Hey all, Not sure how many of you are aware of this malware floating around in the linux space.
http://arstechnica.com/security/2013/04/admin-beware-attack-hitting-apache-websites-is-invisible-to-the-naked-eye/ Here is another article from eSET: http://www.welivesecurity.com/2013/04/26/linuxcdorked-new-apache-backdoor-in-the-wild-serves-blackhole/ Here is a python script to see if your server is running this nasty backdoor code. If you don't trust a random binary off the internet ( and you shouldn't). http://www.welivesecurity.com/wp-content/uploads/2013/04/dump_cdorked_config.7z At the end of the second article is a python script you can look over and run. It's estimated that at least 20,000 websites (minimum) have been hit with this so far. News about this only broke friday apparently. Respectfully, Andrew McElroy -- -- You received this message because you are subscribed to the Google Groups "NLUG" group. To post to this group, send email to [email protected] To unsubscribe from this group, send email to [email protected] For more options, visit this group at http://groups.google.com/group/nlug-talk?hl=en --- You received this message because you are subscribed to the Google Groups "NLUG" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. For more options, visit https://groups.google.com/groups/opt_out.
