RSS Feed for This Post

Hunting for Backdoor scripts

a great disclosure from burmese hackers community for finding a backdoor scrips at your server. this isn’t so complicated since we use to search the php function that used by a backdoor / rooting script like c99 , r57 or erne shell. if you have use this scripts that mentioned. i think you should read this folowing sintax at that scripts:

  • exec — Execute an external program
  • passthru — Execute an external program and display raw output
  • shell_exec — Execute command via shell and return the complete output as a string
  • system — Execute an external program and display the output

  • proc_open — Execute a command and open file pointers for input/output
  • eval — Evaluate a string as PHP code
  • and an backtick operator (eg. echo ” `ls –R` “)

so what we have to do is search the mentioned strings. this is regural expression that we can use :

(`|exec|shell_exec|system|proc_open|passthru|eval)

that all, :D thanks to yehg community

Looking for similar article like this? Try with this search terms, You will automatically go to search page with the term: step by step using pwdump, tutorial shell R57, tutorial script r57, prevent hacking c99, !scan backdoor r57, , !scan backdoor r57, c99 shell injection, c99 injection tutorail, c99, intitle: phpMyAdmin Welcome to phpMyAdmin **** *running on * as root@, Welcome To Phpmyadmin Create New Database, telnet_crack, ssldump webmitm and arpspoof live cd, scanning for computers hack,

Trackback URL

RSS Feed for This PostPost a Comment

  • Meta

  • Partner links