3 ms·
They pointed out that there are malware files and suggested an online security scanner. I tried it out and pointed back to them that their web server is outdat
by ForFreedom 12y ago
They pointed out that there are malware files and suggested an online security scanner. I tried it out and pointed back to them that their web server is outdated.
Well my question to them was how can that be that I have malware and its okay for them to have outdated web server software.
I asked them for patch dates :: didnt get a reply
They said if they upgrade then all users will have problems with their websites.
I have been hosting with them for over 5 years now and they are good.
I may be wrong in my opinion or have over looked something so wanted to know what others think.
- stevekemp 12y agoSounds like you're unhappy with your hosting company and your preferred solution would be to choose an alternative. If you believe your hosting company is lying then staying there is not a sensible decision to make. Your server/site could be compromised. There could be malware present. That may or may not be related to the version of Apache. Most web-compromises are due to weak SSH passwords, old versions of Wordpress, or other applications. I've never yet seen a compromised host which was caused by an old version of Apache, but that isn't to say that this is impossible.
- digital-rubber 12y agoI see. And yes there have been some module/syntax changes between apache versions that makes one less motivated to upgrade. Also upgrading doesn't always give you better security, you might be introducing a new issue/bug. But i could see their reasoning, why not to upgrade/change the version. The scanner most likely does a simple version compare. The scanner assumes anything under version X.Y == vulnerable. If it would be hiding or faking the vendor and version to latest IIS (or apache, or nginx or etc), possible it would simply report all is A-Okay. Unless the scanner really test the actual exploit/vulnerabilities, i assume the simple version compare happens. Though i'm quite certain the malware didn't get *there via a method that only utilises the webserver; more likely a poor coded (php, perl, etc) script allowed 3rd parties to download/write to disk of your webserver. If for example shellshock wasn't patched in time, and there was a vulnerable cgi script or similar on the website/server, it could have been that script+bash, that has been exploited. But that doesn't make the webserver vulnerable. (even though the malicious upload/ action was executed via the webserver)
- ForFreedom 12y agoCan the upload go into a non-www directory via a php? A non-www directory is not viewable. If this directory is accessible then would it be server or application level exploit?
- mortenlarsen 12y agoYes, and any exploit is much more likely to be through a vulnerability in the PHP application you are running on the site. That is my experience as a former system administrator at a webhost.