Show newer

same with .syslog I've seen it like that on someone else's machine hah

Show thread

the kswapd0 thing is pretty smart, as all the results for 'kswapd0 high cpu' (which you would be seeing) are non-malicious explanations like
askubuntu.com/questions/259739

Show thread

and slightly more in-depth writeup, yoroi.company/research/outlaw-
the 'c' component is actually what alerted us, with abuse email sent from another provider 'hey pls stop bruteforcing our hosts'

Show thread

- ssh with password auth enabled
- ssh'd into minecraft user with apparently weak password
- deployed payload, consisting of an irc c&c, and a monero miner disguised as 'kswapd0'

by far not the only ones, for example blog.alvarezp.org/2020/06/18/m

Show thread

well fun morning, server from friends got epic haxored so i did forensics from my phone, in bed

subtooty 

heh, i guess my search-bubble is better than theirs, my experience doesn't match that at all

uni 

im glad, got a good reply on my email and don't have to attend the attendance check now

Show thread

@deletescape@notbird.site :bing: Internet of 🅱️ings

@deletescape@notbird.site Internet of Treasures

maybe this should become a silly bot

@AllNyaNoBite@notbird.site what is loaf, baby don't hurt me

Show older
Pixietown

Small server part of the pixie.town infrastructure. Registration is closed.