Welcome! Log In Create A New Profile

Advanced

Malware in /tmp/nginx_client

June 27, 2015 09:45AM
The software maldet, discovered some malware in the the /tmp/nginx_client directory, like this:

> {HEX}php.cmdshell.unclassed.357 : /tmp/nginx_client/0050030641
> {HEX}php.cmdshell.unclassed.357 : /tmp/nginx_client/0060442670

I did some research, and found out that indeed, there were some malicious code in them.

I did a extensive search in the sites, and nothing malicious was found, including the code that appeared in the tmp files.

Around the time the files were created, there were similar requests, to non existent Worpress plugins, and to a file of the Worpres backend.

Digging up a little, I found this: blog.inurl.com.br/2015/03/wordpress-revslider-exploit-0day-inurl.html

Basically an exploit for a Wordpress plugin vulnerability, (it doesn't affect my sites, though), that do similar requests to the ones I found.

One of those, is a post request that includes an attacker's php, file that thanks to this vulnerability will be uploaded to the site and it can be run by the attacker.

So what it seems to be happenning is that nxing is caching post requests with malicious code, that later is found by the antimalware software.

Could this be the case? I read and seems that Nginx does't cache post request by default, so it seems odd.

Is there a way to know if that tmp files are caching internal or external content?

I will be thankful for any info about it.

Nginx is working as reverse proxy only.


This is a bit of another file that was marked as malware:

>
> --13530703071348311
> Content-Disposition: form-data; name="uploader_url"
>
> http:/MISITE/wp-content/plugins/wp-symposium/server/php/
> --13530703071348311
> Content-Disposition: form-data; name="uploader_uid"

> 1
> --13530703071348311
> Content-Disposition: form-data; name="uploader_dir"
>
> ./NgzaJG
> --13530703071348311
> Content-Disposition: form-data; name="files[]"; filename="SFAlTDrV.php"
> Content-Type: application/octet-stream
Subject Author Posted

Malware in /tmp/nginx_client

guillefar June 27, 2015 09:45AM

Re: Malware in /tmp/nginx_client

Lucas Rolff June 27, 2015 10:36AM

Re: Malware in /tmp/nginx_client

guillefar June 29, 2015 05:08AM

Re: Malware in /tmp/nginx_client

Lucas Rolff June 29, 2015 05:14AM



Sorry, only registered users may post in this forum.

Click here to login

Online Users

Guests: 318
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready