RPI Status with PHP

system date : Sun Feb  2 00:07:04 PST 2025

whoami : www-data

uname -a : Linux rpi4bmedia 5.10.103-v7l+ #1529 SMP Tue Mar 8 12:24:00 GMT 2022 armv7l GNU/Linux

uptime :  00:07:04 up 110 days,  1:37,  2 users,  load average: 0.27, 0.25, 0.21

File systems on RPI
Filesystem                     Size  Used Avail Use% Mounted on
/dev/root                       29G  8.2G   20G  30% /
devtmpfs                       1.8G     0  1.8G   0% /dev
tmpfs                          1.9G     0  1.9G   0% /dev/shm
tmpfs                          1.9G  199M  1.7G  11% /run
tmpfs                          5.0M  4.0K  5.0M   1% /run/lock
tmpfs                          1.9G     0  1.9G   0% /sys/fs/cgroup
/dev/mmcblk0p1                 253M   49M  204M  20% /boot
/dev/sda1                      1.9T   19G  1.9T   1% /media/usbdisk2t
//192.168.11.182/rpi4_usbdisk  3.7T  835G  2.9T  23% /media/rpi4b_usbdisk
//192.168.11.141/Shiva_D       7.3T  4.8T  2.5T  66% /media/Shiva_D
//192.168.11.141/Shiva_E       2.8T  2.7T   59G  98% /media/Shiva_E
tmpfs                          384M  4.0K  384M   1% /run/user/1001

