3 ms·
Unless I missed it, the article doesn't mention exactly how it gets on your web server in the first place, or what vulnerability it exploits. I presume some vul
by jonpaul 14y ago
Unless I missed it, the article doesn't mention exactly how it gets on your web server in the first place, or what vulnerability it exploits. I presume some vulnerability in Nginx? This would be the most important part, how can I prevent my web server from getting infected with this specific rootkit. Did I miss this part?
- Nursie 14y agoThe 'vulnerability' is in the kernel, it replaces some of the tcp send functionality and is at a much lower level than nginx. It looks for outgoing http traffic and injects a bad iframe. No idea on how it gets there though, no details from any source I've seen.
- tangue 14y agoNobody knows. But the attacker has to have root privileges to install the rootkit. So the usual suspects are weak password and unpatched software.