LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-19-2015, 11:54 AM   #1
dwhswebhosting
LQ Newbie
 
Registered: Jun 2004
Location: Earth
Distribution: CentOS 6 and 7
Posts: 27

Rep: Reputation: 0
Question Anyway to scan for entry scripts on a website?


This is shot in the dark but I have a customer who keeps getting random files dropped into his domain. The hacker must have a backdoor somewhere or in several places to be able to add the file even after it's removed and in different places.

I just can't find it anywhere.

I was thinking I could do a file content search if there was a common denominator with all or most back door scripts. Like an upload snippet or something.

Thanks,
Charles
 
Old 09-19-2015, 12:32 PM   #2
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
Bullet 1
 
Old 09-19-2015, 04:14 PM   #3
dwhswebhosting
LQ Newbie
 
Registered: Jun 2004
Location: Earth
Distribution: CentOS 6 and 7
Posts: 27

Original Poster
Rep: Reputation: 0
Quote:
Originally Posted by Habitual View Post
Sorry.

distribution - Centos
version - 6.5
hardware details - Intel server mobo, raid 10, 96 gigs of ddr ram, enterprise hard drives
application version - Apache 2.2 with CPanel
exact error messages where applicable. - In the web public space of the domain, /home/username/public_html/ there is a file that allows a hacker access to add more files which are being used to send mass email. Our system blocks the email from being sent but it still is an issue that the hacker can add files into the public domain.

The files that are added are using phpmailer to send the mail.

The file used to allow the hacker access we cannot find.
 
Old 09-19-2015, 04:59 PM   #4
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
Wordpress or anything like that?
 
Old 09-19-2015, 05:03 PM   #5
dwhswebhosting
LQ Newbie
 
Registered: Jun 2004
Location: Earth
Distribution: CentOS 6 and 7
Posts: 27

Original Poster
Rep: Reputation: 0
Yeah it has WHMCS a hosting manager script.

That is the only php files that are on the site. So it has to be in there somewhere and all the drop files are in the scripts folder as well which is kind of a clue.
 
  


Reply

Tags
backdoor



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Scan a website with OpenVAS? turiyain Linux - Newbie 6 06-21-2012 01:25 AM
LXer: Bash scripts to scan and monitor network LXer Syndicated Linux News 0 05-13-2010 12:00 AM
testing shell scripts before entry into crontab. bartonski Linux - Server 1 10-15-2009 08:28 PM
Making Cron entry through perl scripts devkpict Linux - Software 1 10-20-2007 07:40 AM
so what does this entry in iwlist wlan scan mean ? dimgr Linux - Wireless Networking 0 05-12-2005 10:13 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:48 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration