LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - General
User Name
Password
Linux - General This Linux forum is for general Linux questions and discussion.
If it is Linux Related and doesn't seem to fit in any other forum then this is the place.

Notices


Reply
  Search this Thread
Old 04-15-2013, 10:39 AM   #16
konsolebox
Senior Member
 
Registered: Oct 2005
Distribution: Gentoo, Slackware, LFS
Posts: 2,248
Blog Entries: 8

Rep: Reputation: 235Reputation: 235Reputation: 235

It's not the only script that should be found there. What it does only is send the cookie and other information of whoever is viewing the server to another server. And it could also reconfigured remotely via special parameters. It's not the one that propagates the lines to the other files.

Edit: Or perhaps not really if the toolkits delete themselves after making a successful propagation to another host, or just after after making the infection, or perhaps after some attempts or time limits. Perhaps also that the ones that make the attacks on the other servers have different setups.

Last edited by konsolebox; 04-15-2013 at 10:52 AM.
 
Old 04-16-2013, 09:36 AM   #17
rizlo
LQ Newbie
 
Registered: Apr 2013
Posts: 2

Rep: Reputation: Disabled
Hi all,
In my case the server compromission turned out to have nothing to do with Wordpress. It was a Joomla 1.5.x outdated template (beez) used to upload a very nasty PHP shell!
That php shell injected the js that points to http://abtt.tv/modules/mod_servises/ua.js, so if you see the same check your system for the presence of this shell.
I found 2 copy of the same shell, with 2 different names, one is mysite/templates/beez/958b.php and the other myothersite/templates/beez/28bc.php it's a modification of a known php backdoor shell. If someone is interested I'll post the shell code.
 
Old 04-16-2013, 08:20 PM   #18
chrism01
LQ Guru
 
Registered: Aug 2004
Location: Sydney
Distribution: Rocky 9.2
Posts: 18,356

Rep: Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751
This article talks about recent mass attacks via WP / Joomla http://www.theregister.co.uk/2013/04...bie_offensive/
 
Old 04-16-2013, 09:29 PM   #19
konsolebox
Senior Member
 
Registered: Oct 2005
Distribution: Gentoo, Slackware, LFS
Posts: 2,248
Blog Entries: 8

Rep: Reputation: 235Reputation: 235Reputation: 235
Quote:
Originally Posted by rizlo View Post
I found 2 copy of the same shell, with 2 different names, one is mysite/templates/beez/958b.php and the other myothersite/templates/beez/28bc.php it's a modification of a known php backdoor shell. If someone is interested I'll post the shell code.
I had my time studying the previous code already so I don't mind if you do.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] sed help. Search and replace multiple strings with one command. dbrazeau Programming 4 02-13-2013 11:45 AM
sed command search and replace zulkifal Linux - Newbie 8 11-26-2012 10:56 AM
Mass search and replace on php pages delphig Linux - General 1 02-08-2010 10:10 PM
Need command to search and replace text in file acascianelli AIX 12 04-11-2007 08:16 PM
problem in perl replace command with slash (/) in search/replace string ramesh_ps1 Red Hat 4 09-10-2003 01:04 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - General

All times are GMT -5. The time now is 11:08 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration