Restrict session to IP 


Global Rank: 17
Totalscore: 431153
Posts: 40
Thanks: 36
UpVotes: 22
Registered: 16y 25d

The User is Offline
Google/translate0Thank You!0Good Post!1Bad Post! link
Assuming I run a server which hosts ~200 websites. I know for sure that one is infected with a botnet. Can any of you think of a suitable way of detecting that particular site without having to analyze each website's source code ?
Global Rank: 202
Totalscore: 101894
Posts: 65
Thanks: 67
UpVotes: 44
Registered: 16y 47d
xen`s Avatar

The User is Offline
RE: Botnet
Google/translate0Thank You!0Good Post!0Bad Post! link
"infected with a botnet" could you expand on this more?
do you mean the website is running as part of the botnet,,,,
or it propagates the malware to spread the botnet?

if as part then could you listen for patterns with input/output? e.g. botnet C&C sends instructions and address/ip range, the site then acts on that.
chmod ---x--x--x,, i'm illiterate!
Global Rank: 543
Totalscore: 47147
Posts: 37
Thanks: 21
UpVotes: 24
Registered: 12y 152d
stormsurfer`s Avatar

Last Seen: 7y 263d
The User is Offline
RE: Botnet
Google/translate0Thank You!0Good Post!0Bad Post! link
yeah, "infected by botnet" needs further explenation.

anywhy, if it's a script, you can find /home/*/public_html -type f -exec grep -H <something> {} \;
or if it's actualy connecting to the net, using lsof you can cross reference ports with full path names of files.
tunelko, stormsurfer, quangntenemy, TheHiveMind, Z, balicocat, Ge0, samuraiblanco, arraez, jcquinterov, hophuocthinh, alfamen2, burhanudinn123, Ben_Dover, stephanduran89, braddie0, SwolloW, dangarbri, csuquvq have subscribed to this thread and receive emails on new posts.
1 people are watching the thread at the moment.
This thread has been viewed 4167 times.