|
Current User: Guest
|
|
c99Madshell and other backdoors php shell programs |
|
| Page: 1 |
| User | Post |
|---|---|
|
3:46 Tim Guest
|
c99Madshell (I think that is the name) seems to be sweeping the net allowing hackers into many php websites. I found c99Madshell or one of its variants inside my wordpress installation today. c99Madshell works like this…The hacker uploads a file as an image file or something to a CMS (wordpress/moodle/joomla), then browses to that file. And somehow that allows the attacker to call an amazing shell program written in php which then gives him complete control over your server! If you do not have the right php.ini settings, the php script can be off site. One of my wordpress instalations was hacked. There was an upload of the backdoor shell file call "mdl_utf.php" in the upload directory and then a whole load of other stuff and encoded junk in my theme. Madshell obfuscates its php code, so I recommend those worried to grep for mdl_utf.php may not be related to worpress at all. It could have got in initially via Moodle, another CMS I am using that I hear was weak to this type of attack but moodle user a data file area that is not browsable above public_html, and since the hackers shell file was in the uploads section of wp-contents, and it seems to be only my wordpress installation that is corrupted, I am wondering how to stop this happening again. I am also wondering if there is any connection with Flexible UPload. To recap the symptoms I upgraded wordpress and flexible upload completely via http://ftp. I hear that setting Any other tips to make sure that noone uploads this sort of malware again? |
|
8:17 Tim Guest
|
By the way, I think that the attack started with the application of somene to be a user. I thought that our blog |
|
7:28 Tim Guest
|
Post Awaiting Approval by Forum Administrator |
| Page: 1 |
|
About the Ma Tasse de Thé forum | |||
|---|---|---|---|
|
Currently Online: 3 Guests Maximum Online: 51 |
Forums: Groups: 1 Forums: 3 Topics: 145 Posts: 479 |
Members: There are 1 members There are 206 guests Antoine has made 130 posts |
Top Posters: |
Simple Forum WordPress Plugin created by Andy Staines: Yellow Swordfish
Forum Skin/Icons: default / default
Default 'Silk' Icon Set created by Mark James: fam fam fam
Math Spam Protection based on code by Michael Woehrer: Software Guide
Tabbed Admin uses Tabifier by Patrick Fitzgerald: BarelyFitz Designs
My thanks to all the people who have aided, abetted, suggested and helped test this plugin