Quantcast
Channel: BOT24
Viewing all articles
Browse latest Browse all 8064

Server Compromises – Understanding Apache Module iFrame Injections and Secure Shell Backdoor

$
0
0

There are many ways to inject a malicious payload onto a website. The attacker can modify any of the web files (index.php for example), the .htaccess file or php.ini (if the site is using PHP). There are other ways, but those are the most common methods, specially on shared hosts.

However, for the last year, we started to see a new way to inject malware on compromised servers via a malicious Apache module. We posted about it before and it has been covered on many other mediums. After a few months of tracking them, and working on multiple servers that had this issue, we want to share a bit of what we have learned.

read more.........http://blog.sucuri.net/2013/01/server-side-iframe-injections-via-apache-modules-and-sshd-backdoor.html

Viewing all articles
Browse latest Browse all 8064

Trending Articles