Hi, this morning the tiger on one of my servers reported that apache is listening on some new ports:
# Checking listening processes NEW: --WARN-- [lin003w] The process `apache' is listening on socket 43133 (TCP on every interface) is run by root. NEW: --WARN-- [lin003w] The process `apache' is listening on socket 43142 (TCP on every interface) is run by root. NEW: --WARN-- [lin003w] The process `apache' is listening on socket 43143 (TCP on every interface) is run by root. NEW: --WARN-- [lin003w] The process `apache' is listening on socket 43144 (TCP on every interface) is run by root. After restarting apache it was gone. What could that be? I'm a bit confused since these ports were never mentioned in the config-files... The other thing I discovered this morning is that shortly after restarting apache it spawns around 70 times and one instance is defunct, together with one defunct instance of php3 (which I run here as cgi). Is there a new apache-exploit in the wild? - Alexander
pgpsjRNfLBu0H.pgp
Description: PGP signature