Thursday, May 26, 2011

/usr/sbin/lfd: FAILED

Message:-

The following list of files have FAILED the md5sum comparison test. This means that the file has been changed in some way. This could be a result of an OS update or application upgrade. If the change is unexpected it should be investigated:

/usr/sbin/lfd: FAILED

Executable:

/usr/bin/php


Command Line (often faked in exploits):

/usr/bin/php /home/tuxunited/public_html/page.php

00400000-0087b000 r-xp 00000000 08:03 328849 /usr/bin/php
00a7a000-00ad7000 rw-p 0047a000 08:03 328849 /usr/bin/php
00ad7000-00e6f000 rw-p 00000000 00:00 0 [heap]
360c800000-360c802000 r-xp 00000000 08:03 196871 /usr/lib64/libXau.so.6.0.0
360c802000-360ca01000 ---p 00002000 08:03 196871 /usr/lib64/libXau.so.6.0.0
360ca01000-360ca02000 rw-p 00001000 08:03 196871 /usr/lib64/libXau.so.6.0.0
360cc00000-360cd05000 r-xp 00000000 08:03 196875 /usr/lib64/libX11.so.6.2.0
360cd05000-360cf05000 ---p 00105000 08:03 196875 /usr/lib64/libX11.so.6.2.0
360cf05000-360cf0c000 rw-p 00105000 08:03 196875 /usr/lib64/libX11.so.6.2.0
360d800000-360d810000 r-xp 00000000 08:03 197687 /usr/lib64/libXpm.so.4.11.0

==================================
This is because of your firewall(LFD) software has been updated automatically. If you are sure about the particular file and this was uploaded by you on your account and also you are no more interested to getting this mail anymore please do the following steps

go into WHM, and click on Configserver Firewall at the bottom of the left menu, then scroll down and add the following line to the "ignore list":

cmd:/usr/bin/php /home/tuxunited/public_html/page.php

1 comment: