3 ms·
Unobfuscating and Attack - a look into an evil PHP script
- jtagen 16y agoSeriously? Who allows uploads to a web-accessible directory with execution enabled? There are so many options that can be transparently used to protect against this without randomly searching for uploaded web scripts.
- alanpca 16y agoIt was uploaded through a client account via sftp, not injected into the actual directory by any other means. I think that's outlined in the post.