Recently I got my VPS port scanned by anonymous guy.
He came from : leased-line-87-252-246-142.telecom.by and was using "Test" as his login ID.
The process consuming more than 60% CPU
He was running some script (./pscan2)
How did he gained access to my VPS (root login has been disabled)?
I remembered I just updated my FluxBB (officially) to the latest and this all happened .
Anyone can share of how to prevent this happen again in the future?
test 18354 0.0 0.3 3000 1620 pts/2 Ss 05:05 0:00 /bin/bash
test 18358 0.0 0.2 3140 1212 pts/2 S+ 05:05 0:00 /bin/bash
test 30553 0.0 0.1 968 560 pts/2 S+ 16:38 0:01 ./ssh-scan 100
test 30574 0.0 0.1 968 560 pts/2 S+ 16:39 0:00 ./ssh-scan 100
test 30577 0.0 0.1 968 560 pts/2 S+ 16:40 0:00 ./ssh-scan 100
test 30578 0.0 0.1 968 560 pts/2 S+ 16:40 0:01 ./ssh-scan 100
test 30581 0.0 0.1 968 560 pts/2 S+ 16:40 0:00 ./ssh-scan 100
test 30582 0.0 0.1 968 560 pts/2 S+ 16:40 0:00 ./ssh-scan 100
test 30583 0.1 0.1 976 516 pts/2 S+ 16:40 0:01 ./ssh-scan 100
test 30593 0.0 0.1 968 560 pts/2 S+ 16:40 0:01 ./ssh-scan 100
test 30594 0.0 0.1 968 560 pts/2 S+ 16:40 0:00 ./ssh-scan 100
test 30598 0.0 0.1 968 560 pts/2 S+ 16:40 0:00 ./ssh-scan 100
test 30604 0.0 0.1 968 560 pts/2 S+ 16:40 0:00 ./ssh-scan 100
test 30605 0.0 0.1 968 560 pts/2 S+ 16:40 0:00 ./ssh-scan 100
test 30613 0.0 0.1 968 560 pts/2 S+ 16:40 0:00 ./ssh-scan 100
test 30617 0.1 0.1 976 516 pts/2 S+ 16:40 0:01 ./ssh-scan 100
test 30620 0.0 0.1 968 560 pts/2 S+ 16:40 0:00 ./ssh-scan 100
test 30636 0.0 0.1 968 560 pts/2 S+ 16:40 0:00 ./ssh-scan 100
test 30638 0.1 0.1 976 516 pts/2 S+ 16:40 0:01 ./ssh-scan 100
test 30642 0.0 0.1 1128 612 pts/2 S+ 16:40 0:00 ./ssh-scan 100
test 30643 0.0 0.1 968 560 pts/2 S+ 16:40 0:00 ./ssh-scan 100
test 30651 0.0 0.1 964 556 pts/2 S+ 16:41 0:00 ./ssh-scan 100
test 30657 0.0 0.1 968 560 pts/2 S+ 16:41 0:00 ./ssh-scan 100
test 30659 0.0 0.1 968 560 pts/2 S+ 16:41 0:00 ./ssh-scan 100
test 30664 0.0 0.1 968 560 pts/2 S+ 16:41 0:00 ./ssh-scan 100
test 30670 0.0 0.1 968 560 pts/2 S+ 16:41 0:00 ./ssh-scan 100
test 30746 0.0 0.2 2640 1108 pts/2 S+ 16:46 0:00 /bin/bash ./a 200.23
test 30838 0.0 0.0 948 188 pts/2 S+ 16:55 0:00 ./ssh-scan 100