3 ms·
The injected code disables error logging and allows remote users to execute arbitrary code on the server by submitting the 'g' and 's' parameters as part of a G
by bmohlenhoff 14y ago
The injected code disables error logging and allows remote users to execute arbitrary code on the server by submitting the 'g' and 's' parameters as part of a GET query string. It then looks for a file called 'lic.log' and aborts if it exists. Otherwise it decodes and decompresses a CURL script embedded in base64 before generating the 'lic.log' file, which prevents it from occurring more than once.
The real mystery is how that code got onto the development server to begin with. They can fix the zip file but it won't do much good if the machine is still compromised.
- Adirael 14y agoFrom what I gather on their post someone used a vulnerable Wordpress plugin to write onto the web server's filesystem, overwriting the latest.tar.gz file with it's own hacked version. You should be safe if you didn't update using that file.