Trying to ignore a Perl script, but still getting alerts
Posted: 12 Dec 2023, 20:28
I've been getting a ton of "suspicious process" alerts lately about a Perl script that hasn't been modified since 2020. So I'm pretty sure these are false alerts.
The email says:
I'm still getting emailed alerts on it, though.
The code looks right to me, so what have I done wrong?
The email says:
So I added this to csf.pignore via WHM, and of course let WHM restart lfd:Time: Tue Dec 12 15:18:14 2023 -0500
PID: 19935 (Parent PID:23922)
Account: nobody
Uptime: 99 seconds
Executable:
/usr/bin/perl
Command Line (often faked in exploits):
/usr/bin/perl /home/example/public_html/cgi-bin/cart.cgi
Code: Select all
pexe:/home/example/public_html/cgi-bin/cart\.cgi
The code looks right to me, so what have I done wrong?