// you’re reading...

Asides

A hacker came by with c99madshell v. 2.0 madnet edition

*Update: Okay, I think I located the potential entry to the WP-Forum, which I have read having some security issues coming up lately. It has now been removed from this site. * 

Alright, not really what I wanted to happen on a Monday evening.

I came home, and just before I started to make dinner, I went to check my mail, in there was a mail from an advertiser that an ad was not showing, and naturally I went to the site to check.

Lo and behold, my site was hacked, and the hacker installed the c99madshell v. 2.0 on my domain.

Searching for information I found only vague information, and never really found out how the ‚Ǩ#”%”‚Ǩ# hacker came in.

I started by updating my Wordpress installation to the latest version, and then went hunting. I found the script in my themes folder, where it replaced one the .php files.

The only information I found that gave any clue to where to look was here: http://www.devside.net/blog/smf-exploit-like-phpbb-hack

I included below screenshot, which is from the same blog-entry (credit where credit is due) since I focused on removing the hack instead of documenting it. I hope the owner does not take offence.

c99sh_1_2.jpg

Removing it was fairly easy once I knew where to look, but I had to have a serious look around to see where it was hidden.

So, what did I learn from this? To backup, backup often, and to always update my Wordpress installations.

Have you had a visit?

Tags: advertise, blog, tutorial, wordpress

Related posts

Discussion

3 comments for “A hacker came by with c99madshell v. 2.0 madnet edition”

  1. I have. I found an index.php in a folder that didn’t have one before. The contents were wrapped up like described at http://danilo.ariadoss.com/2006/01/04/decoding-eval-gzinflate-base64_decode/

    After decoding it I found a reference to c99madshell inside and have found a couple references on the web to c99 shell.

    The person that put it there seemed to be after my Wordpress installation even though I can’t say for sure yet how they got the shell on my host in the first place.

    Posted by me too | February 27, 2008, 3:55 pm
  2. hi “me too” :-)

    Thanks for the link, I am gonna try to decode the code and have a look.

    I have no idea either how they got access to my host either, but I suspect a Wordpress problem that has not been fixed yet.

    Posted by admin | March 6, 2008, 12:00 pm
  3. document.body.innerHTML=”(:: Hacked By ulpian hajrullahu ::)”;

    Posted by document.body.innerHTML="(:: Hacked By ulpian hajrullahu ::)"; | July 4, 2008, 9:34 am

Post a comment