Slashdot Mirror


Backdoor Targeting Apache Servers Spreads To Nginx, Lighttpd

An anonymous reader writes "Last week's revelation of the existence of Linux/Cdorked.A, a highly advanced and stealthy Apache backdoor used to drive traffic from legitimate compromised sites to malicious websites carrying Blackhole exploit packs, was only the beginning — ESET's continuing investigation has now revealed that the backdoor also infects sites running the nginx and Lighttpd webservers. Researchers have, so far, detected more than 400 webservers infected with the backdoor, and 50 of them are among the world's most popular and visited websites." Here's the researchers' original report.

3 of 136 comments (clear)

  1. Fix by Frankie70 · · Score: 5, Funny

    You can download a fix here.

  2. Re:and this is why.... by Anonymous Coward · · Score: 5, Funny

    FreeBSD runs the same software stack, so it would make little difference.

    That's why our organization uses a custom server software written in 68K assembly running on MacOS 7.6.1 on a cluster of Quadra 610s.

  3. Re:I have a stupid question. by Zontar+The+Mindless · · Score: 5, Funny

    What kind of developer thinks that a web server needs a GUI?

    Where else are they going to put the ON and OFF buttons?

    --
    Il n'y a pas de Planet B.