Vesta Control Panel - Forum

Community Forum

Skip to content

Advanced search
  • Quick links
    • Main site
    • Github repo
    • Google Search
  • FAQ
  • Login
  • Register
  • Board index Main Section Web Server
  • Search

why there is a folder with strange name?

Questions regarding the Web Server
Apache + Nginx, Nginx + PHP5-FPM
Post Reply
  • Print view
Advanced search
5 posts • Page 1 of 1
baijianpeng
Posts: 301
Joined: Tue Dec 22, 2015 2:06 pm

why there is a folder with strange name?
  • Quote

Post by baijianpeng » Tue Jan 05, 2016 1:25 pm

I installed VestaCP on CentOS 7 to offer web panel for my Joomla website.

Today I noticed that in the public_html folder, which is the web root of my website, there is a folder with strange name:

Code: Select all

[root@joomlacloud public_html]# ls
administrator                         components         includes     logs          remos_downloads
A;ٙr4O???x!?X"?*K?)>K6??7??[}????????  configuration.php  index.php    media         robots.txt
bin                                   demo               joomla.xml   modules       robots.txt.dist
bithost.htaccess                      downloads          language     php_errorlog  templates
build.xml                             fpa-en.php         layouts      php_mail.log  tmp
cache                                 htaccess.txt       libraries    plugins       web.config.txt
cli                                   images             LICENSE.txt  README.txt
[root@joomlacloud public_html]# 
Please not this folder name in above texts which were copied from my SSH terminal:

A;ٙr4O???x!?X"?*K?)>K6??7??[}????????

This folder will NOT be shown up if I check my website with FTP client. But on SSH terminal it will show up.

I tried to enter that folder with "cd" command to see what is inside that folder, but the cd command can not work for it.

I tried to delete it with "rmdir" command, then it was deleted.

But, I still have no idea how did that folder being created?

Does this means that my website was hacked?

Thank you.
Top

SS88
Posts: 336
Joined: Thu Nov 19, 2015 12:40 pm

Re: why there is a folder with strange name?
  • Quote

Post by SS88 » Wed Jan 06, 2016 9:21 pm

It could either mean:
  • Your website has been compromised or;
  • Your server has been compromised.
Very hard to tell unless you dig into the logs.
Top

baijianpeng
Posts: 301
Joined: Tue Dec 22, 2015 2:06 pm

Re: why there is a folder with strange name?
  • Quote

Post by baijianpeng » Fri Jan 08, 2016 12:02 am

OK. I have no idea how to investigate this.

The good news is, I deleted that folder with "rmdir" commander. It seems that it has not been re-created yet.

Thank you.
Top

joem
Posts: 378
Joined: Thu Nov 13, 2014 8:33 am

Os: CentOS 6x
Web: nginx + php-fpm
Re: why there is a folder with strange name?
  • Quote

Post by joem » Fri Jan 08, 2016 9:23 am

baijianpeng wrote:OK. I have no idea how to investigate this.

The good news is, I deleted that folder with "rmdir" commander. It seems that it has not been re-created yet.

Thank you.
You really should check the logs in /var/log/ look for the files named access_log or auth.log I would start with ssh, vesta, proftp, and/or vsftpd access logs and see if you can find anything odd or related to the folder name. Also consider changing your root & admin passwords, configure ssh to a different port.
Top

skurudo
VestaCP Team
Posts: 8099
Joined: Fri Dec 26, 2014 2:23 pm
Contact:
Contact skurudo
Website Facebook Google+ Skype
Twitter

Re: why there is a folder with strange name?
  • Quote

Post by skurudo » Fri Jan 08, 2016 9:44 am

baijianpeng wrote:OK. I have no idea how to investigate this.
The good news is, I deleted that folder with "rmdir" commander. It seems that it has not been re-created yet.
Best to change passwords ftp/ssh/db and update the scripts, if it's possible.
Top


Post Reply
  • Print view

5 posts • Page 1 of 1

Return to “Web Server”



  • Board index
  • All times are UTC
  • Delete all board cookies
  • The team
Powered by phpBB® Forum Software © phpBB Limited
*Original Author: Brad Veryard
*Updated to 3.2 by MannixMD
 

 

Login  •  Register

I forgot my password