apache web server compromised and backdoor

From: Giovanni (gcasanoNOSPAM_at_freemail.it)
Date: 12/19/03

  • Next message: Alessandro Selli: "Re: apache web server compromised and backdoor"
    Date: Fri, 19 Dec 2003 10:14:31 GMT
    
    

    hi all,

    one of my web servers was compromised by hacker intrusion.

    today, while upgrading the apache from 1.3.27 to 1.3.29, a strange thing
    happened:

    - I stopped the old apache server;
    - I tried to start the new apache but I have got the following:
    "unable to bind (...) port already in use"

    so after I realize port 80 was really in use, I tried "ps -ef" and discovered
    a process called "./f".

    I tried to telnet to my server's port 80 and I've got a prompt waiting for
    something, susch as a password.

    I have killed that process and, finally, I was able to start the apache.

    My question his: how do i find the file on the hd which spawned that
    backdoor?

    I am trying "find -ctime 2 (...)" but I am not confident it will work.

    did you know which exploit/backdoor/whatever was used to break into my
    server?

    thanks in advance,

    -- 
    giovanni casano
    

  • Next message: Alessandro Selli: "Re: apache web server compromised and backdoor"

    Relevant Pages

    • Hacker problem...Takes down apache?
      ... It seems to be doing *something* to break Apache in an attempt ... When connecting to port 80 on the web server with a web browser a "page ... However sockstat still shows httpd listening on port ...
      (freebsd-questions)
    • Re: still having problems contacting the apache server
      ... I think I have narrowed this down to a port issue is there a way to actually change the port with in Apache. ... Firefox can't establish a connection to the server at pilotalk.dyndns.biz. ...
      (Fedora)
    • Re: Rogue PHP file
      ... Of course none of them will admit to installing Apache ... used by another program" I ran netstat -ano and found Apache on port 80. ... are not running a public web server on your SBS (and you should NOT ...
      (microsoft.public.windows.server.sbs)
    • Re: Rogue PHP file
      ... Of course none of them will admit to installing Apache ... are not running a public web server on your SBS (and you should NOT ... then close port 80 to your SBS. ...
      (microsoft.public.windows.server.sbs)
    • Re: Rogue PHP file
      ... Of course none of them will admit to installing Apache ... another program" I ran netstat -ano and found Apache on port 80. ... are not running a public web server on your SBS, ... then close port 80 to your SBS. ...
      (microsoft.public.windows.server.sbs)

  • Quantcast