LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-30-2011, 04:02 PM   #1
anon02
Member
 
Registered: Aug 2011
Posts: 223

Rep: Reputation: Disabled
Linux Virus?


Recently I was browsing the web on my netbook, and I clicked a link. It went to Encyclopedia Dramatica, and Epiphany said it downloaded a file called css.php. I thought this was just the website not set up correctly, but Geany opened the file. Since then, I deleted the file, ran chkrootkit, but I was wondering if anyone else knew about it.

I am using Ubuntu 11.04

Last edited by anon02; 09-30-2011 at 04:04 PM.
 
Old 09-30-2011, 04:28 PM   #2
MS3FGX
LQ Guru
 
Registered: Jan 2004
Location: NJ, USA
Distribution: Slackware, Debian
Posts: 5,852

Rep: Reputation: 361Reputation: 361Reputation: 361Reputation: 361
What makes you think it's a virus? More than likely just a poorly written website.

What did the css.php file contain?
 
Old 09-30-2011, 04:28 PM   #3
frieza
Senior Member
 
Registered: Feb 2002
Location: harvard, il
Distribution: Ubuntu 11.4,DD-WRT micro plus ssh,lfs-6.6,Fedora 15,Fedora 16
Posts: 3,233

Rep: Reputation: 406Reputation: 406Reputation: 406Reputation: 406Reputation: 406
it's probably just the website not set up correctly, php scripts can't run without a php interpreter even if you did manage to grab the code, and even so are unlikely to contain malicious payloads.
 
Old 10-01-2011, 12:29 AM   #4
anon02
Member
 
Registered: Aug 2011
Posts: 223

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by MS3FGX View Post
What makes you think it's a virus? More than likely just a poorly written website.

What did the css.php file contain?
Originally I was suspicious as Geany instantly opened it. When I get the PHP files off of my website to work on, it just saves them. It contained something like @FONTTYPE (Probably not FONTTYPE, something like it.) UTF-8


Quote:
Originally Posted by frieza View Post
it's probably just the website not set up correctly, php scripts can't run without a php interpreter even if you did manage to grab the code, and even so are unlikely to contain malicious payloads.
Thanks for the reassurance. I think now that is was just a badly written website.
 
Old 10-01-2011, 01:15 AM   #5
qlue
Member
 
Registered: Aug 2009
Location: Umzinto, South Africa
Distribution: Crunchbangified Debian 8 (Jessie)
Posts: 747
Blog Entries: 1

Rep: Reputation: 172Reputation: 172
There's is a 'trick' used by some website designers that use the 'include' function in php to create dynamic css code. (for example, a different theme according to time of day or the season)
It sounds like your browser downloaded this file instead and, because it didn't know what else to do with it, it simply passed it on to the system's default text editor. (geany on your system)
 
Old 10-01-2011, 02:10 AM   #6
anon02
Member
 
Registered: Aug 2011
Posts: 223

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by qlue View Post
There's is a 'trick' used by some website designers that use the 'include' function in php to create dynamic css code. (for example, a different theme according to time of day or the season)
It sounds like your browser downloaded this file instead and, because it didn't know what else to do with it, it simply passed it on to the system's default text editor. (geany on your system)
Ah, thanks for the explanation. Geany isn't my systems default text editor, but it is default for PHP, C, and C++ files. That explains it, I think.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Microsoft Virus Removal... (Virus Live CD) Nathan1993 Linux - Distributions 7 04-06-2011 06:55 PM
dual boot without anti-virus, virus now in linux gardner Linux - Security 7 03-09-2009 01:01 PM
Boot virus or Anti-Virus? AVG Free Anti-Virus Software problems SparceMatrix Linux - Security 9 08-02-2004 02:35 PM
trend chipway virus detected boot virus rafc Linux - Security 1 05-13-2004 01:44 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 02:09 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration