[08:39] morning [08:45] morning [08:49] allo allo [09:00] Ok... I've been receiving frequent automated email alerts about someone's server that I help maintain some services on. The alerts have been happening for a couple of months, but within a minute or so of the alert I get another "resolved" one [09:00] I've been working on other stuff, so I ignored them (for too long). Finally I contacted the server owner and asked if they knew what was going on [09:01] They said no, but they'd be happy if I could look into it [09:02] I log in, and there's a cryptocurrency minor using 1150% CPU [09:02] *miner [09:03] Assuming the machine had been compromised, I told them... but yes, they installed it themselves, and yes, it coincided with the alerts starting [09:06] did you remove it or leave it? [09:09] Left it, it's their server :) [09:09] But now I can send the alerts to /dev/null with a clear conscience [09:17] and an email saying this in case some other behaviour tries to send similar alerts? [09:51] morn [09:51] cor crypto eh, nasty