pack of crapfiles from compromised site

All about creating websites!
Post Reply
User avatar
bad_brain
Site Owner
Site Owner
Posts: 11636
Joined: 06 Apr 2005, 16:00
19
Location: In your eye floaters.
Contact:

pack of crapfiles from compromised site

Post by bad_brain »

now that was the most pwnd site I have seen yet... :lol:
website of a client, I did the initial site but then they had the great idea to hire a cheapo SEO company for a make-over, after a quick convo I knew they have zero technical knowledge....so it was just question of time until it gets funny.

anyway, when logging in I was instantly alarmed by the server load of 2, which is not much but still much more than usual. processes showed lots of processed by the user/owner of the site and a quick log check did the rest.

most funny is a whole new directory in the site root containing 2023 .php crapfiles... :lol:

if you want to have a look: https://file.io/MyPtJBDN" onclick="window.open(this.href);return false;
Image

User avatar
bad_brain
Site Owner
Site Owner
Posts: 11636
Joined: 06 Apr 2005, 16:00
19
Location: In your eye floaters.
Contact:

Re: pack of crapfiles from compromised site

Post by bad_brain »

the first files seem to be mostly spam/phishing pages, attached the shell stuff I found by a quick look.
Attachments
1.zip
(48.67 KiB) Downloaded 150 times
Image

User avatar
ayu
Staff
Staff
Posts: 8109
Joined: 27 Aug 2005, 16:00
18
Contact:

Re: pack of crapfiles from compromised site

Post by ayu »

Funny how I'm reading this now. This exact thing happened to me yesterday xD.
Client called in panic and said their WP site had been hacked. Spend all day yesterday cleaning it all up xD
"The best place to hide a tree, is in a forest"

User avatar
computathug
Administrator
Administrator
Posts: 2693
Joined: 29 Mar 2007, 16:00
17
Location: UK
Contact:

Re: pack of crapfiles from compromised site

Post by computathug »

bad_brain wrote:
09 Jun 2020, 14:58
now that was the most pwnd site I have seen yet... :lol:
website of a client, I did the initial site but then they had the great idea to hire a cheapo SEO company for a make-over, after a quick convo I knew they have zero technical knowledge....so it was just question of time until it gets funny.
Phewww, glad i'm not cheap :-99
The devil can cite Scripture for his purpose.
-- William Shakespeare, "The Merchant of Venice"
https://tshirt-memes.com

User avatar
bad_brain
Site Owner
Site Owner
Posts: 11636
Joined: 06 Apr 2005, 16:00
19
Location: In your eye floaters.
Contact:

Re: pack of crapfiles from compromised site

Post by bad_brain »

computathug wrote:
17 Nov 2020, 15:11
Phewww, glad i'm not cheap :-99
also we have the technical skills to blame the clients when one of our sites gets hacked....which is usually even true... :lol:
Image

Post Reply