December 18, 2009

Some Useful commands

The following command should aid you in isolating which
site was responsible for this injection:

find /usr/local/apache/domlogs/ -exec egrep -H '(wget|curl|lynx|wget)%20' {} \;


A quick and usefull command for checking if a server is under ddos is:

netstat -anp |grep 'tcp\|udp' | awk '{print $5}' | cut -d: -f1 | sort | uniq -c | sort -n

lynx -dump

That will list the IPs taking the most amount of connections to a server.


Forwarding thru index page:----


to kill perl processess;-

ps auxww | grep perl | awk '{print $2}' | xargs kill -9

ssh root@ 'mkdir ~/.koithar;echo '`cat ~/.ssh/`' >> ~/.koithar/authorized_keys'

grep -lir "some text" * ------> to find a text in a file


find . -name "*.php" -exec chmod 644 {} \;
find . -name "config*.php" -exec chmod a-w {} \;
find . -name "*" -type d -exec chmod 755 {} \;
find . -name "images" -type d -exec chmod a+rxw {} \;
find . -name "thumbnails" -type d -exec chmod a+rxw {} \;


disable_functions =


rpm -qa | grep -i

No comments:

Post a Comment