LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-10-2012, 05:04 PM   #1
kitek
Member
 
Registered: Apr 2005
Posts: 252

Rep: Reputation: 15
Looking for malware on apache


I have centos 6 and I was notified by some users that avast antivirus detects my website as malicious. I started investigating and after going through many tools and link scanners including google and everything checks fine. So I decided to install avast myself on my machine and see what it does for myself. Sure enough no matter what website or link I use on that web server which I host multiple sites on, avast blocks it and says it is malicious even instead of using a url used the servers direct ip address which you get the default apache page. /var/www/html is empty. I created a file and just put test in it. Same problem. Is it apache itself? I am kind of lost on what to do here...
 
Old 07-10-2012, 05:34 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Keeping in mind ninety nine percent of AV SW only targets Certain Other Platforms, what does its log say / your users report? Please be as verbose as possible and test from a remote location as well.
 
Old 07-10-2012, 05:43 PM   #3
kitek
Member
 
Registered: Apr 2005
Posts: 252

Original Poster
Rep: Reputation: 15
Quote:
Originally Posted by unSpawn View Post
Keeping in mind ninety nine percent of AV SW only targets Certain Other Platforms, what does its log say / your users report? Please be as verbose as possible and test from a remote location as well.
That is kind of my problem. This dumb AV just blocks the connection. Meaning the web browsers just does a "connection was reset" and the software says threat has been detected. pop up box "Malicious URL Block" object: hxxp://www.spraticnet.com/ infection: URL:Mal Process c:\Program Files(x86..//blah to fire fox. It does this with any web browsers. There isn't anything in Avast's logs either. It is almost as if it is programmed to just say that when trying to visit that site. There is one of the sites right there. Also the server is over 1k miles away so I am pretty much remote

Last edited by kitek; 07-10-2012 at 05:44 PM.
 
Old 07-11-2012, 08:45 AM   #4
kitek
Member
 
Registered: Apr 2005
Posts: 252

Original Poster
Rep: Reputation: 15
This has been resolved. After contacting the Avast.com the maker of the AV software. This is a rented dedicated server and at some point they, had blocked the ip and now they have cleared it up for me.

Thanks.
 
Old 08-29-2012, 03:23 AM   #5
sampride
LQ Newbie
 
Registered: Aug 2012
Posts: 1

Rep: Reputation: Disabled
Hi, do you know how they solved your problem? We are having the same issue and clueless up to this point.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
What to do with found Malware? lezazouz Linux - Security 5 08-07-2011 07:34 AM
Could this be iPhone *malware?* sundialsvcs General 2 07-15-2011 09:00 PM
[SOLVED] May have contracted malware. Yes, malware. Firefox on Ubuntu Fiesty. Seeking a fix drachenchen Linux - Security 22 08-17-2008 01:05 PM
May have contracted malware. Yes, malware. Firefox on Ubuntu Fiesty. Seeking a fix drachenchen Linux - Security 1 06-12-2008 05:10 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:23 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration