On 04/30/2013 11:34 AM, andrew mcelroy wrote:
Hey all,
Not sure how many of you are aware of this malware floating around in
the linux space.

http://arstechnica.com/security/2013/04/admin-beware-attack-hitting-apache-websites-is-invisible-to-the-naked-eye/

Here is another article from eSET:

http://www.welivesecurity.com/2013/04/26/linuxcdorked-new-apache-backdoor-in-the-wild-serves-blackhole/


Here is a python script to see if your server is running this nasty
backdoor code.
If you don't trust a random binary off the internet ( and you shouldn't).
http://www.welivesecurity.com/wp-content/uploads/2013/04/dump_cdorked_config.7z

At the end of the second article is a python script you can look over
and run.

It's estimated that at least 20,000 websites (minimum) have been hit
with this so far.
News about this only broke friday apparently.

Respectfully,
Andrew McElroy

--

Thank you very much for this alert, Andrew. I copied down the python script and attempted to run. I get:

    shmid = shmget(SHM_KEY, SHM_SIZE, 0o666)
                                          ^
SyntaxError: invalid syntax


Howard, je ne parle pas python, White

--
--
You received this message because you are subscribed to the Google Groups 
"NLUG" group.
To post to this group, send email to [email protected]
To unsubscribe from this group, send email to 
[email protected]
For more options, visit this group at 
http://groups.google.com/group/nlug-talk?hl=en

--- You received this message because you are subscribed to the Google Groups "NLUG" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/groups/opt_out.


Reply via email to