Virus code entered in PHP files

I have a website running on LAMP - Linux, Apache, mySQL and PHP. Over the past 2-3 weeks, PHP and jQuery files on my site have been infected by malware from gumblar.cn

I don’t understand how this malware enters my PHP files and how I can prevent it from happening again and again.

Any ideas?

UPDATE:

Looks like this is a cpanel exploit

+3
source share
10 answers

Your site is hacked , so crackers simply replace your files.

You should always update your Linux, Apache, MySQL, PHP, and PHP web programs whenever a security warning is issued.

Linux-, , , .

+22

, , , , .

, . PHP-, , ( , Wordpress phpBB), , (PHP, Apache ..).

. . , , ; , . , 26 . , .

-, , , -, . , ; , PHP, , .

, , , . , , .

( , , , ) , - , , , . .:)

+14

, , , - - .

gumblar.cn, , JS-Redirector-H. , , .

- , , . , . , .

, - , , . , , , Gallery (, PHP Gallery). , .

, . , .

+3

Google: http://safebrowsing.clients.google.com/safebrowsing/diagnostic?client=Firefox&hl=en-US&site=http://gumblar.cn ( )

. , .

PHP ( PHPBB, Mamboserver ). - PHP-, , ​​ .

, , . , (, ) ( ) PHP- ( ).

+3

PHP- - , PHP. , , :

1. - , PHP .

, , ( , , cookie,...), , . , . , , ( ), . Zend_Filter Zend Framework . .

2.they , PHP. - - / script , .

, , . , .

+2

, , SO - , , , / ppl .

, , ppl , , , , , .

: google gumblar.cn, , .

, , , :

  • Google , , . , , . "".
  • ( ) FRESH INSTALL!!
  • (, ) . , php, .
  • PHP, . , , , .
+1

/ . , :

1) TROJAN . , ( > ... Windows + R) "cmd" "regedit". , , Js: Redirector. , aVast Malware Bytes - ( , ). , , , , , .

2) , -, - inflash pdf-, , , t Internet Explorer!

, , , , Windows "", ( - ..), , , , , . , -IE ! , , .., , BAD Windows. : Windows , (aVast Web Shield + Network Shield).

3) , FTP-, , !

4) lceanup Malware aVast, , ".ctv"   14 . ( ), ( , , , , HiJackThis , , )

5) , , , !

6) FTP, IP- script/hacker .

7) "" , .

8) DONT ! aVast Home Edition "Web Shield", .

+1

, , .

ftp- - . , . , "", - ftp-, , , . ftp, , , IP-, . , IP- .

0

- -. - - - Apache, PHP , . , , PHP HTML . , , , . , , , , , , , ( ), , , , , .

Needless to say, I quickly switched hosting providers right after the infection of my site. My hosting provider was pretty bad in many other ways, but that was pretty much the final straw.

0
source

Source: https://habr.com/ru/post/1707462/


All Articles