{"id":83,"date":"2006-09-02T19:12:34","date_gmt":"2006-09-03T03:12:34","guid":{"rendered":"http:\/\/wp.colliertech.org\/cj\/?p=83"},"modified":"2006-09-02T19:32:49","modified_gmt":"2006-09-03T03:32:49","slug":"bugzilla-compromized","status":"publish","type":"post","link":"https:\/\/wp.c9h.org\/cj\/?p=83","title":{"rendered":"bugzilla compromised"},"content":{"rendered":"<p>Yow.<\/p>\n<p>Go spamhater.zoomshare.com<\/p>\n<p>\nI&#8217;ve posted a bzip2&#8217;d ext3 image of the compromised (etch) OS here:<br \/>\n<a href=\"http:\/\/wp.colliertech.org\/~cjcollier\/bugzilla.img.bz2\">bugzilla.img.bz2<\/a>\n<\/p>\n<p>\nList of packages installed on the machine here:<br \/>\n<a href=\"http:\/\/wp.colliertech.org\/~cjcollier\/bugzilla-packageList.txt\">bugzilla-packageList<\/a>\n<\/p>\n<p>I&#8217;ll be pointing the authorities to it and providing any other logs required to track down the responsible party.<\/p>\n<pre>\r\nDear Carl\r\n\r\nPlease read this message carefully.\r\n\r\nYou are receiving this email because you are responsible for IP\r\naddress 66.152.65.7\r\nhttps:\/\/bugzilla.colliertech.org\/cgi-bin\/bugzilla\/index.cgi\r\n\r\nThe machine at this address has been hijacked, and an extra process\r\ncalled \"tswapd\" has been installed.\r\nThis process is running many web sites as shown by these URLs:\r\n\r\nhttp:\/\/66.152.65.7:8080\/p\/images\/weship.gif\r\nhttp:\/\/66.152.65.7:8080\/legalrx\/images\/logo.gif\r\nhttp:\/\/66.152.65.7:8080\/usd\/images\/logo.gif\r\nhttp:\/\/66.152.65.7:8080\/rolex\/images\/logo.gif\r\nhttp:\/\/66.152.65.7:8080\/caviar\/images\/main_logo.gif\r\n\r\nAction required\r\n\r\n1. locate the machine at this IP address\r\n2. change the root and any administrator passwords to make them more secure\r\n3. shutdown the machine, and restart\r\n\r\nAlternatively, you can issue the commands to display the process id and kill it:\r\n\r\nps wax | grep \"tswapd\"\r\nkill &lt;pid&gt;\r\n [where &lt;pid&gt; is the process-id displayed by the ps command]\r\n\r\nIf you are not the administrator, please forward this information to\r\nthe administrator.\r\n\r\nTo help you locate the hijacked machine, use this link\r\nhttp:\/\/www.dnsstuff.com\/tools\/tracert.ch?ip=66.152.65.7\r\n\r\n\r\nThank you from the Pharmacy Alert Security Team\r\nFor more information view\r\nhttp:\/\/pharmalert.zoomshare.com\/   and   http:\/\/spamhater.zoomshare.com\/2.shtml\r\n\r\n<\/pre>\n\n<div class=\"twitter-share\"><a href=\"https:\/\/twitter.com\/intent\/tweet?via=cjamescollier\" class=\"twitter-share-button\">Tweet<\/a><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Yow. Go spamhater.zoomshare.com I&#8217;ve posted a bzip2&#8217;d ext3 image of the compromised (etch) OS here: bugzilla.img.bz2 List of packages installed on the machine here: bugzilla-packageList I&#8217;ll be pointing the authorities to it and providing any other logs required to track down the responsible party. Dear Carl Please read this message carefully. You are receiving this [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-83","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"jetpack_featured_media_url":"","jetpack_shortlink":"https:\/\/wp.me\/p1YDIB-1l","jetpack_sharing_enabled":true,"jetpack_likes_enabled":true,"_links":{"self":[{"href":"https:\/\/wp.c9h.org\/cj\/index.php?rest_route=\/wp\/v2\/posts\/83","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wp.c9h.org\/cj\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wp.c9h.org\/cj\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wp.c9h.org\/cj\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/wp.c9h.org\/cj\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=83"}],"version-history":[{"count":0,"href":"https:\/\/wp.c9h.org\/cj\/index.php?rest_route=\/wp\/v2\/posts\/83\/revisions"}],"wp:attachment":[{"href":"https:\/\/wp.c9h.org\/cj\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=83"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wp.c9h.org\/cj\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=83"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wp.c9h.org\/cj\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=83"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}