Solved

Webserver being used as a Proxy

Posted on 2004-08-09
2
196 Views
Last Modified: 2010-03-04
One of our Client's has a webserver that runs on Mandrake and is using Apache. I am not a Linux guru but I can navigate my way around. I did figure out that the server was being used as a proxy by looking in the httpd/error_log. There are Proxy errors in there and you can see where someone is trying hack some yahoo logins. Or they are logging in on them.

My situation is that our Linux guru is on the road and will not be available to look at it for several hours. We have shut off the IP's that they were coming in through. So my question is two-fold. One, how do I find out what version of Apache they are using. I am guessing that it was a vulnerability there that is the issue. Two, has anyone else seen this before and do you know what service might be used for the proxy? SSH and HTTP/S were all open.
0
Comment
Question by:kevinlw1974
2 Comments
 
LVL 9

Accepted Solution

by:
ronan_40060 earned 500 total points
ID: 11761603
Hello kevin
In linux  to find out the version of apache that you have installed
go to the bin directory of apche on your OS once your in there
i.i /usr/local/apache/bin
type ./httpd -v

you should see the version of apache installed

good luck
ronan
0
 

Author Comment

by:kevinlw1974
ID: 11763019
Thanks, we were able to track down the issue even further. But you staill answered my question so you get credit :)

The issue is that Mandrake had the mod_perl running with Apache and I guess an Apache vulnerability was exploited. They had a perl proxy running some bots.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

As Wikipedia explains 'robots.txt' as -- the robot exclusion standard, also known as the Robots Exclusion Protocol or robots.txt protocol, is a convention to prevent cooperating web spiders and other web robots from accessing all or part of a websit…
Over the last year I have answered a couple of basic URL rewriting questions several times so I thought I might as well have a stab at: explaining the basics, providing a few useful links and consolidating some of the most common queries into a sing…
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…
In a recent question (https://www.experts-exchange.com/questions/29004105/Run-AutoHotkey-script-directly-from-Notepad.html) here at Experts Exchange, a member asked how to run an AutoHotkey script (.AHK) directly from Notepad++ (aka NPP). This video…

808 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question