View Single Post
Old 09-22-2009, 09:57 AM  
hjnet
Confirmed User
 
Join Date: May 2002
Location: European Union
Posts: 3,815
Quote:
Originally Posted by HEAT View Post
Yes, all backdoors had the same strings starting with 6966202873 in my case.
Thanks, I've already found a few backdoor files in the thumbs folder of one of my ST installations. The string to search for is indeed "6966202873" on my backdoor files too

So people search your servers:

grep -R "6966202873" * > list_of_backdoor_files


Oh, and the backdoor files are called "sync.php, thumbs.php and backup.php" in my case, user:group -> nobody:nobody

Last edited by hjnet; 09-22-2009 at 10:00 AM..
hjnet is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote