We use cookies to provide you with a better experience. If you continue to use this site, we'll assume you're happy with this. Alternatively, click here to find out how to manage these cookies

hide cookie message
80,259 News Articles

Apache web servers targeted by stealthy 'Cdorked' malware

Hard to spot in logs

Security researchers have discovered a new Apache web server backdoor that is so stealthy it leaves almost no trace of its redirection behaviour on the hard drive or in server log files.

According to an analysis by security firms ESET and Sucuri, spotting the Linux/Cdorked.A module will prove a challenge to even the most diligent web admin.

Unlike the majority of such malware, Cdorked writes no files to the server's hard drive, storing its configuration in a few megabytes of main memory that it happily shares with other processes.

No traces of command and control are left on the victim server thanks to the way it pushes its configuration through obfuscated HTTP that doesn't appear in logs.

"There are two ways the attacker can control the behaviour of the backdoored server: through a reverse connect shell or through special commands, all of them are triggered via HTTP requests," said ESET's Pierre-Marc Bureau.

The malware's purpose is mostly to serve the redirects to Blackhole Exploit Kit that currently dominates the threat landscape although it is well designed enough to avoid this behaviour if it detects it is being accessed by an admin interface.

Although small by Internet standards, ESET's engineers still estimate that hundreds of servers are affected which probably equates to thousands of websites co-opted to serve redirects.

Detecting and getting rid of it means either checking the integrity of the Apache package or, better still, looking at a memory dump to spot the malware's binary.

"We urge system administrators to check their servers and verify that they are not affected by this threat," said ESET.

ESET previously reported on Linux/Chapro.A, an attack aimed at Internet bank users, and the Snasko server rootkit.

As with these attacks, Cdorked is a reminder to apply all patches and that attackers are now aiming at vulnerable servers as a weakness.

IDG UK Sites

5 reasons Facebook Messenger is terrible, and 5 reasons it's great

IDG UK Sites

Samsung: King of the Androids (or MWC, at least)

IDG UK Sites

Inside Microsoft's universal platform for designing apps that work on PCs, tablets, phones, Xbox...

IDG UK Sites

How to watch Apple's 9 March 'Spring Forward' Apple Watch event live stream, and what to expect: Ap?......