mysqld in Linux hacked

Check for crap in /var/lib/mysql like this

 

ls -al /var/lib/mysql/
total 20888
drwxr-xr-x 24 mysql mysql     4096 Oct  3 18:30 .
drwxr-xr-x 20 root  root      4096 Oct  3 04:23 ..

-rw-rw-rw-  1 mysql mysql    11776 Oct  3 17:10 c:\exp.exe
-rw-rw-rw-  1 mysql mysql    48128 Oct  3 17:10 c:\exp1.exe
-rw-rw-rw-  1 mysql mysql    55296 Oct  3 17:10 c:\exp2.exe
-rw-rw-rw-  1 mysql mysql    33812 Oct  3 17:10 c:\tan.exe
-rw-rw-rw-  1 mysql mysql    45056 Oct  3 17:10 c:\tan1.exe
 

This happened to a client who didn't firewall their port 3306 and had a weak root password.


Tags:

mysqld, linux, hackedcheck, var, lib, mysql, ls, drwxr, xr, oct, rw, exp, exe, tan, didn, firewall, password,

Latest Articles

  • Cisco Unified Communication Manager (CUCM) - How To Add Phones
  • pptp / pptpd not working in DD-WRT iptables / router
  • systemd-journald high memory usage solution
  • How to Install FreePBX in Linux Debian Ubuntu Mint Guide
  • How To Install Cisco's CUCM (Cisco Unified Communication Manager) 12 Guide
  • Linux Ubuntu Redhat How To Extract Images from PDF
  • Linux and Windows Dual Boot Issue NIC Won't work After Booting Windows
  • Cisco CME How To Enable ACD hunt groups
  • How to install gns3 on Linux Ubuntu Mint
  • How to convert audio for Asterisk .wav format
  • Using Cisco CME Router with Asterisk as a dial-peer
  • Cisco CME How To Configure SIP Trunk VOIP
  • Virtualbox host Only Network Error Failed to save host network interface parameter - Cannot change gateway IP of host only network
  • Cisco CME and C7200 Router Testing and Learning Environment on Ubuntu 20+ Setup Tutorial Guide
  • Abusive IP ranges blacklist
  • How to Install Any OS on a Physical Drive from Windows Using VMware Workstation (Linux, Windows, BSD)
  • CDN Cloudflare how to set and preserve the real IP of the client without modifying application code on Apache
  • CentOS 7 fix Could not retrieve mirrorlist http://mirrorlist.centos.org/?release=7&arch=x86_64&repo=os&infra=container error was 14: curl#6 -
  • Ubuntu Debian How To Install Recommended Packages Automatically
  • How to set Linux Ubuntu Redhat Debian Command Line http https socks proxy for yum apt