Welcome, Guest. Please login or register.
Did you miss your activation email?
May 26, 2012, 07:39:49 AM

Login with username, password and session length
Search:     Advanced search
Interested in joining the WebsiteBaker team?
For more Information read here or on our new website.
155534 Posts in 21713 Topics by 7737 Members
Latest Member: chris85
* Home Help Search Login Register
Pages: [1]   Go Down
Print
Author Topic: hacked Backdoor.PHP.Rst.ap  (Read 635 times)
Xagone
AddOn Development
*
Offline Offline

Posts: 478



WWW
« on: July 15, 2010, 04:22:47 PM »

one of my clients website baker install has been hacked with Backdoor.PHP.Rst.ap
the file was placed in templates
I dont know much about this backdoor, I will try to see if a vulnerability in WSB is at fault or the server, if it's WSB I'll let you know

in the mean while, if somebody know something about this, you can help Wink
Logged

Xagone Inc. (formerly VotreEspace)
http://www.xagone.com/
Waldschwein
Guest
« Reply #1 on: July 15, 2010, 04:31:07 PM »

Hmm, it could be anything. The best is to search in your server logs, and look where, when and so on they put this file.
Here is (an old) thread: http://forums.invisionize.com/Hacked-t104276.html

If you search "websitebaker" with google blogsearch you'll see an CSRF hack, but it's a bit more complicated to explain how that's working and I doubt it has to do with Backdoor.PHP.Rst.ap ...

Yours Michael
Logged
Xagone
AddOn Development
*
Offline Offline

Posts: 478



WWW
« Reply #2 on: July 15, 2010, 04:36:15 PM »

this backdoor has to be installed in a template to work, but I think the hacker dont know wsb, it install itself as if it was a joomla or a wordpress in templates, so wsb is not as evident in this site (admin has been cache, displaced and secured)
Logged

Xagone Inc. (formerly VotreEspace)
http://www.xagone.com/
Pages: [1]   Go Up
Print
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines Valid XHTML 1.0! Valid CSS!