Advertisement

07.16.2008 at 09:21AM PDT, ID: 23570274
[x]
Attachment Details

How to remove suspicious Javascript prepended on files under a Linux Server?

Asked by code4design in Red Hat Linux, Apache Web Server, Linux Network Security

Tags: Red Hat, Enterprise Linux ES, Release 4 (Nahant Update 6), Its a web applications server

Hi, unfortunately our server www8.eonconnect.com seems to have been compromised with an exploit similar to this: http://blog.cpanel.net/?p=31
(even though it's not running cpanel, it seems similar)

For example if you run this at the commandline:
curl http://www8.eonconnect.com
you should get a blank html page page with no javascript (don't visit this with a browser)

But every 10th time or so, you get a malware script inserted at the top of the page.

Whatever it is, it hides itself well. If you run the following:
curl http://www8.eonconnect.com
from the server itself, you will get nothing unusual, it seems not to activate when accessed from its own ip.

But if from another machine you run that, you will get a javascript prepended, which loads a script from the domain wo94ni.cn . It seems to record ip addresses accessing it, so it will usually show the first time, and then you may have to rerun the curl command 10 or 20 times to see it again, and then after a certain number of times it will stop showing altogether for that client IP. We had 3 people in different locations spend a couple hours verifying this behavior yesterday.

In the article referenced or something linked from it, I read that it somehow loads itself into memory so that it can't be detected by checking for filesystem changes? Not sure how true that is, this is beyond my area of expertise. But we're sure that something is able to intermittently add a malicious javascript to web pages served from the server.

I installed 2 rootkit detectors, one called Rootkit HUnter and the other one Chrootkit, I'm attaching the log files if they are helpful at all.

Your help is really appreciated!
ThanksStart Free Trial
Attachments:
 
Rootkit Hunter Log details after check up
 
 
Ch Rootkit Log details after check up
 
 
Loading Advertisement...
 
[+][-]07.17.2008 at 09:52AM PDT, ID: 22027404

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07.17.2008 at 10:00AM PDT, ID: 22027471

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]07.17.2008 at 10:12AM PDT, ID: 22027619

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07.17.2008 at 10:39AM PDT, ID: 22027907

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]07.23.2008 at 11:12AM PDT, ID: 22072141

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]07.28.2008 at 02:31PM PDT, ID: 22106998

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: Red Hat Linux, Apache Web Server, Linux Network Security
Tags: Red Hat, Enterprise Linux ES, Release 4 (Nahant Update 6), Its a web applications server
Sign Up Now!
Solution Provided By: code4design
Participating Experts: 1
Solution Grade: A
 
 
 
Loading Advertisement...
20080716-EE-VQP-32 / EE_QW_2_20070628