csf.pignore - ignore a wget command
Hello guys,
We get alerts from CSF/LFD many times a day about a command running from one of our clients websites. The email reads (changed a little so url isnt correct):
lfd on server1.hostname.com: Suspicious process running under user lloydmorgan
Executable: /usr/bin/wget
Command Line (often faked in exploits):
wget --quiet --delete-after --no-check-certificate
What am i doing wrong, how can i ignore this process correctly by wildcard the wget domain? Is it possible?
Please sign in to leave a comment.
Comments
0 comments