3 ms·
The presence of an "eval" makes it pretty obvious that there was something going on. The only clever thing here is putting the code after the GPL text that usu
by TheYComb 13y ago
The presence of an "eval" makes it pretty obvious that there was something going on.
The only clever thing here is putting the code after the GPL text that usually nobody reads.
Does not Joomla community code reviews the contribution to their code base?
- fein 13y agoThe fact that $_REQUEST was used is a huge red flag as well. edit: I should expand a bit: $_REQUEST is a nono, it should be $_GET or $_POST depending on the request. The actual badness of request is that it also contains everything in $_COOKIE as well.
- ipax 13y agoAs I mentioned in the article the code was inserted into a good core file from Joomla as part of a malicious attack. Thanks for the comment.
- dave1010uk 13y agoThis was found on a deployed instance, rather than in the main Joomla source repository or download? The article doesn't make this clear.