PDA

View Full Version : Security: Block File Name C99sh.php


hostroyal
12-21-05, 02:05 AM
I would personally recomend after seeing this you try your best to remove this file name. I had found it uplaoded somehow on my accoutn after a little reaserch i found it was responsible for attemted hack of my server. All the user needs to do is upload the file C99sh.php

These are 2 screenshots found on the hacking site i found out about this file
http://img477.imageshack.us/img477/2929/c9922gj.gif
http://img477.imageshack.us/img477/6209/c996vt.gif

jpetersen
12-27-05, 09:07 AM
Hi,

This is just one of many "php shells". Its existence on your account is the symptom of a greater problem. Should your account get hacked again, my recommendation would be to note the timestamp on any files uploaded by the attacker(s), then search your domain logs for any activity that occurred around that time. While timestamps can be easily changed, many attackers simply don't bother to do this. Of course, your account wasn't necessarily attacked via a vulnerability in one of your websites, but this is a good place to start.

GordonH
12-27-05, 12:26 PM
In my experience these are commonly uploaded using insecure image upload scripts. e.g. photp galleries or even avatar upload scripts in bulletin boards.