/srv/irclogs.ubuntu.com/2021/04/30/#ubuntu-uk.txt

MattJmorning08:39
lunamorning08:45
zxm-pi_allo allo08:49
MattJOk... I've been receiving frequent automated email alerts about someone's server that I help maintain some services on. The alerts have been happening for a couple of months, but within a minute or so of the alert I get another "resolved" one09:00
MattJI've been working on other stuff, so I ignored them (for too long). Finally I contacted the server owner and asked if they knew what was going on09:00
MattJThey said no, but they'd be happy if I could look into it09:01
MattJI log in, and there's a cryptocurrency minor using 1150% CPU09:02
MattJ*miner09:02
MattJAssuming the machine had been compromised, I told them... but yes, they installed it themselves, and yes, it coincided with the alerts starting09:03
zxm-pi_did you remove it or leave it?09:06
MattJLeft it, it's their server :)09:09
MattJBut now I can send the alerts to /dev/null with a clear conscience09:09
zxm-pi_and an email saying this in case some other behaviour tries to send similar alerts?09:17
daftykinsmorn09:51
daftykinscor crypto eh, nasty09:51

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!