LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-28-2012, 05:41 AM   #1
dinakumar12
Member
 
Registered: Mar 2010
Location: INDIA (chennai)
Distribution: centos
Posts: 271
Blog Entries: 7

Rep: Reputation: 18
phishing attack on myserver


Hi all,

A php application in my server got phishing attack.I found many new files inside that application folder.

I dont know how this hack had been happened.We dont have ftp access for that application.

Can any one please explain me how the hacker would have uploaded these files in to my application.

And how to get rid of this.At present i have stopped my application.

Your suggestions please.
 
Click here to see the post LQ members have rated as the most helpful post in this thread.
Old 01-28-2012, 06:23 AM   #2
eeekster
Member
 
Registered: Sep 2011
Posts: 163

Rep: Reputation: Disabled
Quote:
Originally Posted by dinakumar12 View Post
Can any one please explain me how the hacker would have uploaded these files in to my application.
I don't think anybody can explain it without more infomation.
 
Old 01-28-2012, 06:28 AM   #3
dinakumar12
Member
 
Registered: Mar 2010
Location: INDIA (chennai)
Distribution: centos
Posts: 271

Original Poster
Blog Entries: 7

Rep: Reputation: 18
Hi,

What are the information i need to provide.I am ready to share.
 
Old 01-28-2012, 07:31 AM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by eeekster View Post
I don't think anybody can explain it without more infomation.
In this forum members post about problems that may or may not be security issues. These members are often new to Linux and may need more than the average amount of guidance. I ask you to reply not "just because you can" but only if you really want to help. Troubleshooting will be more efficient if you have (and will provide) a rudimentary understanding of Linux security and can anticipate the OPs questions.


Quote:
Originally Posted by dinakumar12 View Post
A php application in my server got phishing attack.
Where is the server located (home, work, colocation)? Is it shared or a VPS? Is it yours (root access)?
What is the name of the application?
If it's not homebrewn software, which version exactly?
Was it installed correctly? (No setup files left, proper access permissions)
Was it publicly accessible? (HTTPS vs HTTP, .htaccess or other access restrictions)


Quote:
Originally Posted by dinakumar12 View Post
I found many new files inside that application folder.
Which files? (Post list from running '/bin/ls --time-style=long-iso --quoting-style=c -altr /path/to/files;' as root.)
Do any of the web servers logs reference files found or show odd entries (often multiple lines) involving (output of) GET, curl, wget or other wget-like applications?
Do any of the web servers logs show other anomalies around the times the files were placed?


Quote:
Originally Posted by dinakumar12 View Post
how to get rid of this. At present i have stopped my application.
If you can not confirm downloading is due to one specific application it would be best to stop the web server for the duration of the investigation.
Please confirm no other problems have arisen before, during and after file placement. If unsure which steps to follow please use this checklist:
Intruder Detection Checklist (CERT): http://web.archive.org/web/200801092...checklist.html
Please post back the results if any.

* Please stay with the thread (subscribe?) until completion and reply as soon as possible when replies are posted.
 
2 members found this post helpful.
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] nslookup answer ns.myserver.myserver.com windstory Linux - Newbie 2 05-14-2010 12:54 AM
nfs:server myserver not responding still trying fcfury Linux - Newbie 1 05-08-2009 08:00 AM
Linux Phishing Attack Circulates on Net (from e-security) webwolf70 Linux - Security 3 11-22-2004 09:54 AM
the operation timed out when attempting to contact myserver:8080 sanw2k Linux - Networking 1 06-09-2003 07:50 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:49 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration