A security analyst is reviewing a server after a suspected compromise. The server is a Linux web server running Apache. The analyst discovers a suspicious file named 'shell.php' in the web root directory (/var/www/html) containing base64 encoded strings and commands for executing system processes. The file was created by the 'apache' user. Which of the following is the MOST appropriate eradication step for this finding?
- AIsolate the server from the network and perform a full forensic image.
- BChange the password for the 'apache' user and block the attacker's IP.
- CRebuild the server from a trusted, known-good image and apply all patches.
- DDelete the 'shell.php' file and restart the Apache service.
Show answer & explanationAnswer & explanation
Correct answer: C. Rebuild the server from a trusted, known-good image and apply all patches.
Discovering a web shell created by the 'apache' user in the web root indicates a severe compromise, likely involving an exploited web application vulnerability or privilege escalation. Simply deleting the file (B) and restarting Apache might not remove the root cause or other hidden backdoors. Rebuilding the server from a known-good image (C) ensures complete eradication of the threat and any persistence mechanisms, which is the most thorough and appropriate step for a deep compromise like this. Isolating (A) is containment, and changing the password/blocking IP (D) are partial measures.
Why the other options are wrong
- A. This is a containment step, not eradication.
- B. Changing the password is a good step but does not eradicate the existing compromise; blocking the IP is containment.
- D. Deleting the file might not address the root vulnerability or other persistence mechanisms.
Eradication Strategy: Re-imaging
A comprehensive incident response eradication strategy that involves wiping a compromised system and reinstalling the operating system and applications from trusted, known-good sources.
- Used for deep or persistent compromises (e.g., rootkits, web shells).
- Ensures complete removal of malware and persistence mechanisms.
- Requires verified backups or clean installation media.
Memory trick: Clean, Patch, Rebuild