Skip to main content

http being hijacked

Comments

6 comments

  • quizknows
    ModSecurity, or Mod DumpIO can be used to log egress http traffic, but I'm unsure if the infection would break that. See [url=http://blogs.cisco.com/security/linuxcdorked-faqs]Linux/CDorked FAQs or [url=http://www.welivesecurity.com/2013/04/26/linuxcdorked-new-apache-backdoor-in-the-wild-serves-blackhole/]Linux/Cdorked.A - A new Apache backdoor is being used in the wild to serve Blackhole
    0
  • noimad1
    Thanks for the info, I'll look at mod DumpIO to see what that does. I had already tested for the CDorked on this server, but the memory came back clean, and there doesn't seem to be any trace of it. Not to say that it isn't a variation of it?
    0
  • quizknows
    I've heard there's a new variation on it but I haven't had time to investigate it. DumpIO is pretty nice, though your logs will be absolutely massive. Obviously only use it for debugging.
    0
  • cPanelMichael
    Hello :) For reference, there is a similar thread here (user mentions only 25% of traffic redirected): Questions about hacked server Thank you.
    0
  • noimad1
    Yea, that was the first server that was compromised. We moved that client to a new server. Right now I'm just trying to confirm if this server is for sure compromised. Do you think something like snort would pick up this malicious code being added to the sites?
    0
  • quizknows
    Snort could probably do it if you can get any data to make a signature from. Maybe the emerging threats rules could pick it up.
    0

Please sign in to leave a comment.