Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Alternative Computing > Linux Support
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Linux Support Linux - Operating Systems and Applications Support

Reply
 
LinkBack Thread Tools
Old 08-29-2008, 05:44 AM   #1 (permalink)
Registered User
 
Join Date: Aug 2008
Posts: 1
OS: xp


Thumbs Up Unknown phishing from my mail/web server

My mail/ web server is running on RHEL 4 with sendmail and apache . I generally access it from web interface of squirellmail.

A few days back I revceived a mail and a call from some security agency looking after a financial site telling me there is a folder called redirect.to in my web server's virtual directory , and to stop this phising I need to delete the folder. I deleted the folder immediately.

I changed the root passwords and stop all the unnecessary services. After this also the folder reapears and started phising all over again.

Urgent help is required .
gjsnath is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Sponsored Links
Old 08-30-2008, 04:51 PM   #2 (permalink)
Moderator/Fedora Amb.
 
wmorri's Avatar
 
Join Date: May 2008
Location: /pm/etc
Posts: 2,275
OS: XP SP3/Fedora 10


Send a message via AIM to wmorri
Re: Unknown phishing from my mail/web server

Welcome to TSF!!

I am interested in knowing what security agency called you and told you to remove this folder? I haven't ever heard of this happening. Unless you have a company monitoring your web servers?

Is this financial site hosted from your web server?

Cheers!
__________________


Linux Forever!

I won't be back until Tuesday, I am moving this weekend

wmorri is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 08-30-2008, 06:16 PM   #3 (permalink)
Registered User
 
Join Date: Oct 2007
Location: Littleton, Colorado USA
Posts: 470
OS: xp 64 sp2 Fedora Core 8 (vmware xp core 8 x32) Minix


Re: Unknown phishing from my mail/web server

Restore the directory "redirect.to" off of a backup tape and see what was in the directory. From google, it sounds like this is used by Apache to redirect broken links to another site. If your Apache directory tree was "writeable", it is possible someone could have put a redirect meta tag there.

Sorry I don't have any recent Apache experience. Maybe somebody else can help you. I'm with wmorri, some security agency should have been ignored. If they call again, ask for a name and phone number, then you look them up and call back to see if they are legit.
lensman3 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 09:50 PM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84