Author Topic: heads up, nginx exploit  (Read 5074 times)

0 Members and 1 Guest are viewing this topic.

Offline sth

  • 2 girls 1 cuprubber
  • Thread Starter
  • Posts: 3438
11:48 -!- SmallFry [~SmallFry@unaffiliated/smallfry] has quit [Ping timeout: 245 seconds] ... rest in peace

Offline alaricljs

  • I be WOT'ing all day...
  • ** Moderator Emeritus
  • Posts: 3715
  • Location: NE US
Re: heads up, nginx exploit
« Reply #1 on: Wed, 21 November 2012, 21:17:40 »
While that's interesting it does not indicate that nginx is the culprit.  Whatever infected his system is using kernel modules and root level processes to hijack data between nginx and the NIC.  Would probably do the same thing with apache.

So until someone serious figures out the infection vector, this is just some dude that got pwned in an unknown way.
Filco w/ Imsto thick PBT
Ducky 1087XM PCB+Plate, w/ Matias "Quiet Click" spring-swapped w/ XM Greens

Offline sth

  • 2 girls 1 cuprubber
  • Thread Starter
  • Posts: 3438
Re: heads up, nginx exploit
« Reply #2 on: Wed, 21 November 2012, 21:21:48 »
sorry i kind of smushed that all together.
it's either a buggy or replaced kernel module that they were able to get on the system or exploit on a system that already had it, and then load it when it is needed. then, to actually take advantage of the rootkit they were able to exploit a different hole in nginx.

i know this stuff is usually very focused in the nix world compared to windows servers. i also don't know or care to know anything about the hardware/software that GH runs on but it's hard not to know that the site runs on top of nginx when we see timeouts from time to time :)

the reason i was a bit alarmed and decided to post was because it affects a very stable kernel (the one used in deb6). creative destruction!
11:48 -!- SmallFry [~SmallFry@unaffiliated/smallfry] has quit [Ping timeout: 245 seconds] ... rest in peace

Offline alaricljs

  • I be WOT'ing all day...
  • ** Moderator Emeritus
  • Posts: 3715
  • Location: NE US
Re: heads up, nginx exploit
« Reply #3 on: Wed, 21 November 2012, 21:33:05 »
What hole in nginx?  It's sticking code in the network handling part of the kernel.  Has nothing to do with nginx.
Filco w/ Imsto thick PBT
Ducky 1087XM PCB+Plate, w/ Matias "Quiet Click" spring-swapped w/ XM Greens

Offline sth

  • 2 girls 1 cuprubber
  • Thread Starter
  • Posts: 3438
Re: heads up, nginx exploit
« Reply #4 on: Wed, 21 November 2012, 21:37:10 »
from what i gathered they were serving up malware pages using nginx. no mention of other webservers.

if you don't think it's a big deal I trust you :)
11:48 -!- SmallFry [~SmallFry@unaffiliated/smallfry] has quit [Ping timeout: 245 seconds] ... rest in peace

Offline alaricljs

  • I be WOT'ing all day...
  • ** Moderator Emeritus
  • Posts: 3715
  • Location: NE US
Re: heads up, nginx exploit
« Reply #5 on: Wed, 21 November 2012, 21:49:29 »
deeper in it is explained that nginx was producing the correct response and it was mangled inside the kernel between nginx and the network stack.
Filco w/ Imsto thick PBT
Ducky 1087XM PCB+Plate, w/ Matias "Quiet Click" spring-swapped w/ XM Greens

Offline sth

  • 2 girls 1 cuprubber
  • Thread Starter
  • Posts: 3438
Re: heads up, nginx exploit
« Reply #6 on: Wed, 21 November 2012, 21:53:14 »
deeper in it is explained that nginx was producing the correct response and it was mangled inside the kernel between nginx and the network stack.

got it. i've been paging back to the exploit analysis in between work stuff and getting a better picture of it.
i raise the alarm as soon as i see smoke, no fire necessary :P
11:48 -!- SmallFry [~SmallFry@unaffiliated/smallfry] has quit [Ping timeout: 245 seconds] ... rest in peace

Offline SmallFry

  • ** Moderator Emeritus
  • Posts: 3887
  • Location: Wisconsin, USA
  • Leaving 6/15; returning 6/22 or so.
Re: heads up, nginx exploit
« Reply #7 on: Thu, 22 November 2012, 12:29:31 »
Somebody PM iMav, I know he runs nginx.

Offline sth

  • 2 girls 1 cuprubber
  • Thread Starter
  • Posts: 3438
heads up, nginx exploit
« Reply #8 on: Thu, 22 November 2012, 14:52:51 »
It's not an nginx exploit afawk :p
11:48 -!- SmallFry [~SmallFry@unaffiliated/smallfry] has quit [Ping timeout: 245 seconds] ... rest in peace

Offline mkawa

  •  No Marketplace Access
  • Posts: 6562
  • (ツ)@@@. crankypants
Re: heads up, nginx exploit
« Reply #9 on: Fri, 23 November 2012, 09:39:31 »
who says we're even running deb6?

to all the brilliant friends who have left us, and all the students who climb on their shoulders.