Author Topic: Apache malware targeting online banking  (Read 309 times)

Offline Just17

  • PCLinuxOS Tester
  • Super Villain
  • *******
  • Posts: 10696
  • MLUs Forever!
Apache malware targeting online banking
« on: January 03, 2013, 11:02:24 AM »
http://www.net-security.org/malware_news.php?id=2364

Quote
Analysis of a malicious Apache module, detected by ESET as Linux/Chapro.A, found that the world's most widely used web server, Apache, is being used to carry out these attacks, injecting malicious content into web pages served by an infected Linux server, without the knowledge of the website owner.
MLUs rule the roost!

Linux XPS 3.4.38-pclos1.bfs  64 bit
Intel Core2 Quad CPU Q9450 @ 2.66GHz
4 GB RAM
MCP51 High Def Audio
GeForce GTX 550 Ti
PHILIPS  ‎DVD+-RW DVD8701
‎Logitech ‎BT Mini-Receiver
Afatech DTT

Offline kjpetrie

  • PCLinuxOS Tester
  • Hero Member
  • *******
  • Posts: 4004
Re: Apache malware targeting online banking
« Reply #1 on: January 03, 2013, 12:25:07 PM »
A bit thin on the vital content. How does the malicious module get installed into the Apache server? What can server/website owners do to guard against it?

Once a website is compromised it can try to exploit holes in browsers, in this case on Windows machines to install malware. What are the browser manufacturers/MS doing about that?

Finally, it uses a social engineering exploit, asking for information in a context where it wouldn't normally be needed.

There's no real information here, though it's useful to be reminded there are criminals out there and we all need to be careful.
-----------
KJP
-----------------------------------------------------------
PClos64 RC1 on Intel D945GCLF2 motherboard (Atom 330), 2GB DDR2 RAM, Maxtor STM325031, HL-DT-ST DVDRAM GSA-H42N, Amilo LSL 3220T monitor. Also Acer 5810TG (with custom kernel) and Asus eeePC 2G surf

Offline horusfalcon

  • Hero Member
  • *****
  • Posts: 998
  • Wayfarer of The Western Wastes
Re: Apache malware targeting online banking
« Reply #2 on: January 03, 2013, 01:11:47 PM »
A quick google on Sweet Orange reveals that it is an exploit kit capable of delivering a wide range of payloads, and is a potent threat to Windows Users...  (and I'll leave that right there).

It's one of several exploit kits (Blackhole and Nuclear, just to name two others is a growing field) which cybercriminals now have access to for their various nefarious purposes.

kjpetrie's assessement of this article is spot-on, but there's more out there.  Sweet Orange is creating a lot of buzz in security-related web spaces.  That it's primary vector involves Apache (the most popular web server on the planet) should come as no surprise.  I'm sure the folks at Apache are looking into this with all due diligence and haste.

In reading around on this, I do note a Windows-centric bias that tends to pervade the security blogosphere/journalism space - everyone I've read so far refer to this as a "malicious Linux module" when I doubt they would know a Linux module if it reached up and bit them on their hineys.  (What is in that kool-aid these days? :D)  Bring your B.S. filter, and set it to "High".

The usual cautions against social engineering are well taken.  It only takes a few seconds to make that mistake, a few seconds that could be tempered by sitting on one's hands for a few more seconds while engaging one's brain to really consider what that nice, friendly-looking popup is really asking for, and why...

Later On,
D



"The Way is not a matter of knowing or not knowing.  One word to a wise man; one lash to a bright horse."

Dell Latitude D620, PCLinuxOS 2012.08 KDE4/LXDE, 3.2.18.pclos.bfs, specs here.

Offline YouCanToo

  • PCLinuxOS Tester
  • Hero Member
  • *******
  • Posts: 5337
  • Location: Lebanon, OR., USA
    • Spreading the word.......
Re: Apache malware targeting online banking
« Reply #3 on: January 03, 2013, 02:34:03 PM »
Pretty vague article.




Be sure to visit the NEW Knowledge Base


Linux is user-friendly- it's just picky who its friends are!

Offline Tony

  • Hero Member
  • *****
  • Posts: 1744
  • Reason_able ;)
Re: Apache malware targeting online banking
« Reply #4 on: January 03, 2013, 04:11:40 PM »
I'm starting to worry about Just17, anything to do with Linux, and security are making him concerned. Fair enough, and rightly so.

I don't know that anything has changed greatly. I'm sure Apache Server Software will plug there holes. Often attacks are just a proof of concept, alerting that this exploit is possible; on the flip side often they are starving Ukranian coders trying to get some bucks.

Very systemic in the MS circle I believe; vulnerabilities. Big Business pluging 'em, talking about them, being a Rock Star Vulnerability plugger; it's a dangerous but lucrative game for a lot of folk in that industry, and it's gone on always.
Reading info from reputable Anti-Malware sites as always the way to get your head around all reported vulnerabilities.
For MS users there's only roughly 100,000 new variants of exploits each day, the choice of Linux is kinda easy.

I love reading the Monthly Security Bulletins from MS. Really very funny.
http://technet.microsoft.com/en-us/security/bulletin/ms12-dec  

horusfalcon:
Quote
In reading around on this, I do note a Windows-centric bias that tends to pervade the security blogosphere/journalism space - everyone I've read so far refer to this as a "malicious Linux module" when I doubt they would know a Linux module if it reached up and bit them on their hineys.  (What is in that kool-aid these days?  :D)  Bring your B.S. filter, and set it to "High".

 ;D ;D ;D
« Last Edit: January 03, 2013, 04:19:30 PM by Tony »
*PCLOS 3.2.18-pclos2 - MiniMe 2013.x - KDE 4.10.1 - Intel(R) Pentium(R) 4 CPU 3.00GHz - 1GiB DIMM DDR 533 MHz RAM  = SHABANG ! ;) *Software Updates