Announcement

Collapse
No announcement yet.

Is this a trojan or backdoor in my images/attachments folder?

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • #16
    Originally posted by MarcoH64
    Only if the hack is done on your account.

    Is it a dedicated server, or shared hosting?

    PS The script could be almost anywhere on your server, even embedded in a regular file/script.

    There are some tools to help finding this kind of things like chrootkit, your host should know more about them. Unfortunatly, unless you can find exactly how the server was compromised and you can find all traces of it, the only secure way to get rid of things like this, i s acomplete new install (OS and everything) with clean files.
    I'm on a shared server with HostRocket. VBB team is investigating if it is a VBB security hole, if not, I'll notify HR.

    Comment


    • #17
      It looks like a backdoor inclusion hole, make sure that php setting allow_url_fopen is OFF on the server to counter such attacks.
      StylWolny.pl - Polskie Forum Dyskusyjne | guziki wieszaki producent - Bonetti.pl
      Join Tattoo Group Now

      Comment


      • #18
        I've passed this thread on to HR tech support, also, the VBB team did some digging and have discovered that this may be a phpBB and phpNuke security flaw. I had both of these installed on my server at one time.

        It appears that these files are used for spamming a redirecting to search engines.

        Comment


        • #19
          I'm on a shared host, is there anything I can do or do I have to ask my hosting company to turn it off for the whole server?

          Originally posted by sensimilla
          It looks like a backdoor inclusion hole, make sure that php setting allow_url_fopen is OFF on the server to counter such attacks.
          DMCTalk.com forums - For DeLorean owners and enthusiasts.

          Comment

          widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
          Working...
          X