LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-14-2009, 12:20 PM   #1
Kallisti
LQ Newbie
 
Registered: Dec 2009
Posts: 1

Rep: Reputation: 1
requests to 80 and 443 are redirected to another site when running iptables


Hi guys,

I have a really strange situation that I can't wrap my head around. I'm trying out a new VPS vendor and just have some services installed to try it out, so nothing really sensitive or valuable on this server. Suddenly a week ago requests to the domain on http and https started to be redirected to some other server.

I have narrowed down the symptoms to know that when I have a http/https-service (either apache or nginx) running on my system AND have iptables running the requests get redirected. iptraf show the connection coming in but the logs of nginx/apache shows no activity. The / index.html just types a single row of the domain of the other server. If I open up another port (like 8080) and recon nginx/apache to listen there it works perfectly. If, on the other hand, I disable iptables (sercice iptables stop or flushes the tables) requests to http/https times out, i.e. nginx/httpd never receives it even though they are configured to listen to those ports.

If I run iptables, actually with RH standard ruleset, and do not run a http-service on 80/443 the redirection does not happen. So it's only if something is supposed to answer to http/https requests on my server that they are redirected.

I'm not seeing any other strange (or even normal) traffic on my server, nothing else is really running on the machine.

The other server seems to be a german domain, which is also visible in the ssl-certificate when accessing https. There doesn't seem to be anything on that server other than the single line of the domain name.

I'm running a CentOS 5.3 pretty vanilla installation with nginx, httpd, mysql, php running. I have been trying out poptop, pptpd, nuxeo dms.

I'm at a loss to what to check! As I said I can't see any other traffic so if it is compromised either they haven't been able to turn it or they are masking it from me.. root password is not compromised, which is the only user configured, except for the mysql user. Any pointers would be greatly appreciated!

/Kallisti
 
Old 01-04-2010, 06:42 AM   #2
C.R.Ritson
LQ Newbie
 
Registered: Jan 2006
Posts: 1

Rep: Reputation: 0
iptables and unwanted http(s) redirection

Quote:
Originally Posted by Kallisti View Post

If I run iptables, actually with RH standard ruleset, and do not run a http-service on 80/443 the redirection does not happen. So it's only if something is supposed to answer to http/https requests on my server that they are redirected.

/Kallisti
Can you ignore any standard redhat tools and look at the installed iptables setup with /sbin/iptables-save - you will need root access for this? Does this help?

Chris Ritson
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
iptables to block 443 port except for partcular sites crackyblue Linux - Security 6 03-28-2010 09:53 AM
redirect some http requests to port 443. FMH Linux - Software 5 09-17-2007 08:19 AM
firefox issue; google redirected to kpn hotspots after visiting the site at hotspot qanopus General 3 08-07-2007 08:24 AM
iptables - why am I still being redirected? michaelsanford Linux - Networking 1 05-23-2005 03:52 PM
localhost:901 gets redirected to "Power Linking" web site advertisement condosolon Linux - Newbie 2 03-04-2004 12:23 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:34 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration