LinuxQuestions.org

LinuxQuestions.org (/questions/)
-   Linux - Security (https://www.linuxquestions.org/questions/linux-security-4/)
-   -   Looking for malware on apache (https://www.linuxquestions.org/questions/linux-security-4/looking-for-malware-on-apache-4175415983/)

kitek 07-10-2012 05:04 PM

Looking for malware on apache
 
I have centos 6 and I was notified by some users that avast antivirus detects my website as malicious. I started investigating and after going through many tools and link scanners including google and everything checks fine. So I decided to install avast myself on my machine and see what it does for myself. Sure enough no matter what website or link I use on that web server which I host multiple sites on, avast blocks it and says it is malicious even instead of using a url used the servers direct ip address which you get the default apache page. /var/www/html is empty. I created a file and just put test in it. Same problem. Is it apache itself? I am kind of lost on what to do here...

unSpawn 07-10-2012 05:34 PM

Keeping in mind ninety nine percent of AV SW only targets Certain Other Platforms, what does its log say / your users report? Please be as verbose as possible and test from a remote location as well.

kitek 07-10-2012 05:43 PM

Quote:

Originally Posted by unSpawn (Post 4724376)
Keeping in mind ninety nine percent of AV SW only targets Certain Other Platforms, what does its log say / your users report? Please be as verbose as possible and test from a remote location as well.

That is kind of my problem. This dumb AV just blocks the connection. Meaning the web browsers just does a "connection was reset" and the software says threat has been detected. pop up box "Malicious URL Block" object: hxxp://www.spraticnet.com/ infection: URL:Mal Process c:\Program Files(x86..//blah to fire fox. It does this with any web browsers. There isn't anything in Avast's logs either. It is almost as if it is programmed to just say that when trying to visit that site. There is one of the sites right there. Also the server is over 1k miles away so I am pretty much remote ;)

kitek 07-11-2012 08:45 AM

This has been resolved. After contacting the Avast.com the maker of the AV software. This is a rented dedicated server and at some point they, had blocked the ip and now they have cleared it up for me.

Thanks.

sampride 08-29-2012 03:23 AM

Hi, do you know how they solved your problem? We are having the same issue and clueless up to this point.


All times are GMT -5. The time now is 04:06 AM.