Slashdot Mirror


Backdoor Targeting Apache Servers Spreads To Nginx, Lighttpd

An anonymous reader writes "Last week's revelation of the existence of Linux/Cdorked.A, a highly advanced and stealthy Apache backdoor used to drive traffic from legitimate compromised sites to malicious websites carrying Blackhole exploit packs, was only the beginning — ESET's continuing investigation has now revealed that the backdoor also infects sites running the nginx and Lighttpd webservers. Researchers have, so far, detected more than 400 webservers infected with the backdoor, and 50 of them are among the world's most popular and visited websites." Here's the researchers' original report.

7 of 136 comments (clear)

  1. Re:Why? by Skapare · · Score: 3, Funny

    Are you afraid of little infected web site? Something wrong with your browser?

    --
    now we need to go OSS in diesel cars
  2. Fix by Frankie70 · · Score: 5, Funny

    You can download a fix here.

    1. Re:Fix by Anonymous Coward · · Score: 1, Funny

      Yes, indeed. Why suffer from this minor malware when you could have all the best ones infecting you? Lightweights!

  3. screw it by clam666 · · Score: 4, Funny

    I knew this was a mistake. Secure my ass. I'm going back to Windows.

    --
    I'm a satanic clam.
  4. Re:and this is why.... by Anonymous Coward · · Score: 5, Funny

    FreeBSD runs the same software stack, so it would make little difference.

    That's why our organization uses a custom server software written in 68K assembly running on MacOS 7.6.1 on a cluster of Quadra 610s.

  5. Re:Why? by Opportunist · · Score: 3, Funny

    Find out what they're experts in, become a complete idiot in that field and start pestering them with requests for help.

    Keeps my dad away. Though I now have to pay for repairs when my car breaks down.

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  6. Re:I have a stupid question. by Zontar+The+Mindless · · Score: 5, Funny

    What kind of developer thinks that a web server needs a GUI?

    Where else are they going to put the ON and OFF buttons?

    --
    Il n'y a pas de Planet B.