Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 10-26-2011, 10:49 AM   #1
biskoppen
Confirmed User
 
Join Date: Mar 2003
Location: Very small penis
Posts: 5,809
Server brains : what software can scan an apache server for installed exploits and stuff?

If I wanted all my configuation files, htaccess'es .. php files.. etc .. scanned for exploits and vira's installered by dirty russians.. what do I wanna use for this?
__________________
Submit my videos to make bank, tons of 5 minute videos offered right here
biskoppen is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-26-2011, 11:00 AM   #2
blazin
Confirmed User
 
Join Date: Aug 2002
Posts: 2,781
At my old company we used to use Clam... http://www.clamav.net/lang/en/
__________________
I don't endorse a god damn thing......
blazin is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-26-2011, 11:20 AM   #3
signupdamnit
Confirmed User
 
signupdamnit's Avatar
 
Industry Role:
Join Date: Aug 2007
Posts: 6,697
If you're making $200,000 a year with those servers then you should throw a decent guy $100-$200 a month ($1,200 to $2,400 a year) to come in and handle these things for you every now and then. Otherwise you're asking for trouble and being pennywise and pound foolish. One day of downtime due to an unnecessary incident and you'll lose more than you would pay the admin for a full year.

Last edited by signupdamnit; 10-26-2011 at 11:23 AM..
signupdamnit is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-26-2011, 11:26 AM   #4
Shedevils
Confirmed User
 
Shedevils's Avatar
 
Industry Role:
Join Date: Jun 2010
Posts: 498
We recently did some scans with clamscan on a server that we had found php backdoors and it did not detect them.

Really you are going to have to hand check for php backdoors. And lock it all down with only a few IP's able to use ssh or sftp.
Shedevils is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-26-2011, 11:28 AM   #5
Klen
 
Klen's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
Quote:
Originally Posted by Shedevils View Post
We recently did some scans with clamscan on a server that we had found php backdoors and it did not detect them.

Really you are going to have to hand check for php backdoors. And lock it all down with only a few IP's able to use ssh or sftp.
Yes i would agree with that,i also used some two specialized scanners and they didn't found anything.
Klen is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-30-2011, 11:20 PM   #6
ifapdb
Registered User
 
Industry Role:
Join Date: Sep 2011
Posts: 1
No quick way really, but if you have a bunch of php exploits - probably best to start over and move files over in batches making sure permissions are correct.

Check any user uploadable files to see if they are really what they're supposed to be. Jpg, gif, png etc. Exploitable .htaccess can make those files executable.

grep for common php exploit methods (exec/system/decode/chmod/mkdir/etc.)

You should then "train" clamav for any of the patterns you find for future scans.

All assuming they came in through bad scripts, if it's via shell/ftp, all bets are off.
ifapdb is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-30-2011, 11:24 PM   #7
marlboroack
So Fucking Banned
 
Industry Role:
Join Date: Jul 2010
Location: ☣
Posts: 9,327
Quote:
Originally Posted by signupdamnit View Post
If you're making $200,000 a year with those servers then you should throw a decent guy $100-$200 a month ($1,200 to $2,400 a year) to come in and handle these things for you every now and then. Otherwise you're asking for trouble and being pennywise and pound foolish. One day of downtime due to an unnecessary incident and you'll lose more than you would pay the admin for a full year.

I agree with what he said. I actually know a few people who you can hire to do this.
marlboroack is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-30-2011, 11:31 PM   #8
dubsix
Confirmed User
 
Industry Role:
Join Date: Dec 2004
Posts: 363
run these and you'll be covered

http://www.ossec.net/
http://www.rfxn.com/projects/linux-malware-detect/
dubsix is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-31-2011, 12:55 AM   #9
vdbucks
Monger Cash
 
Industry Role:
Join Date: Jul 2010
Posts: 2,773
proper security, permissions and common sense will save you 99.9% of the time as opposed to relying on a piece of software to cover your ass.

As stated above though.. seriously, if you're making 200k+ a year then hire someone who knows wtf they're doing.. no 5 minute lesson on server security via gfy is going to do much to protect you in the end.
vdbucks is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-31-2011, 01:19 AM   #10
fris
Too lazy to set a custom title
 
fris's Avatar
 
Industry Role:
Join Date: Aug 2002
Posts: 55,304
nmap and nessus
__________________
Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence.


WP Stuff
fris is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-31-2011, 02:43 AM   #11
AdultEUhost
ORLY?
 
AdultEUhost's Avatar
 
Industry Role:
Join Date: Oct 2005
Location: NL & US
Posts: 2,579
install rkhunter as well !
__________________
ICQ: 267-443-722 / leon [at] adulteuhost [dotcom]

Nominated for an XBIZ Award as "Webhost of the Year" in 2007, 2012, 2013 and 2014
AdultEUhost is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-31-2011, 04:41 AM   #12
raymor
Confirmed User
 
Join Date: Oct 2002
Posts: 3,745
I actually just "finished" a new tool chain that finds a heck of a lot more than clam does. Clam is mainly for detecting Windows virises in email. On the server we just did, Clam found two files. Our tools and process found over seven hundred.
It's pretty in depth. For example, bad guys will hide a hack script in a folder full of jpeg files and name the shell "bonnie2.jpg" or whatever, so we have a tool which opens every supposed image and makes sure it really is an image.

There's still quite a bit of process involved - it's not a fully automated tool. Therefore at this point it's an in house tool we can use to take care of it for you.
__________________
For historical display only. This information is not current:
support@bettercgi.com ICQ 7208627
Strongbox - The next generation in site security
Throttlebox - The next generation in bandwidth control
Clonebox - Backup and disaster recovery on steroids
raymor is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-31-2011, 04:44 AM   #13
raymor
Confirmed User
 
Join Date: Oct 2002
Posts: 3,745
Btw a lot of what was said we agree with, like grepping for exec, popen, etc. We've just developed a procedure and tools to do the things suggested in an organized and efficient way. Our overall rule os that every file is suspicious until we prove it's ok.
raymor is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-31-2011, 07:53 AM   #14
fris
Too lazy to set a custom title
 
fris's Avatar
 
Industry Role:
Join Date: Aug 2002
Posts: 55,304
as always keep your software updated with latest php, mysql, apache
__________________
Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence.


WP Stuff
fris is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.