ps aux --sort=-pcpu on RPI
USER       PID %CPU %MEM    VSZ   RSS TTY      STAT START   TIME COMMAND
gottsch   1345  3.8 12.8 903284 503932 ?       Sl    2024 6162:26 lxpanel --profile LXDE-pi
gottsch   1045  2.9 11.4 849776 449816 ?       Sl    2024 4606:43 lxpanel --profile LXDE-pi
root       949  0.3  1.3 158916 54296 tty7     Ssl+  2024 574:12 /usr/lib/xorg/Xorg :0 -seat seat0 -auth /var/run/lightdm/root/:0 -nolisten tcp vt7 -novtswitch
gottsch    691  0.2  0.7 116072 30728 ?        Sl    2024 375:21 /usr/bin/Xvnc-core :1 -auth /home/gottsch/.Xauthority -pn -fp /usr/share/vnc/fonts/ -geometry 1280x1024 -depth 24
root         1  0.0  0.1  33860  7788 ?        Ss    2024  26:07 /sbin/init splash
root         2  0.0  0.0      0     0 ?        S     2024   0:13 [kthreadd]
root         3  0.0  0.0      0     0 ?        I<    2024   0:00 [rcu_gp]
root         4  0.0  0.0      0     0 ?        I<    2024   0:00 [rcu_par_gp]
root         8  0.0  0.0      0     0 ?        I<    2024   0:00 [mm_percpu_wq]
root         9  0.0  0.0      0     0 ?        S     2024   0:00 [rcu_tasks_rude_]
root        10  0.0  0.0      0     0 ?        S     2024   0:00 [rcu_tasks_trace]
root        11  0.0  0.0      0     0 ?        S     2024   8:10 [ksoftirqd/0]
root        12  0.0  0.0      0     0 ?        I     2024  97:32 [rcu_sched]
root        13  0.0  0.0      0     0 ?        S     2024   0:02 [migration/0]
root        14  0.0  0.0      0     0 ?        S     2024   0:00 [cpuhp/0]
root        15  0.0  0.0      0     0 ?        S     2024   0:00 [cpuhp/1]
root        16  0.0  0.0      0     0 ?        S     2024   0:08 [migration/1]
root        17  0.0  0.0      0     0 ?        S     2024   2:04 [ksoftirqd/1]
root        20  0.0  0.0      0     0 ?        S     2024   0:00 [cpuhp/2]
root        21  0.0  0.0      0     0 ?        S     2024   0:05 [migration/2]
root        22  0.0  0.0      0     0 ?        S     2024   1:12 [ksoftirqd/2]
root        25  0.0  0.0      0     0 ?        S     2024   0:00 [cpuhp/3]
root        26  0.0  0.0      0     0 ?        S     2024   0:03 [migration/3]
root        27  0.0  0.0      0     0 ?        S     2024   2:15 [ksoftirqd/3]
root        30  0.0  0.0      0     0 ?        S     2024   0:00 [kdevtmpfs]
root        31  0.0  0.0      0     0 ?        I<    2024   0:00 [netns]
root        34  0.0  0.0      0     0 ?        S     2024   0:00 [kauditd]
root        36  0.0  0.0      0     0 ?        S     2024   0:08 [khungtaskd]
root        37  0.0  0.0      0     0 ?        S     2024   0:00 [oom_reaper]
root        38  0.0  0.0      0     0 ?        I<    2024   0:00 [writeback]
root        39  0.0  0.0      0     0 ?        S     2024  12:24 [kcompactd0]
root        59  0.0  0.0      0     0 ?        I<    2024   0:00 [kblockd]
root        60  0.0  0.0      0     0 ?        I<    2024   0:00 [blkcg_punt_bio]
root        61  0.0  0.0      0     0 ?        S     2024   0:00 [watchdogd]
root        64  0.0  0.0      0     0 ?        I<    2024   0:00 [rpciod]
root        65  0.0  0.0      0     0 ?        I<    2024   0:00 [kworker/u9:0-hci0]
root        66  0.0  0.0      0     0 ?        I<    2024   0:00 [xprtiod]
root        67  0.0  0.0      0     0 ?        S     2024   3:21 [kswapd0]
root        68  0.0  0.0      0     0 ?        I<    2024   0:00 [nfsiod]
root        69  0.0  0.0      0     0 ?        I<    2024   0:00 [kthrotld]
root        70  0.0  0.0      0     0 ?        I<    2024   0:00 [iscsi_eh]
root        71  0.0  0.0      0     0 ?        I<    2024   0:00 [iscsi_destroy]
root        72  0.0  0.0      0     0 ?        I<    2024   0:00 [nvme-wq]
root        73  0.0  0.0      0     0 ?        I<    2024   0:00 [nvme-reset-wq]
root        74  0.0  0.0      0     0 ?        I<    2024   0:00 [nvme-delete-wq]
root        78  0.0  0.0      0     0 ?        I<    2024   0:00 [DWC Notificatio]
root        79  0.0  0.0      0     0 ?        I<    2024   0:00 [uas]
