Hi all,
I have a serious problem. I have a Linux Redhat 6.2 box. Recently, when I use IP sniffer to check, I see a connection to a chatroom (nobody logs in at that time, also it happens right after I restart the system).
1. It tries to connect to "Haarlem.NL.EU.UnderNet.Org 433 _lamer- Sysop- :Nickname is already in use.." with the nick "NICK Sysop-..UnderN".
2. Then that IRC server returns "Haarlem.NL.EU.UnderNet.Org 433 _lamer- Sysop- :Nickname is already in use.."
3. My server sends "S¨AWAY :Sug sule de moldoveni toata ziua.
ysop"
4. Then that IRC server returns "Haarlem.NL.EU.UnderNet.Org 306 _lamer- :You have been marked as being away."
After that, the process begins from step 1 again. It sends these info every 2-4 seconds.
The IP address of that IRC chatroom is 62.250.14.6.
Following is all the processes running on the Linux box (ps -Af). Could anyone find the program (you think) it is the cause.
One more thing, in windows they have autoexec.bat to run programs on booting. Where is that file (or directory) in Linux? I couldn't find anything like that in Linux (sc directory ..). I am not really good with Linux but have some experiences. Please just tell me anything you think of, if I don't undertand well I can look it up.
UID PID PPID C STIME TTY TIME CMD
root 1 0 0 10:31 ? 00:00:04 init [5]
root 2 1 0 10:31 ? 00:00:00 [kflushd]
root 3 1 0 10:31 ? 00:00:00 [kupdate]
root 4 1 0 10:31 ? 00:00:00 [kpiod]
root 5 1 0 10:31 ? 00:00:00 [kswapd]
root 6 1 0 10:31 ? 00:00:00 [mdrecoveryd]
bin 320 1 0 10:33 ? 00:00:00 portmap
root 335 1 0 10:33 ? 00:00:00 [lockd]
root 336 335 0 10:33 ? 00:00:00 [rpciod]
root 345 1 0 10:33 ? 00:00:00 rpc.statd
root 359 1 0 10:33 ? 00:00:00 /usr/sbin/apmd -p 10 -w 5 -W -s /etc/sysconfig/apm-scripts/suspend -r /etc/sysconfig/apm-scrip
root 410 1 0 10:33 ? 00:00:00 syslogd -m 0
root 419 1 0 10:33 ? 00:00:00 klogd
daemon 437 1 0 10:33 ? 00:00:00 /usr/sbin/atd
root 451 1 0 10:33 ? 00:00:00 crond
root 469 1 0 10:33 ? 00:00:00 inetd
root 483 1 0 10:33 ? 00:00:00 lpd
root 528 1 0 10:33 ? 00:00:00 sendmail: accepting connections on port 25
root 543 1 0 10:33 ttyS0 00:00:00 gpm -t ms
xfs 595 1 0 10:33 ? 00:00:00 xfs -droppriv -daemon -port -1
root 604 1 0 10:33 ? 00:00:24 httpd
root 655 1 0 10:34 tty1 00:00:00 /sbin/mingetty tty1
root 656 1 0 10:34 tty2 00:00:00 /sbin/mingetty tty2
root 657 1 0 10:34 tty3 00:00:00 /sbin/mingetty tty3
root 658 1 0 10:34 tty4 00:00:00 /sbin/mingetty tty4
root 659 1 0 10:34 tty5 00:00:00 /sbin/mingetty tty5
root 660 1 0 10:34 tty6 00:00:00 /sbin/mingetty tty6
root 661 1 0 10:34 ? 00:00:00 /usr/bin/kdm -nodaemon
root 737 661 0 10:41 ? 00:00:00 /etc/X11/X -auth /usr/X11R6/lib/X11/xdm/authdir/A:0-rz9vtb
root 741 661 0 10:41 ? 00:00:00 -:0
I have a serious problem. I have a Linux Redhat 6.2 box. Recently, when I use IP sniffer to check, I see a connection to a chatroom (nobody logs in at that time, also it happens right after I restart the system).
1. It tries to connect to "Haarlem.NL.EU.UnderNet.Org 433 _lamer- Sysop- :Nickname is already in use.." with the nick "NICK Sysop-..UnderN".
2. Then that IRC server returns "Haarlem.NL.EU.UnderNet.Org 433 _lamer- Sysop- :Nickname is already in use.."
3. My server sends "S¨AWAY :Sug sule de moldoveni toata ziua.
ysop"
4. Then that IRC server returns "Haarlem.NL.EU.UnderNet.Org 306 _lamer- :You have been marked as being away."
After that, the process begins from step 1 again. It sends these info every 2-4 seconds.
The IP address of that IRC chatroom is 62.250.14.6.
Following is all the processes running on the Linux box (ps -Af). Could anyone find the program (you think) it is the cause.
One more thing, in windows they have autoexec.bat to run programs on booting. Where is that file (or directory) in Linux? I couldn't find anything like that in Linux (sc directory ..). I am not really good with Linux but have some experiences. Please just tell me anything you think of, if I don't undertand well I can look it up.
UID PID PPID C STIME TTY TIME CMD
root 1 0 0 10:31 ? 00:00:04 init [5]
root 2 1 0 10:31 ? 00:00:00 [kflushd]
root 3 1 0 10:31 ? 00:00:00 [kupdate]
root 4 1 0 10:31 ? 00:00:00 [kpiod]
root 5 1 0 10:31 ? 00:00:00 [kswapd]
root 6 1 0 10:31 ? 00:00:00 [mdrecoveryd]
bin 320 1 0 10:33 ? 00:00:00 portmap
root 335 1 0 10:33 ? 00:00:00 [lockd]
root 336 335 0 10:33 ? 00:00:00 [rpciod]
root 345 1 0 10:33 ? 00:00:00 rpc.statd
root 359 1 0 10:33 ? 00:00:00 /usr/sbin/apmd -p 10 -w 5 -W -s /etc/sysconfig/apm-scripts/suspend -r /etc/sysconfig/apm-scrip
root 410 1 0 10:33 ? 00:00:00 syslogd -m 0
root 419 1 0 10:33 ? 00:00:00 klogd
daemon 437 1 0 10:33 ? 00:00:00 /usr/sbin/atd
root 451 1 0 10:33 ? 00:00:00 crond
root 469 1 0 10:33 ? 00:00:00 inetd
root 483 1 0 10:33 ? 00:00:00 lpd
root 528 1 0 10:33 ? 00:00:00 sendmail: accepting connections on port 25
root 543 1 0 10:33 ttyS0 00:00:00 gpm -t ms
xfs 595 1 0 10:33 ? 00:00:00 xfs -droppriv -daemon -port -1
root 604 1 0 10:33 ? 00:00:24 httpd
root 655 1 0 10:34 tty1 00:00:00 /sbin/mingetty tty1
root 656 1 0 10:34 tty2 00:00:00 /sbin/mingetty tty2
root 657 1 0 10:34 tty3 00:00:00 /sbin/mingetty tty3
root 658 1 0 10:34 tty4 00:00:00 /sbin/mingetty tty4
root 659 1 0 10:34 tty5 00:00:00 /sbin/mingetty tty5
root 660 1 0 10:34 tty6 00:00:00 /sbin/mingetty tty6
root 661 1 0 10:34 ? 00:00:00 /usr/bin/kdm -nodaemon
root 737 661 0 10:41 ? 00:00:00 /etc/X11/X -auth /usr/X11R6/lib/X11/xdm/authdir/A:0-rz9vtb
root 741 661 0 10:41 ? 00:00:00 -:0