Can a website be hosted from a compromised device?¶
Yes. An attacker can make a computer, server, router or NAS deliver pages, files or redirects without the owner’s knowledge.
How the device can be misused¶
Malware may install a web service, add files to an existing server, change router forwarding or create an outbound tunnel. The visible IP can therefore belong to the victim’s connection or an intermediary even though control comes from elsewhere.
This is similar to stolen premises being used as an unattended collection point: locating the premises does not identify the person directing the activity.
Test how the service was created and maintained. Relevant traces can include unexpected user accounts, remote-access tools, new listening services, altered configuration, unexplained files, scheduled tasks, malware, administrator logins and unusual outbound connections.
Time is important. Compare the first appearance of the content with software installation, account access, configuration changes and communications. Determine whether the owner continued interacting with or benefiting from the service after becoming aware.
Compromise should neither be presumed nor dismissed because it is technically possible. The claim needs to fit the system evidence. Preserve volatile and easily overwritten records before remediation where lawful and appropriate.
The point to remember
A compromised device can supply the infrastructure while another person supplies the control. Establish installation, access and command evidence.