Server anti-virus software needed any suggestions?

Thread Solved
Reply

Join Date: Feb 2008
Posts: 462
Reputation: tiger86 is an unknown quantity at this point 
Solved Threads: 10
tiger86's Avatar
tiger86 tiger86 is offline Offline
Posting Pro in Training

Server anti-virus software needed any suggestions?

 
0
  #1
Nov 8th, 2008
Hi, I work for a server that runs on apache and red hat. I need to get a anti-virus for the server as we have possible trojans that we need to quarantine. I appreciate any posts.
If I helped you I would appreciate it if you would give me some reputation.
read my actionscript to english blog
Currently developing what should be social network 2.0 offline.
Reply With Quote Quick reply to this message  
Join Date: Apr 2006
Posts: 5,050
Reputation: John A is a splendid one to behold John A is a splendid one to behold John A is a splendid one to behold John A is a splendid one to behold John A is a splendid one to behold John A is a splendid one to behold John A is a splendid one to behold John A is a splendid one to behold 
Solved Threads: 331
Moderator
John A's Avatar
John A John A is offline Offline
Vampirical Lurker

Re: Server anti-virus software needed any suggestions?

 
0
  #2
Nov 8th, 2008
What gives you the impression that you might have Trojans on your system?
"Technological progress is like an axe in the hands of a pathological criminal."
Reply With Quote Quick reply to this message  
Join Date: Feb 2008
Posts: 462
Reputation: tiger86 is an unknown quantity at this point 
Solved Threads: 10
tiger86's Avatar
tiger86 tiger86 is offline Offline
Posting Pro in Training

Re: Server anti-virus software needed any suggestions?

 
0
  #3
Nov 10th, 2008
Well the unix version of trojans here is what I have.
Scan for Trojan Horses

Appears Clean


/dev/stderr


Scanning for Trojan Horses.....


Possible Trojan - /usr/sbin/pureauth


Possible Trojan - /usr/sbin/antirelayd


Possible Trojan - /usr/bin/pod2man


Possible Trojan - /usr/bin/pod2usage


Possible Trojan - /usr/bin/podchecker

Possible Trojan - /usr/bin/podselect


Possible Trojan - /usr/bin/psed


Possible Trojan - /usr/bin/pstruct


Possible Trojan - /usr/bin/s2p


Possible Trojan - /usr/bin/splain


Possible Trojan - /usr/bin/xsubpp


11 POSSIBLE Trojans Detected
If I helped you I would appreciate it if you would give me some reputation.
read my actionscript to english blog
Currently developing what should be social network 2.0 offline.
Reply With Quote Quick reply to this message  
Join Date: Apr 2006
Posts: 5,050
Reputation: John A is a splendid one to behold John A is a splendid one to behold John A is a splendid one to behold John A is a splendid one to behold John A is a splendid one to behold John A is a splendid one to behold John A is a splendid one to behold John A is a splendid one to behold 
Solved Threads: 331
Moderator
John A's Avatar
John A John A is offline Offline
Vampirical Lurker

Re: Server anti-virus software needed any suggestions?

 
1
  #4
Nov 11th, 2008
Well, there's 3 possible causes:

- A virus got onto your system. This would most likely involve a virus exploiting a security hole in one of your daemons, or you or another administrator executing malicious code under the root account.
- A hacker broke into your system. They replaced a number of your system binaries with Trojans (and probably a hell of a lot of other stuff too).
- Your system is fine, that's just the result of a lousy Trojan-checker.

Since I find #1 extremely unlikely, and judging by the fact that you haven't even bothered to mention the name of the program that made these Trojan claims, nor has it provided any kind of proof on why it's making these claims, I would say that it's most likely to be case #3.

Of course, if you did manage to compromise the security of an entire server, I would recommend you wiping the entire OS and starting from scratch again. It's one thing to have a virus or two on a desktop computer, it's quite another when an entire network server gets compromised.

The first thing you should probably do is compare checksums between the suspected binaries and fresh copies downloaded from the web (remember to download the exact same version). If they match, then it was a false alarm. However, if you're finding quite a number of those binaries to have different checksums, then the security of your server has probably been compromised.
"Technological progress is like an axe in the hands of a pathological criminal."
Reply With Quote Quick reply to this message  
Join Date: Feb 2008
Posts: 462
Reputation: tiger86 is an unknown quantity at this point 
Solved Threads: 10
tiger86's Avatar
tiger86 tiger86 is offline Offline
Posting Pro in Training

Re: Server anti-virus software needed any suggestions?

 
0
  #5
Nov 16th, 2008
Thanks it was #3 I had the techs at the company I work at update all of our software and doublecheck the server to make sure it is safe and it is. IT was a bad whm scanner.
If I helped you I would appreciate it if you would give me some reputation.
read my actionscript to english blog
Currently developing what should be social network 2.0 offline.
Reply With Quote Quick reply to this message  
Join Date: Apr 2005
Posts: 15,953
Reputation: jbennet is a name known to all jbennet is a name known to all jbennet is a name known to all jbennet is a name known to all jbennet is a name known to all jbennet is a name known to all 
Solved Threads: 504
Moderator
Featured Poster
jbennet's Avatar
jbennet jbennet is offline Offline
Moderator

Re: Server anti-virus software needed any suggestions?

 
0
  #6
Nov 25th, 2008
I think you can get ClamAV and AVG for linux anyway
If i am helpful, please give me reputation points.
Reply With Quote Quick reply to this message  
Reply

This thread has been marked solved.
Perhaps start a new thread instead?
Message:



Other Threads in the *nix Software Forum
Thread Tools Search this Thread



About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC