Ad Widget

Collapse

Security issue with Zabbix?

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Niro
    Junior Member
    • Feb 2010
    • 4

    #1

    Security issue with Zabbix?

    I'm running a few EC2/Scalr instances with zabbix monitoring.
    I received complaints about one of my servers port scanning other servers. the logs show it is accessing port 22 on consecutive IP addresses.

    I looked at the processes list and saw scanssh is running under the user Zabbix.

    My question is- Is scanssh part of zabbix? Is it suppesd to run?
    I have active autodiscovery on zabbix but it is looking at another IP addresses and definately not port 20.
    Is it possible that something in the config of zabbix agent is controlling it and not the settings on zabbix server?

    What can I do to find out if zabbix is somehow misbehaving or it is a hacker?
    Any advice is highly appreciated.
  • nelsonab
    Senior Member
    Zabbix Certified SpecialistZabbix Certified Professional
    • Sep 2006
    • 1233

    #2
    Do you have network discovery running?

    Heh... reread and answered my on question... Double check your parameters, try some different values.
    RHCE, author of zbxapi
    Ansible, the missing piece (Zabconf 2017): https://www.youtube.com/watch?v=R5T9NidjjDE
    Zabbix and SNMP on Linux (Zabconf 2015): https://www.youtube.com/watch?v=98PEHpLFVHM

    Comment

    • Niro
      Junior Member
      • Feb 2010
      • 4

      #3
      Let me rephrase my question

      I see Scanssh processes owned by zabbix user. Is it normal?
      If it isn't I assume that Zabbix user has been compromised. How can I prevent it in the future?

      Comment

      Working...