I've noticed random shared hosting users get affected (usually WP installs) by randomly named .php scripst that contain malicious spam mailing code.
Example, very similar to a handful I found today from various legitimate users:
Ran Rkhunter, similar results on 3 cPanel boxes:
Example, very similar to a handful I found today from various legitimate users:
Code:
- Removed -
Code:
/sbin/ifdown [ Warning ]
/sbin/ifup [ Warning ]
/usr/bin/GET [ Warning ]
/usr/bin/ldd [ Warning ]
/usr/bin/whatis [ Warning ]
Checking if SSH root access is allowed [ Warning ]
Checking /dev for suspicious file types [ Warning ]
Checking for hidden files and directories [ Warning ]
Checking version of OpenSSL [ Warning ]
Last edited by a moderator: