چند روز پیش متوجه شدم که سایت بنده به صورت موقت به حالت تعلیق در آمده است بعد از اینکه با مسئول هاست مکاتبه داشتم آنا به بنده جواب زیر را دادند . آنها فکر می کنند که از طریق سایت بنده قصد حمله و هک کردن سایت آنها را داشته اند به همین علت سایت بنده را به حالت تعلق در آورده اند خواهش می کنم یک نگاهی بیندازید و نظر خودتان را در این مورد بفرمایید امکان دارد که آنها اشتباه می کرده اند یا نه؟
security team has noticed following hacking attempts from your website xxx.com,
we have immediately suspended the website as it is direct abuse of the network services and a violation of our TOS and AUP.
1) Suspicious file created in /tmp directory:
Time: Wed Oct 14 10

12 2009 +1100
File: /tmp/bds
Reason: Binary executable
Owner: xxx

xx
Action: No action taken
2) Remote php shell script uploaded to the website and executed.
crusader [/home/xxx/public_html]# head INSTALL.php
/*******************************************/
/* FaTaLisTiCz_Fx Fx29Sh v1 06.2008 */
/* Re-coded and modified By FaTaLisTiCz_Fx */
/* #CyBeRz@irc.allnetwork.org */
/*******************************************/
$sh_id = "RmFUYUxpc1RpQ3pfRnggRngyOVNoZUxMIHY=";
$sh_ver = "1.5 06.2008";
$sh_name = base64_decode($sh_id).$sh_ver;
$sh_mainurl = "http://legalref.ru/config/";
-------apache log-------
xx.xx.xx.xx - - [14/Oct/2009:09:13:14 +1100] "GET /INSTALL.php HTTP/1.0" 200 6535 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.5) Gecko /2008120122 Firefox/3.0.5"
xx.xx.xx.xx - - [14/Oct/2009:09

27 +1100] "GET /INSTALL.php HTTP/1.0" 200 6543 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.5) Gecko /2008120122 Firefox/3.0.5"
xx.xx.xx.xx - - [14/Oct/2009:09

17 +1100] "GET /INSTALL.php?act=ls&d=%2Fhome%2Firanpowe%2Fpublic_h tml%2Flogs&sort=0a HTTP/1.0" 404 - "http://www.xxx.com/INSTALL.php" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0.5"
xx.xx.xxx.xxx - - [14/Oct/2009:09

21 +1100] "GET /INSTALL.php HTTP/1.0" 200 6543 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.5) Gecko /2008120122 Firefox/3.0.5"
72.52.96.163 - - [14/Oct/2009:09

26 +1100] "GET /INSTALL.php HTTP/1.0" 200 6542 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.5) Gecko /2008120122 Firefox/3.0.5"
xx.xx.xx.xx - - [14/Oct/2009:09

30 +1100] "GET /INSTALL.php?act=ls&d=%2Fhome%2Firanpowe%2Fpublic_h tml%2Fadministrator&sort=0a HTTP/1.0" 404 - "http:/ /www.xxx.com/INSTALL.php" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0.5"
xx.xx.xx.xxx - - [14/Oct/2009:09

33 +1100] "GET /INSTALL.php HTTP/1.0" 200 6543 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.5) Gecko /2008120122 Firefox/3.0.5"
72.52.96.163 - - [14/Oct/2009:09

00 +1100] "POST /INSTALL.php HTTP/1.0" 200 6634 "http://www.xxx.com/INSTALL.php" "Mozilla/5.0 (Windows; U; W indows NT 5.1; en-US; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0.5"
72.52.96.163 - - [14/Oct/2009:09

29 +1100] "GET /cpanel.php HTTP/1.0" 401 20 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.5) Gecko/20 08120122 Firefox/3.0.5"
xx.xxx.xx.xx - - [14/Oct/2009:09

54 +1100] "GET /cpanel.php HTTP/1.0" 401 20 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.5) Gecko/20 08120122 Firefox/3.0.5"
xx.xx.xx.xx - - [14/Oct/2009:09

00 +1100] "GET /cpanel.php HTTP/1.0" 200 5024 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.5) Gecko/ 2008120122 Firefox/3.0.5"
xxx.xx.xx.xxx - - [14/Oct/2009:09

46 +1100] "POST /cpanel.php HTTP/1.0" 200 5224 "http://www.xxx.com/cpanel.php" "Mozilla/5.0 (Windows; U; Win dows NT 5.1; en-US; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0.5"
xx.xx.xx.xxx- - [14/Oct/2009:09

51 +1100] "GET /cpanel.php HTTP/1.0" 200 5024 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.5) Gecko/ 2008120122 Firefox/3.0.5"
xx.xx.xx.xxx - - [14/Oct/2009:09

45 +1100] "POST /cpanel.php HTTP/1.0" 200 12710 "http://www.xxx.com/cpanel.php" "Mozilla/5.0 (Windows; U; Wi ndows NT 5.1; en-US; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0.5"
xx.xx.xxx.xxx - - [14/Oct/2009:09

38 +1100] "POST /cpanel.php HTTP/1.0" 200 12712 "http://www.xxx.com/cpanel.php" "Mozilla/5.0 (Windows; U; Wi ndows NT 5.1; en-US; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0.5"
xx.xx.xx.xx - - [14/Oct/2009:09

11 +1100] "GET /cpanel.php HTTP/1.1" 401 20 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2. 0.50727; .NET CLR 3.0.04506.30)"
xx.xx.xxx.xxx - - [14/Oct/2009:09

21 +1100] "GET /cpanel.php HTTP/1.1" 200 5024 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)"
xx.xx.xx.xx - - [14/Oct/2009:09

41 +1100] "POST /cpanel.php HTTP/1.1" 200 12712 "http://www.xxx.com/cpanel.php" "Mozilla/4.0 (compatible; M SIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)"
xxx.xx.xx.xx - - [14/Oct/2009:09

49 +1100] "POST /cpanel.php HTTP/1.1" 200 12712 "http://www.xxx.com/cpanel.php" "Mozilla/4.0 (compatible; M SIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)"
xxx.xxx.xx.xx - - [14/Oct/2009:09

33 +1100] "POST /cpanel.php HTTP/1.1" 200 12710 "http://www.xxx.com/cpanel.php" "Mozilla/4.0 (compatible; M SIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)"
xx.xx.xx.xx - - [14/Oct/2009:09

17 +1100] "GET /INSTALL.php HTTP/1.0" 200 6593 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.5) Gecko /2008120122 Firefox/3.0.5"
xx.xxx.xxx.xxx - - [14/Oct/2009:09

17 +1100] "POST /INSTALL.php? HTTP/1.0" 200 6551 "http://www.xxx.com/INSTALL.php" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0.5"