Web 2.0 Tutorials

11 Feb, 2008

A hacker came by with c99madshell v. 2.0 madnet edition

Posted by: admin In: Asides| blog updates| wordpress

*Update: Okay, I think I located the potential entry to the WP-Forum, which I have read having some security issues coming up lately. It has now been removed from this site. * 

Alright, not really what I wanted to happen on a Monday evening.

I came home, and just before I started to make dinner, I went to check my mail, in there was a mail from an advertiser that an ad was not showing, and naturally I went to the site to check.

Lo and behold, my site was hacked, and the hacker installed the c99madshell v. 2.0 on my domain.

Searching for information I found only vague information, and never really found out how the ‚Ǩ#”%”‚Ǩ# hacker came in.

I started by updating my Wordpress installation to the latest version, and then went hunting. I found the script in my themes folder, where it replaced one the .php files.

The only information I found that gave any clue to where to look was here: http://www.devside.net/blog/smf-exploit-like-phpbb-hack

I included below screenshot, which is from the same blog-entry (credit where credit is due) since I focused on removing the hack instead of documenting it. I hope the owner does not take offence.

c99sh_1_2.jpg

Removing it was fairly easy once I knew where to look, but I had to have a serious look around to see where it was hidden.

So, what did I learn from this? To backup, backup often, and to always update my Wordpress installations.

Have you had a visit?

This post might be interesting for you as well: ASP Tutorials, or by reading other entries on this website.
Tags: advertise, blog, tutorial, wordpress

Related posts

4 Responses to "A hacker came by with c99madshell v. 2.0 madnet edition"

1 | me too

February 27th, 2008 at 3:55 pm

Avatar

I have. I found an index.php in a folder that didn’t have one before. The contents were wrapped up like described at http://danilo.ariadoss.com/2006/01/04/decoding-eval-gzinflate-base64_decode/

After decoding it I found a reference to c99madshell inside and have found a couple references on the web to c99 shell.

The person that put it there seemed to be after my Wordpress installation even though I can’t say for sure yet how they got the shell on my host in the first place.

2 | admin

March 6th, 2008 at 12:00 pm

Avatar

hi “me too” :-)

Thanks for the link, I am gonna try to decode the code and have a look.

I have no idea either how they got access to my host either, but I suspect a Wordpress problem that has not been fixed yet.

3 | jd

October 19th, 2008 at 4:49 pm

Avatar

I just found c99madshell on one of my sites on a shared server. In addition I found installed.php files a couple other domains on the same server. I’ve removed the files but need to determine how this happened.

What else should I be looking for? Please help!

4 | Denny

November 17th, 2008 at 2:26 am

Avatar

I also found a gzipped version of C99madShell v. 2.0 madnet edition on one of my servers. It appears the only purpose served was to drop tons of spam links in the footer of one of my Wordpress installations.

Does anyone have any more information on this? How to prevent it, repair it, log it, remove it… ???

Comment Form

Advertisers


  • Denny: I also found a gzipped version of C99madShell v. 2.0 madnet edition on one of my servers. It appears the only purpose served was to drop tons of spam
  • admin: Good point, I will add that to the next tutorial.
  • admin: Hi sagbee I think you're right. I should make a plugin for this. Let me think a little on how to do it, and I'll get on it. Good idea by the way

About

Tutorialvine.com showcases Web 2.0 Tutorials and News as well as everything about developing from Webdesign to how to maximize your revenue streams.


Top Commentators