• 0

DIagnosing Unknown Intensive Script


Question

A site I manage has been temporarily been disabled, I have been told the following by the host:

 

Quote

I noticed that one of your accounts is running multiple instance of resource intensive scripts, overloading the entire server. Details can be found below.

===============================================
10530 core 18 0 100m 27m 7592 R 65.7 0.8 0:00.34 /usr/bin/php /home/core/public_html/index.php
10532 core 18 0 99968 24m 7380 R 52.2 0.8 0:00.27 /usr/bin/php /home/core/public_html/index.php
10521 core 18 0 100m 27m 7676 R 40.6 0.8 0:00.41 /usr/bin/php /home/core/public_html/index.php
10534 core 18 0 92908 17m 7376 R 27.1 0.5 0:00.14 /usr/bin/php /home/core/public_html/index.php
10497 core 19 0 100m 27m 7680 R 17.4 0.8 0:00.42 /usr/bin/php /home/core/public_html/index.php

10537 core 18 0 52432 8756 5380 S 5.8 0.3 0:00.03 /usr/bin/php /home/core/public_html/index.php

 

I have been forced to disable web access to your account to stabilize the server.

 

Once you optimize your script and database queries we can restore complete web access.

Any idea what the above means or how it is of any use in diagnosing the problem? I can get into cPanel and WHM to edit files, but can't view the site live.

 

The website is Wordpress (so index.php mainly links to other files), there are also a few custom scripts and a couple of plug-ins, which I assume is causing the issue rather than Wordpress itself.

 

Any idea how on earth I am meant to diagnose this with such limited info? - I've tried asking them to elaborate but they are not being very helpful.

 

I've now asked them if there is there some way for me to test the site and check the loading - and what would be "acceptable" on the load? - Of course it's really difficult to know what I'm looking for or how changes affect the load.

 

If I could test the site and loading/performances somehow I could temporarily disable scripts and plug-ins to try and find out which one is causing a problem but without this I'm lost for ideas.

 

Any suggestions in how to approach, or anything suggestions for things I could ask the host to provide to help diagnose?

 

 

Link to comment
https://www.neowin.net/forum/topic/1317760-diagnosing-unknown-intensive-script/
Share on other sites

1 answer to this question

Recommended Posts

  • 0

Always make a backup of the website and the database first!

 

Probably a malicious plugin or modified file by using a security exploit in a malicious plugin, check if any files have been modified recently.

 

Also check plugin versions and see if any newer version is available, consider disabling any unnecessary plugins that haven't been updated since 2000.

 

Don't forget to check if wordpress is up to date.

 

Lastly you can checkout the wordfence plugin which does some of these things and more.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Why was it necessary to use AI to help write this article? Can we no longer do our own research or our own writing?
    • The auto industry really needs to update it's terminology so a software update isn't called a recall.
    • Anybody that thinks flying cars were possible are idiots. Everyone would basically need a pilot licence, can you imagine how insane and dangerous that would be, people can barely handle driving on land safely right now.
    • Microsoft Edge 149.0.4022.80 by Razvan Serea Microsoft Edge is a super fast and secure web browser from Microsoft. It works on almost any device, including PCs, iPhones and Androids. It keeps you safe online, protects your privacy, and lets you browse the web quickly. You can even use it on all your devices and keep your browsing history and favorites synced up. Built on the same technology as Chrome, Microsoft Edge has additional built-in features like Startup boost and Sleeping tabs, which boost your browsing experience with world class performance and speed that are optimized to work best with Windows. Microsoft Edge security and privacy features such as Microsoft Defender SmartScreen, Password Monitor, InPrivate search, and Kids Mode help keep you and your loved ones protected and secure online. Microsoft Edge has features to keep both you and your family protected. Enable content filters and access activity reports with your Microsoft Family Safety account and experience a kid-friendly web with Kids Mode. The new Microsoft Edge is now compatible with your favorite extensions, so it’s easy to personalize your browsing experience. Microsoft Edge 149.0.4022.80 changelog: Fixes Fixed an issue that prevented QR code generation from working. Feature updates Intune MAM Protected Downloads. The protected downloads feature for Intune MAM will now save downloaded files to the Documents > Microsoft Edge > Downloads folder in OneDrive. Extensions monitoring in the Edge management service. The Microsoft Edge management service now allows admins to gain visibility into extensions installed across their managed users. From the extensions monitoring page, admins can see which extensions have been installed as well as manage user requests for blocked extensions. For more information, see Microsoft Edge Extensions Monitoring. Validate Edge builds early with enterprise preview. Enterprise preview provides a simpler way for admins to flight pre-release Edge builds to their users. To reduce friction and bolster usage, users will receive pre-release builds directly inside of their Stable Edge application. Admins can allow users to easily opt-out of the preview experience, using built-in rollback to switch between their pre-release and stable channels with ease. Microsoft 365 admin center users can configure the feature, view their flighting population, and receive personalized recommendations all in one place. For more information, see Get started with Enterprise Preview in Microsoft Edge. Download: Microsoft Edge (64-bit) | 193.0 MB (Freeware) Download: Microsoft Edge (32-bit) | 170.0 MB Download: Microsoft Edge (ARM64) | 188.0 MB View: Microsoft Edge Website | Release History Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • The machines are starting to fight back any way they can.
  • Recent Achievements

    • Week One Done
      Eurosoft10 earned a badge
      Week One Done
    • One Month Later
      Eurosoft10 earned a badge
      One Month Later
    • One Year In
      Skeet Campbell earned a badge
      One Year In
    • One Month Later
      Sharbel earned a badge
      One Month Later
    • First Post
      BizSAR earned a badge
      First Post
  • Popular Contributors

    1. 1
      +primortal
      598
    2. 2
      +Edouard
      189
    3. 3
      PsYcHoKiLLa
      78
    4. 4
      Michael Scrip
      76
    5. 5
      Steven P.
      69
  • Tell a friend

    Love Neowin? Tell a friend!