- Joined
- Aug 14, 2014
- Messages
- 100
- Reaction score
- 0
Their calling card is changing the /var/www/html/index.php file to give a 301 moved error that points to google.com
There was an empty /admin/readme.php which the exploit probably created. From there I think they were able to inject a file and that is probably how they got access. This was an updated system so this may be a new exploit. They were also looking for the vtiger directory but that had been removed from this system because of all the exploits on it.
There was an empty /admin/readme.php which the exploit probably created. From there I think they were able to inject a file and that is probably how they got access. This was an updated system so this may be a new exploit. They were also looking for the vtiger directory but that had been removed from this system because of all the exploits on it.