== TDog_ is now known as TDog
=== gfrog_afk is now known as gfrog
=== aarcane_ is now known as aarcane
aarcaneDoes anybody know how to force DKMS to rebuild a module it says is already built?06:42
Neytirithis is sort of a odd question, but how woud i use box A as ddos protection for box B.  both boxes are on the public internet but on different subnets and different datacenters06:48
=== TDog_ is now known as TDog
=== TDog_ is now known as TDog
=== TDog_ is now known as TDog
=== TDog_ is now known as TDog
=== TDog_ is now known as TDog
=== TDog_ is now known as TDog
=== TDog_ is now known as TDog
=== TDog_ is now known as TDog
=== TDog_ is now known as TDog
=== TDog_ is now known as TDog
=== TDog_ is now known as TDog
=== TDog_ is now known as TDog
=== railsraider_ is now known as railsraider
=== TDog_ is now known as TDog
=== TDog_ is now known as TDog
=== TDog_ is now known as TDog
stethoDoes anyone know if ubuntu servers rate limit you or block you in other ways?10:37
=== Jare_ is now known as Jare
=== lionel_ is now known as lionel
=== TDog_ is now known as TDog
=== TDog_ is now known as TDog
balachmarHi, I am looking for some documentation how to set up a multisite config for drupal using the ubuntu packages15:19
=== TDog_ is now known as TDog
=== njbair_ is now known as njbair
=== TDog_ is now known as TDog
=== TDog_ is now known as TDog
=== TDog_ is now known as TDog
=== Beltechs is now known as OjO
markthomasstetho: I don't believe there is any kind of rate limit.  Large Ubuntu clouds mirror the mirrors just as you are attempting to do.17:38
aarcaneon ubuntu 12.04.3 with kernel 3.5.0-43-generic and openvswitch (A setup I have working on two other systems at present)  I get the following error when starting a guest in libvirt:18:23
aarcaneUnable to add bridge br0 port vnet0: No such process18:23
aarcaneGoogle provides no helpful results, and I'm unable to glean anything from the logs.18:23
TJ-aarcane: See https://access.redhat.com/site/documentation/en-US/Red_Hat_Enterprise_Linux/6/html-single/Virtualization_Host_Configuration_and_Guest_Installation_Guide/#App_Bridge_Device18:39
aarcaneTJ-, that's a similar error, but I've found that possible resolution before, and it's not a fruitful path to peruse.18:44
TJ-aarcane: Permissions of the user are sufficient? "No such process" error can show when elevated permissions aren't available19:02
boldfieldI'm having some issues with dhcpd I was hoping someone could help me with.  I've got a host defined in dhcpd.conf setting a fixed-address, but the client is never assigned the correct IP.  I've triple checked the MAC address and tried clearing the client's leases and removing the relevant entries in server's leases19:23
boldfieldanyone have any ideas of other things I might try to troubleshoot19:23
bekksThe client still has a lease file.19:24
boldfieldI've tried killing the client and clearing the lease files19:28
boldfieldthe host just gets a lease on another dynamically assigned IP, not the static one the server is configured to give19:29
boldfieldor... supposedly configured to give, though I can't spot the error in the config, and I've spent a while looking19:29
=== Sneak is now known as Guest21931
TJ-boldfield: maybe you should pastebin the config?19:41
=== Guest21931 is now known as Newk_z1
boldfieldTJ-: I've got to check that it's kosher that I do, if so I will19:44
aarcaneTJ-, sudo.19:51
markthomasboldfield: I assume you checked the obvious, such as restarting dhcpd, making sure there were no other DHCP servers on the subnet, etc.21:09
boldfieldmarkthomas: you are correct21:10
markthomasboldfield: Just checking.  Then it's time to look at the config.21:11
sheptardinitramfs seems to be trying to make drivers for a kernel I removed using apt23:27
sheptardany suggestions?23:27
JanCsheptard: initramfs doesn't "make" drivers23:40

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!