3 ms·
The attacker obfuscated "base64_decode" part but not "eval". It's not the first time I see base64_decode() being more the focus of attention than eval, I don't
by Yver 13y ago
The attacker obfuscated "base64_decode" part but not "eval". It's not the first time I see base64_decode() being more the focus of attention than eval, I don't know where it originates from.
Also, if cron infected the PHP files I wonder what infected the crontab. :\
- eponeponepon 13y agoPresumably PHP itself, no? Assuming it was running with a few too many permissions, or even under root...
- lmz 13y agoIt's the web user's own crontab judging by the lack of username in the file.
- Shish2k 13y agoI'd expect the old insecure joomla install was the original source of the infection, the cron was just there to automatically re-infect it without the attacker needing to run the same remote exploit repeatedly