root        80  0.0  0.0      0     0 ?        S<    2024   0:00 [vchiq-slot/0]
root        81  0.0  0.0      0     0 ?        S<    2024   0:00 [vchiq-recy/0]
root        82  0.0  0.0      0     0 ?        S<    2024   0:00 [vchiq-sync/0]
root        83  0.0  0.0      0     0 ?        I<    2024   0:00 [zswap-shrink]
root        87  0.0  0.0      0     0 ?        I<    2024   0:00 [sdhci]
root        88  0.0  0.0      0     0 ?        S     2024   0:00 [irq/47-mmc0]
root        90  0.0  0.0      0     0 ?        I<    2024   0:00 [mmc_complete]
root        92  0.0  0.0      0     0 ?        S     2024   7:42 [jbd2/mmcblk0p2-]
root        93  0.0  0.0      0     0 ?        I<    2024   0:00 [ext4-rsv-conver]
root        95  0.0  0.0      0     0 ?        S     2024   0:00 [scsi_eh_0]
root        96  0.0  0.0      0     0 ?        I<    2024   0:00 [scsi_tmf_0]
root        97  0.0  0.0      0     0 ?        S     2024   2:43 [usb-storage]
root        98  0.0  0.0      0     0 ?        I<    2024   0:00 [ipv6_addrconf]
root       130  0.0  0.5  45988 20092 ?        Ss    2024  10:10 /lib/systemd/systemd-journald
root       160  0.0  0.0  18604  3844 ?        Ss    2024   0:20 /lib/systemd/systemd-udevd
root       194  0.0  0.0      0     0 ?        S     2024   0:00 [vchiq-keep/0]
root       195  0.0  0.0      0     0 ?        S<    2024   0:00 [SMIO]
root       201  0.0  0.0      0     0 ?        I<    2024   0:00 [mmal-vchiq]
root       206  0.0  0.0      0     0 ?        I<    2024   0:00 [mmal-vchiq]
root       208  0.0  0.0      0     0 ?        I<    2024   0:00 [mmal-vchiq]
root       211  0.0  0.0      0     0 ?        I<    2024   0:00 [mmal-vchiq]
root       215  0.0  0.0      0     0 ?        I<    2024   0:00 [mmal-vchiq]
root       230  0.0  0.0      0     0 ?        I<    2024   0:00 [cfg80211]
root       238  0.0  0.0      0     0 ?        I<    2024   0:00 [brcmf_wq/mmc1:0]
root       241  0.0  0.0      0     0 ?        S     2024   2:47 [brcmf_wdog/mmc1]
root       247  0.0  0.0      0     0 ?        S     2024  57:59 [v3d_bin]
root       249  0.0  0.0      0     0 ?        S     2024  89:28 [v3d_render]
root       252  0.0  0.0      0     0 ?        S     2024   0:00 [v3d_tfu]
root       253  0.0  0.0      0     0 ?        S     2024   0:00 [v3d_csd]
root       256  0.0  0.0      0     0 ?        S     2024   0:00 [v3d_cache_clean]
root       276  0.0  0.0      0     0 ?        S     2024   0:00 [card1-crtc0]
systemd+   340  0.0  0.1  22384  5436 ?        Ssl   2024   0:29 /lib/systemd/systemd-timesyncd
root       356  0.0  0.0   4264  2960 ?        Ss    2024  52:29 /sbin/mount.ntfs-3g /dev/sda1 /media/usbdisk2t -o rw,nosuid,nodev,uid=1001,gid=1001,user,exec
root       375  0.0  0.0  25500  3836 ?        Ssl   2024   1:43 /usr/sbin/rsyslogd -n -iNONE
root       376  0.0  0.2  63320  8888 ?        Ssl   2024   1:29 /usr/lib/udisks2/udisksd
root       378  0.0  0.1  11720  4604 ?        SNs   2024   0:03 /usr/sbin/alsactl -E HOME=/run/alsa -s -n 19 -c rdaemon
message+   379  0.0  0.0   6956  3728 ?        Ss    2024  22:16 /usr/bin/dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only
root       381  0.0  0.0  10712  3656 ?        Ss    2024   0:59 /sbin/wpa_supplicant -u -s -O /run/wpa_supplicant
avahi      395  0.0  0.0   5896  2956 ?        Ss    2024   9:10 avahi-daemon: running [rpi4bmedia.local]
nobody     397  0.0  0.0   4316  2000 ?        Ss    2024   1:37 /usr/sbin/thd --triggers /etc/triggerhappy/triggers.d/ --socket /run/thd.socket --user nobody --deviceglob /dev/input/event*
root       404  0.0  0.1  13124  5812 ?        Ss    2024   9:43 /lib/systemd/systemd-logind
avahi      422  0.0  0.0   5764   220 ?        S     2024   0:00 avahi-daemon: chroot helper
root       477  0.0  0.0   2132    48 ?        S     2024   0:00 /usr/bin/hciattach /dev/serial1 bcm43xx 3000000 flow -
root       479  0.0  0.0      0     0 ?        I<    2024   0:00 [kworker/u9:2-hci0]
colord     489  0.0  0.2  43552  9900 ?        Ssl   2024   0:00 /usr/lib/colord/colord
