Malicious code in *.php files

Discussion regarding Joomla! 1.5 security issues.
Joomla! Vulnerable Extensions: http://feeds.joomla.org/JoomlaSecurityV ... Extensions

Moderator: General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Security Checklist
Forum Post Assistant - If you are serious about wanting help, you will use this tool to help you post.
Locked
josebalmeida
Joomla! Fledgling
Joomla! Fledgling
Posts: 1
Joined: Mon Jun 03, 2013 2:57 pm

Malicious code in *.php files

Post by josebalmeida » Mon Jun 03, 2013 3:05 pm

Hello!

My hosting provider says my site have malicious code in *.php files. The code is:

eval(code);

However I can't find it.

I run joomla Forum Post Assistant but I don't see nothing about an eval() code.

Thanks
José Almeida

Cholent MT
Joomla! Guru
Joomla! Guru
Posts: 822
Joined: Mon Apr 01, 2013 5:15 pm
Location: Las Vegas, NV USA
Contact:

Re: Malicious code in *.php files

Post by Cholent MT » Mon Jun 03, 2013 3:46 pm

What you just sent its' self is not malicious, but can be used in an injection attack. IF it is there it is best to properly adjust the code to help prevent this sort of attack.

Have you tried inserting your files into somewhere like notepad++ and using the search function?

Sometimes in all that code our eyes miss things. But the search and find function always wins. haha
http://www.thehonorablehacker.com
Hacking For Honor
A Blog To Learn Everything From Ethical Hacking To Design & Marketing!


Locked

Return to “Security in Joomla! 1.5”