Hi guys!
I wonder if you can help me.
On my site I run S2Member.
Until last Saturday, I was running a caching plugin alongside it, called WP Rocket.
WP Rocket is incompatible with S2 Member Pro Forms now - so I uninstalled it properly and swapped it out for Comet Cache.
All seems to work great - but since installation, I’ve noticed something strange happening to WordFence.
The first thing I noticed, was that my scheduled WF security scan timed out after hitting the 3 hour max runtime.
I presumed this was down to CometCache caching 20,000 files to disk - and WF having to trawl those.
I thus excluded wp-content/cache from being scanned. The run time dropped to 1 hour and 33 minutes and all is good.
HOWEVER… I run a dedicated server, and since installing CometCache I have been receiving warning emails from my CPanel like this one below (152 of them so far).
Subject: lfd on mysite.com: Suspicious process running under user mysite
Date: Tue, 21 Feb 2017 14:48:29 +0000
Time: Tue Feb 21 14:48:29 2017 +0000
PID: 12854 (Parent PID:12163)
Account: mysite
Uptime: 162 seconds
Executable:
/opt/cpanel/ea-php56/root/usr/bin/php-cgi
Command Line (often faked in exploits):
/opt/cpanel/ea-php56/root/usr/bin/php-cgi
Network connections by the process (if any):
tcp: 213.32.86.29:52450 -> 213.32.86.29:443
Files open by the process (if any):
/var/cpanel/locale/en.cdb.15857 (deleted)
/tmp/.ZendSem.5QFMe1 (deleted)
/dev/urandom
/home/mysite/public_html/wp-content/wflogs/ips.php
/home/mysite/public_html/wp-content/wflogs/config.tmp.7S6RE6 (deleted)
/home/mysite/public_html/wp-content/wflogs/attack-data.php
/etc/pki/nssdb/cert9.db
/etc/pki/nssdb/key4.db
Have you guys any idea what is causing these emails - I see WF noted many times - and it seems these scripts mentioned are taking way longer than normal to run.
It MUST be a cause of running WF and CC together, as this literally began THE MINUTE CC was installed.
I can see the timestamp of the first email, and it was minutes after installing CC - so something is conflicting somewhere.
Let me know your thoughts.
Thanks so much for your time.
Ross