root       490  0.0  0.1  39028  6676 ?        Ssl   2024   2:02 /usr/lib/policykit-1/polkitd --no-debug
root       513  0.0  0.0   9524  2980 ?        Ss    2024   0:00 /usr/lib/bluetooth/bluetoothd
root       531  0.0  0.1  11224  4064 ?        Ss    2024   2:28 wpa_supplicant -B -c/etc/wpa_supplicant/wpa_supplicant.conf -iwlan0 -Dnl80211,wext
root       611  0.0  0.0   2900  1948 ?        Ss    2024   3:16 /sbin/dhcpcd -q -w
root       612  0.0  0.0   4452  2108 ?        Ss    2024   0:00 /usr/bin/vncserver-x11-serviced -fg
root       614  0.0  0.3 189100 12112 ?        Ss    2024  13:06 php-fpm: master process (/etc/php/7.3/fpm/php-fpm.conf)
mosquit+   616  0.0  0.1   8876  4260 ?        Ss    2024  74:50 /usr/sbin/mosquitto -c /etc/mosquitto/mosquitto.conf
root       622  0.0  0.2  27920  9432 ?        Ss    2024  83:46 /usr/sbin/nmbd --foreground --no-process-group
root       625  0.0  0.3  34228 13564 ?        Sl    2024  37:45 /usr/bin/vncserver-x11-core -service
root       636  0.0  0.0   5584  1972 ?        Ss    2024   0:00 /usr/sbin/vsftpd /etc/vsftpd.conf
root       638  0.0  0.0      0     0 ?        I<    2024   0:00 [cifsiod]
root       639  0.0  0.0      0     0 ?        I<    2024   0:00 [smb3decryptd]
root       640  0.0  0.0      0     0 ?        I<    2024   0:00 [cifsfileinfoput]
root       641  0.0  0.0      0     0 ?        I<    2024   0:00 [cifsoplockd]
root       642  0.0  0.0      0     0 ?        I<    2024   0:00 [cifs-dfscache]
root       644  0.0  0.0      0     0 ?        S     2024   2:06 [cifsd]
root       645  0.0  0.0      0     0 ?        S     2024   4:46 [cifsd]
root       653  0.0  0.1  10688  4780 ?        Ss    2024   1:25 /usr/sbin/sshd -D
root       670  0.0  0.1  51532  7552 ?        Ss    2024   0:00 nginx: master process /usr/sbin/nginx -g daemon on; master_process on;
www-data   685  0.0  0.2 189272 10352 ?        S     2024   0:03 php-fpm: pool www
www-data   686  0.0  0.2 189272 10404 ?        S     2024   0:03 php-fpm: pool www
gottsch    689  0.0  0.0   6032  2592 ?        Ss    2024   0:00 vncserver :1 -geometry 1280x1024 -depth 24
root       693  0.0  0.1  17160  5644 ?        S     2024   0:00 /usr/bin/Xvnc -rootHelper 1001 4
root       694  0.0  0.4  45016 16040 ?        Ss    2024   1:36 /usr/sbin/smbd --foreground --no-process-group
root       704  0.0  0.1  41240  5736 ?        S     2024   0:18 /usr/sbin/smbd --foreground --no-process-group
root       707  0.0  0.1  41244  5204 ?        S     2024   0:17 /usr/sbin/smbd --foreground --no-process-group
gottsch    718  0.0  0.0   6544  3332 ?        S     2024   0:00 /usr/bin/dbus-daemon --session --nofork --address=unix:path=/tmp/.vnc-1001/run/session-e832b31ca9ed46af/bus --nopidfile --nosyslog
gottsch    720  0.0  0.1 351656  6548 ?        Sl    2024   7:45 /usr/bin/pulseaudio --daemonize=no
gottsch    729  0.0  0.0   1936   408 ?        S     2024   0:00 /bin/sh /etc/vnc/xstartup
root       751  0.0  0.1  45004  6520 ?        S     2024   2:07 /usr/sbin/smbd --foreground --no-process-group
rtkit      761  0.0  0.0  23184  2332 ?        SNsl  2024   2:30 /usr/lib/rtkit/rtkit-daemon
gottsch    777  0.0  0.3  38320 14820 ?        S     2024   1:28 /usr/bin/vncserverui virtual 14
gottsch    786  0.0  0.2  50304 10416 ?        Sl    2024   0:00 /usr/bin/lxsession -s LXDE-pi -e LXDE
gottsch    800  0.0  0.3  27916 13924 ?        S     2024   0:09 /usr/bin/vncserverui -statusicon 5
root       818  0.0  0.0      0     0 ?        S     2024   4:46 [cifsd]
gottsch    820  0.0  0.0   4492  1188 ?        Ss    2024   0:54 /usr/bin/ssh-agent x-session-manager
root       834  0.0  0.0   3772  2276 ?        Ss    2024   1:12 /usr/sbin/cron -f
root       835  0.0  0.0  28676  1416 ?        SLsl  2024   2:42 /usr/sbin/rngd -r /dev/hwrng
root       846  0.0  0.1  37496  5476 ?        Ssl   2024   0:29 /usr/sbin/lightdm
gottsch    891  0.0  0.1  39232  5580 ?        Sl    2024   0:00 /usr/lib/gvfs/gvfsd
