Mining server virus

Suddenly received information this afternoon mailbox Ali cloud:

Because of external attack is detected, the server has been blocking other server port (TCP: 6379) visit, it is expected to close within a block 2020-03-17 18:34:26 hours, please be safe and timely self-examination. If in doubt, please contact the ticket, or a phone Ali cloud sale.

Open the background discovery cpu occupancy is almost full, the highest occupancy that kill off, and then restarted after a while children, the Internet search found a Trojan horse in the mining, estimated yesterday the installation of redis not set a password, set redis ip is the network, estimated to be in the script one by one ping ip net with Ali cloud network using loopholes redis implanted virus, according to the online tutorial I put the script that starts automatically deleted useless, also covered with the same title useless, this server is mainly used to own play, lacks important data directly heavy equipment.

No automatic password service with a docker installation, after installation password must be set.

Guess you like

Origin www.cnblogs.com/yamiya/p/12508089.html