Sunday, September 13, 2009

Zombie web servers!

"Each of the infected machines examined so far is a dedicated or virtual dedicated server running a legitimate website, But in addition to running an Apache webserver to dish up benign content, they've also been hacked to run a second webserver known as Nginx, which serves malware [on port 8080]. 'What we see here is a long awaited botnet of zombie web servers! A group of interconnected infected web servers with [a] common control center involved in malware distribution, To make things more complex, this botnet of web servers is connected with the botnet of infected home computer(s)."