root       953  0.0  0.0   5616  2516 tty1     Ss    2024   0:00 /bin/login -f
gottsch    972  0.0  0.1  54504  4368 ?        Sl    2024   0:00 /usr/lib/gvfs/gvfsd-fuse /tmp/.vnc-1001/run/gvfs -f -o big_writes
gottsch   1026  0.0  0.3  57808 11932 ?        S     2024   0:00 openbox --config-file /home/gottsch/.config/openbox/lxde-pi-rc.xml
gottsch   1031  0.0  0.4  47408 18356 ?        Sl    2024   0:00 lxpolkit
gottsch   1057  0.0  0.6 153272 25108 ?        Sl    2024   3:17 pcmanfm --desktop --profile LXDE-pi
gottsch   1103  0.0  0.0   4492    92 ?        Ss    2024   0:00 /usr/bin/ssh-agent -s
root      1119  0.0  0.1   7308  3968 ?        S     2024   0:00 /usr/bin/vncagent service 15
gottsch   1154  0.0  0.6  41576 25664 ?        S     2024   0:00 /usr/bin/python3 /usr/share/system-config-printer/applet.py
Debian-+  1176  0.0  0.0  14364  2544 ?        Ss    2024   0:08 /usr/sbin/exim4 -bd -q30m
gottsch   1182  0.0  0.2 103956  8744 ?        Sl    2024   0:01 /usr/lib/gvfs/gvfs-udisks2-volume-monitor
gottsch   1198  0.0  0.1  26436  4372 ?        Sl    2024   0:00 /usr/lib/menu-cache/menu-cached /tmp/.vnc-1001/run/menu-cached-:1
gottsch   1221  0.0  0.0  35924  3716 ?        Sl    2024   0:00 /usr/lib/gvfs/gvfs-goa-volume-monitor
gottsch   1227  0.0  0.1  37492  4316 ?        Sl    2024   0:00 /usr/lib/gvfs/gvfs-gphoto2-volume-monitor
gottsch   1232  0.0  0.1  51976  6360 ?        Sl    2024   0:01 /usr/lib/gvfs/gvfs-afc-volume-monitor
gottsch   1238  0.0  0.1  35924  3948 ?        Sl    2024   0:00 /usr/lib/gvfs/gvfs-mtp-volume-monitor
gottsch   1246  0.0  0.1  48888  6396 ?        Sl    2024   0:01 /usr/lib/gvfs/gvfsd-trash --spawner :1.4 /org/gtk/gvfs/exec_spaw/0
gottsch   1257  0.0  0.0  26800  3748 ?        Sl    2024   0:00 /usr/lib/gvfs/gvfsd-metadata
root      1265  0.0  0.1  29900  5676 ?        Sl    2024   0:01 lightdm --session-child 14 17
gottsch   1270  0.0  0.1  14700  7368 ?        Ss    2024   0:00 /lib/systemd/systemd --user
gottsch   1271  0.0  0.0  16960  2156 ?        S     2024   0:00 (sd-pam)
gottsch   1281  0.0  0.2  50392 10312 ?        Ssl   2024   0:00 /usr/bin/lxsession -s LXDE-pi -e LXDE
gottsch   1289  0.0  0.0   6544  2856 ?        Ss    2024   0:00 /usr/bin/dbus-daemon --session --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only
gottsch   1315  0.0  0.0   4492    88 ?        Ss    2024   0:54 /usr/bin/ssh-agent x-session-manager
gottsch   1326  0.0  0.1  39232  5540 ?        Ssl   2024   0:00 /usr/lib/gvfs/gvfsd
gottsch   1331  0.0  0.1  53480  4708 ?        Sl    2024   0:00 /usr/lib/gvfs/gvfsd-fuse /run/user/1001/gvfs -f -o big_writes
gottsch   1340  0.0  0.2  57304 11320 ?        S     2024   0:00 openbox --config-file /home/gottsch/.config/openbox/lxde-pi-rc.xml
gottsch   1342  0.0  0.2  42956 10016 ?        Sl    2024   1:16 lxpolkit
gottsch   1346  0.0  0.5 120372 22868 ?        Sl    2024   0:00 pcmanfm --desktop --profile LXDE-pi
gottsch   1353  0.0  0.0   4492    92 ?        Ss    2024   0:00 /usr/bin/ssh-agent -s
gottsch   1357  0.0  0.0   4868   996 ?        S     2024   0:00 xcompmgr -aR
gottsch   1369  0.0  0.6  41576 25960 ?        S     2024   0:00 /usr/bin/python3 /usr/share/system-config-printer/applet.py
gottsch   1374  0.0  0.2 363604  8608 ?        S
ddclient in /var/log/daemon.log

/var/log/nginx/access.log
3.15.214.230 - - [02/Feb/2025:00:03:09 -0800] "GET /rpi/rpi_speed/rpi_speed.php HTTP/1.1" 200 376 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)"
45.125.66.35 - - [02/Feb/2025:00:04:05 -0800] "GET /.git/HEAD HTTP/1.1" 404 169 "-" "Python-urllib/3.9"
54.36.148.109 - - [02/Feb/2025:00:05:27 -0800] "GET /robots.txt HTTP/1.1" 200 26 "-" "Mozilla/5.0 (compatible; AhrefsBot/7.0; +http://ahrefs.com/robot/)"
51.222.253.17 - - [02/Feb/2025:00:05:29 -0800] "GET /CCD_Galery/ic2177_asi2600mc.html HTTP/1.1" 200 844 "-" "Mozilla/5.0 (compatible; AhrefsBot/7.0; +http://ahrefs.com/robot/)"

/var/log/nginx/error.log

/var/log/syslog

Failed root login attempts