Skip to main content

File on some accounts with suspicious code .cpanel_config.php

Comments

6 comments

  • Infopro
    You might find this link helpful: /http://wordpress.org/plugins/instant-suggest/
    0
  • speckados
    What interest there're on you link? Plugin of WP? Please extend your comments. Thanks.
    0
  • Infopro
    That's where that plugin originally came from, I suspect. Or some version of it. You might download that version from the reputable site, wordpress.org at that link provided and check its files against the files on your server. You might also ask your users where this file was found, if they installed this plugin. If you suspect a security issue here and not sure what to do next, you might want to hire a professional to assist you with that. The cPanel AppCat should be helpful in locating someone: [url=http://applications.cpanel.net/]cPanel App Catalog That file, where ever it came from, is clearly not a cPanel file, or issue. My linking you to some place where you might find out more Info, should have been enough to assist you in the right direction. The rest of my suggestions here should already be a known thing, I think. I am interested to know why you'd post here on this forum about this though.
    0
  • quietFinn
    I have seen that file uploaded in many accounts in out servers. CXS (ConfigServer eXploit Scanner) detects and quarantines it. Seems that Joomla's extplorer component is used, but I have no idea how... As "first aid" I have password protected Joomla's administrator folder in those accounts.
    0
  • mtindor
    I concur with quietFinn... com_extplorer appears to be the target. I too have seen these attempts intercepted on many machines. 10.20.30.40 - - [18/Dec/2013:23:10:50 -0500] "GET /administrator/components//com_extplorer/ HTTP/1.1" 301 266 "-" 10.20.30.40 - - [18/Dec/2013:23:10:51 -0500] "GET /administrator/components/com_extplorer/ HTTP/1.1" 302 - "-" 10.20.30.40 - - [18/Dec/2013:23:10:51 -0500] "GET / HTTP/1.1" 200 69941 "-" 10.20.30.40 - - [18/Dec/2013:23:10:52 -0500] "POST / HTTP/1.1" 200 69619 "http://somedomain.ext/administrator/components//com_extplorer/" 10.20.30.40 - - [18/Dec/2013:23:10:54 -0500] "POST / HTTP/1.1" 404 - "http://somedomain.ext/administrator/components//com_extplorer/" 10.20.30.40 - - [18/Dec/2013:23:10:50 -0500] "GET /administrator/components//com_extplorer/ HTTP/1.1" 301 266 "-" 10.20.30.40 - - [18/Dec/2013:23:10:51 -0500] "GET /administrator/components/com_extplorer/ HTTP/1.1" 302 - "-" 10.20.30.40 - - [18/Dec/2013:23:10:51 -0500] "GET / HTTP/1.1" 200 69941 "-" 10.20.30.40 - - [18/Dec/2013:23:10:52 -0500] "POST / HTTP/1.1" 200 69619 "http://somedomain.ext/administrator/components//com_extplorer/" 10.20.30.40 - - [18/Dec/2013:23:10:54 -0500] "POST / HTTP/1.1" 404 - "http://somedomain.ext/administrator/components//com_extplorer/" 10.20.30.40 - - [18/Dec/2013:15:54:44 -0500] "GET /administrator/components//com_extplorer/ HTTP/1.1" 200 1128 "-" 10.20.30.40 - - [18/Dec/2013:15:54:45 -0500] "POST /administrator/components//com_extplorer/ HTTP/1.1" 404 - "http://someotherdomain.ext/administrator/components//com_extplorer/" 10.20.30.40 - - [18/Dec/2013:15:54:45 -0500] "POST /administrator/components//com_extplorer/ HTTP/1.1" 404 - "http://someotherdomain.ext/administrator/components//com_extplorer/" 10.20.30.40 - - [18/Dec/2013:15:54:44 -0500] "GET /administrator/components//com_extplorer/ HTTP/1.1" 200 1128 "-" 10.20.30.40 - - [18/Dec/2013:15:54:45 -0500] "POST /administrator/components//com_extplorer/ HTTP/1.1" 404 - "http://someotherdomain.ext/administrator/components//com_extplorer/" 10.20.30.40 - - [18/Dec/2013:15:54:45 -0500] "POST /administrator/components//com_extplorer/ HTTP/1.1" 404 - "http://someotherdomain.ext/administrator/components//com_extplorer/"
    Given the GIF89a at the top, I suspect they are attempting to upload it to the server as a gif [because com_extplorer probably doesn't allow files with .php extensions to be uploaded] and then renaming it once it is on the server should they get that far. And yeah, I heavily massaged that log exerpt. M
    0
  • caeos
    extplorer is currently a vulnerable joomla extension [url=http://vel.joomla.org/live-vel.html]Live VEL the file is very similar to
    0

Please sign in to leave a comment.