Injection Blocked?
-
This showed up in my log tonight:
24/Feb/16 17:59:31 #3855502 critical – 192.185.4.18 POST /index.php – BASE64-encoded injection – [POST:z0 = ZXZhbCgiZWNobygxMjM0NTQzMjArMSk7ZXhpdCgpOyIp]and this is from Wordfence:
File appears to be malicious: wp-content/nfwlog/firewall_2016-02.php
Filename: wp-content/nfwlog/firewall_2016-02.php
File type: Not a core, theme or plugin file.
Issue first detected: 1 hour 6 mins ago.
Severity: Critical
Status New
This file appears to be installed by a hacker to perform malicious activity. If you know about this file you can choose to ignore it to exclude it from future scans. The text we found in this file that matches a known malicious file is: “ZXZhbC”.I am hoping that NF blocked the injection and WF is flagging the log because it contains the name “ZXZhbC”.
Is this true?
Thanks!
- The topic ‘Injection Blocked?’ is closed to new replies.