
In the past 2 days I've seen three examples of Korean Apache Servers running on AnNyang Linux being hacked by phishers, and the Linux Admins then quietly redirecting the phishing site to the legitimate site, as if the don't want anyone to know they got hacked.
(I tried posting another example yesterday, only to have my proxy server crap out on me and lose my post

)
Anyway, today I get notified of another Korean eBay phishing site, but this one's different:
- Port 7301 instead of 80
- Windows, not Linux
- The webserver is something small - no banners:
HEAD / HTTP/1.0
HTTP/1.1 200
Content-Length: 0
Last-modified: Sat, 27 Dec 2003 23:10:22 GMT
Content-Type: text/html
Connection: Keep-Alive
And SOMEONE (Maybe the admin, maybe a white hat, after all, this is an obviously hackable machine) put the words FAKE FORGERY into every table tag on the site to warn people. Effective countermeasure, and although I usually don't agree with vigilate tactics, in this case the good done here and the harm avoided outweighs the negatives.