Issue regarding ./wssh

kam

Verified User
Joined
Jan 4, 2009
Messages
55
http://www.directadmin.com/forum/showthread.php?p=147344#post147344

I just follow above post to update the Roundcube version to 0.2

---

Then I reboot my server, However,

The files still in the /tmp after reboot ,

[root@server /]# cd /tmp
[root@server tmp]# ls -all
total 10688
drwxrwxrwt 4 root root 69632 Jan 13 11:40 .
drwxr-xr-x 24 root root 4096 Jan 13 11:33 ..
-rwxr-xr-x 1 apache apache 4172 Jun 2 2006 cback
-rw-r--r-- 1 apache apache 4172 Jun 2 2006 cback.2
-rw-r--r-- 1 apache apache 4172 Feb 2 2008 cback.3
-rw-r--r-- 1 apache apache 4172 Feb 2 2008 cback.4
-rw-r--r-- 1 apache apache 4172 Feb 2 2008 cback.5
-rw-r--r-- 1 apache apache 4172 Feb 2 2008 cback.6
-rw-r--r-- 1 apache apache 4172 Feb 2 2008 cback.7
drwxrwxrwt 2 root root 4096 Jan 13 11:34 .font-unix
drwxrwxrwt 2 root root 4096 Jan 13 11:33 .ICE-unix
-rw------- 1 apache apache 70 Jan 13 08:36 sess_005c0fe3ad1cb8282572229ba6c61c20
-rw------- 1 apache apache 70 Jan 13 08:47 sess_07229d19a7547e80a291255b77dce975
-rw------- 1 apache apache 598 Jan 10 10:32 sess_4b19fb454922e4f4457125837a85ee67
-rw------- 1 apache apache 2170 Jan 10 07:05 sess_4ea0703014a0ab7032e90f985cde7b75
-rw------- 1 apache apache 70 Jan 13 08:35 sess_53640f971edab45ff7e008170f9504ff
-rw------- 1 apache apache 3755 Jan 10 08:34 sess_61dc1f478da08caf5774c2ed6ac5f04b
-rw------- 1 apache apache 3425 Jan 10 04:57 sess_68e90264fbc72055135dd3dcbab9cdf6
-rw------- 1 apache apache 1060 Jan 10 05:46 sess_6d4051e802ba7d5f1387abf6b2029cdc
-rw------- 1 apache apache 2121 Jan 10 10:37 sess_7afe3ed8455e2f3f35dc5ce8b666b131
-rw------- 1 apache apache 2313 Jan 10 09:59 sess_86430e9ac1f247628b7d4159dc304ced
-rw------- 1 apache apache 598 Jan 10 10:37 sess_965bd5ec39f6bf616b46a35bf47b04fd
-rw------- 1 apache apache 1060 Jan 10 06:13 sess_a1d47a3de2f0ca5f1819e664a35bb499
-rw------- 1 apache apache 70 Jan 13 08:46 sess_ca4fb5fc3345ec876854ccd944ad2d8c
-rw------- 1 apache apache 1060 Jan 10 10:05 sess_e4cadcafa1fc9cc04c9746881fc08562
-rw------- 1 apache apache 3258 Jan 13 09:40 sess_e53a1efb57b4ea27e91488d71bffade3
-rw------- 1 apache apache 2453 Jan 10 10:32 sess_ee14e1999e8188fad38bc15134b4d91d
-rwxr-xr-x 1 apache apache 3569280 Jan 12 09:41 wssh
-rw-r--r-- 1 apache apache 3569280 Jan 12 09:41 wssh.1
-rw-r--r-- 1 apache apache 3569280 Jan 12 09:41 wssh.2


---------------

I will manually delete those Files, but I wonder to know it is a must to reload OS ?

I don't want to spend extra money for a OS reload request.

Thank you for answering,

Kam
 
Last edited:
Unfortunately, we don't know what the hack has installed but the sess_ files appear to just be session files.

Delete the cback and wssh files.
 
If the processes were running as apache then there is nothing to worry about probably. If you had found unknown processes running as root then you would be in trouble.
 
Back
Top