NginX Sudden "Weird server reply" HACKED ?

shahzaib mushtaq shahzaib.cb at gmail.com
Fri Nov 8 12:10:12 UTC 2019


Hi,

We just recently received an alert against one of our Nginx based server
which has started to download files with any extension e.g .html, .php) on
HTTP instead of processing it. On HTTPS file process fine but on HTTP, even
though its .html extension file it is started to download by the browser.

We've forced redirect setup from HTTP to HTTPS, which is also stopped
working. If we send curl request to HTTP , following is the reply we get:

[root at cw025 /usr/local/etc/nginx/vhosts]# curl -I
http://cw025.domain.com/test.html
curl: (8) Weird server reply

Can anyone help whats going on?

Regards.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mailman.nginx.org/pipermail/nginx/attachments/20191108/6b1f572d/attachment.htm>


More information about the nginx mailing list