mysqld in Linux hacked

Check for crap in /var/lib/mysql like this

 

ls -al /var/lib/mysql/
total 20888
drwxr-xr-x 24 mysql mysql     4096 Oct  3 18:30 .
drwxr-xr-x 20 root  root      4096 Oct  3 04:23 ..

-rw-rw-rw-  1 mysql mysql    11776 Oct  3 17:10 c:\exp.exe
-rw-rw-rw-  1 mysql mysql    48128 Oct  3 17:10 c:\exp1.exe
-rw-rw-rw-  1 mysql mysql    55296 Oct  3 17:10 c:\exp2.exe
-rw-rw-rw-  1 mysql mysql    33812 Oct  3 17:10 c:\tan.exe
-rw-rw-rw-  1 mysql mysql    45056 Oct  3 17:10 c:\tan1.exe
 

This happened to a client who didn't firewall their port 3306 and had a weak root password.


Tags:

mysqld, linux, hackedcheck, var, lib, mysql, ls, drwxr, xr, oct, rw, exp, exe, tan, didn, firewall, password,

Latest Articles

  • Cloned VM/Server/Computer in Linux won't boot and goes to initramfs busybox Solution
  • How To Add Windows 7 8 10 11 to GRUB Boot List Dual Booting
  • How to configure OpenDKIM on Linux with Postfix and setup bind zonefile
  • Debian Ubuntu 10/11/12 Linux how to get tftpd-hpa server setup tutorial
  • efibootmgr: option requires an argument -- 'd' efibootmgr version 15 grub-install.real: error: efibootmgr failed to register the boot entry: Operation not permitted.
  • Apache Error Won't start SSL Cert Issue Solution Unable to configure verify locations for client authentication SSL Library Error: 151441510 error:0906D066:PEM routines:PEM_read_bio:bad end line SSL Library Error: 185090057 error:0B084009:x509 certif
  • Linux Debian Mint Ubuntu Bridge br0 gets random IP
  • redis requirements
  • How to kill a docker swarm
  • docker swarm silly issues
  • isc-dhcp-server dhcpd how to get longer lease
  • nvidia cannot resume from sleep Comm: nvidia-sleep.sh Tainted: Linux Ubuntu Mint Debian
  • zfs and LUKS how to recover in Linux
  • [error] (28)No space left on device: Cannot create SSLMutex Apache Solution Linux CentOS Ubuntu Debian Mint
  • Save money on bandwidth by disabling reflective rpc queries in Linux CentOS RHEL Ubuntu Debian
  • How to access a disk with bad superblock Linux Ubuntu Debian Redhat CentOS ext3 ext4
  • ImageMagick error convert solution - convert-im6.q16: cache resources exhausted
  • PTY allocation request failed on channel 0 solution
  • docker error not supported as upperdir failed to start daemon: error initializing graphdriver: driver not supported
  • Migrated Linux Ubuntu Mint not starting services due to broken /var/run and dbus - Failed to connect to bus: No such file or directory solution