Follow Us

We use cookies to provide you with a better experience. If you continue to use this site, we'll assume you're happy with this. Alternatively, click here to find out how to manage these cookies

hide cookie message

Apache web servers targeted by stealthy 'Cdorked' malware

Hard to spot in logs

Article comments

Security researchers have discovered a new Apache web server backdoor that is so stealthy it leaves almost no trace of its redirection behaviour on the hard drive or in server log files.

According to an analysis by security firms ESET and Sucuri, spotting the Linux/Cdorked.A module will prove a challenge to even the most diligent web admin.

Unlike the majority of such malware, Cdorked writes no files to the server’s hard drive beyond its modified binary, storing its configuration in a few megabytes of main memory that it happily shares with other processes.

No traces of command and control are left on the victim server thanks to the way it pushes its configuration through obfuscated HTTP that doesn't appear in logs.

“There are two ways the attacker can control the behaviour of the backdoored server: through a reverse connect shell or through special commands, all of them are triggered via HTTP requests,” said ESET’s Pierre-Marc Bureau.

The malware’s purpose is mostly to serve the redirects to Blackhole Exploit Kit that currently dominates the threat landscape although it is well designed enough to avoid this behaviour if it detects it is being accessed by an admin interface.

Although small by Internet standards, ESET’s engineers still estimate that hundreds of servers are affected which probably equates to thousands of websites co-opted to serve redirects.

Detecting and getting rid of it means either checking the integrity of the Apache package or, better still, looking at a memory dump to spot the malware’s binary.

"We urge system administrators to check their servers and verify that they are not affected by this threat," said ESET.

ESET previously reported on Linux/Chapro.A, an attack aimed at Internet bank users, and the Snasko server rootkit.

As with these attacks, Cdorked is a reminder to apply all patches and that attackers are now aiming at vulnerable servers as a weakness.


More from Techworld

More relevant IT news


Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Choose – and Choose Wisely – the Right MSP for Your SMB

End users need a technology partner that provides transparency, enables productivity, delivers...

Download Whitepaper

10 Effective Habits of Indispensable IT Departments

It’s no secret that responsibilities are growing while budgets continue to shrink. Download this...

Download Whitepaper

Gartner Magic Quadrant for Enterprise Information Archiving

Enterprise information archiving is contributing to organisational needs for e-discovery and...

Download Whitepaper

Advancing the state of virtualised backups

Dell Software’s vRanger is a veteran of the virtualisation specific backup market. It was the...

Download Whitepaper

Techworld UK - Technology - Business

Innovation, productivity, agility and profit

Watch this on demand webinar which explores IT innovation, managed print services and business agility.

Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

From Wow to How : Making mobile and cloud work for you

On demand Biztech Briefing - Learn how to effectively deliver mobile work styles and cloud services together.

Watch now...

Site Map

* *