View Single Post
Old 09-21-2009, 07:49 AM  
hjnet
Confirmed User
 
Join Date: May 2002
Location: European Union
Posts: 3,815
Quote:
Originally Posted by HEAT View Post
grep -R 696620287374 * > /home/backdoor.txt &
Did you check that the "696620287374" is the same in all backdoor files? Cause I think a "smart" hacker would use randomized files to ensure they're harder to detect


Quote:
Originally Posted by HEAT View Post
5. Find infected website files and edit/delete.

grep -R svrtsg:#9@#yliwvi:#mlmv@# * > /home/infected.txt &
For example I had to search for another piece of string to find my infected files, looks like the guy doesn't use the same code strings for his infections all the time





P.S. I'd REALLY like to break some kneecaps today
hjnet is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote