![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Linux Support Linux - Operating Systems and Applications Support |
![]() |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
Registered User
Join Date: Aug 2008
Posts: 1
OS: xp
|
My mail/ web server is running on RHEL 4 with sendmail and apache . I generally access it from web interface of squirellmail.
A few days back I revceived a mail and a call from some security agency looking after a financial site telling me there is a folder called redirect.to in my web server's virtual directory , and to stop this phising I need to delete the folder. I deleted the folder immediately. I changed the root passwords and stop all the unnecessary services. After this also the folder reapears and started phising all over again. Urgent help is required . |
|
|
|
| Sponsored Links |
|
|
#2 (permalink) |
|
Moderator/Fedora Amb.
|
Re: Unknown phishing from my mail/web server
Welcome to TSF!!
I am interested in knowing what security agency called you and told you to remove this folder? I haven't ever heard of this happening. Unless you have a company monitoring your web servers? Is this financial site hosted from your web server? Cheers! |
|
|
|
|
|
#3 (permalink) |
|
Registered User
Join Date: Oct 2007
Location: Littleton, Colorado USA
Posts: 470
OS: xp 64 sp2 Fedora Core 8 (vmware xp core 8 x32) Minix
|
Re: Unknown phishing from my mail/web server
Restore the directory "redirect.to" off of a backup tape and see what was in the directory. From google, it sounds like this is used by Apache to redirect broken links to another site. If your Apache directory tree was "writeable", it is possible someone could have put a redirect meta tag there.
Sorry I don't have any recent Apache experience. Maybe somebody else can help you. I'm with wmorri, some security agency should have been ignored. If they call again, ask for a name and phone number, then you look them up and call back to see if they are legit. |
|
|
|
![]() |
| Thread Tools | |
|
|