We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 4310
    • 2,310 Posts
    Thanks Everett.
    Just tried it on a local copy of 1.0.8 the full results are :
    ./manager/actions/export_site.static.php
    ./manager/actions/files.dynamic.php
    ./manager/includes/document.parser.class.inc.php
    ./manager/media/browser/mcpuk/connectors/php/connector.php
    ./manager/media/rss/extlib/Snoopy.class.inc
    ./manager/media/rss/rss_cache.inc
    ./manager/processors/cache_sync.class.processor.php

    All of which seem legit, off to test some live sites!
      • 4310
      • 2,310 Posts
      Seems this will only find the hack support files.
      The actual files used for sending spam are better hidden.
      I found on a couple of hacked sites a combination of the following :
      ./manager/media/alias.php
      ./assets/plugins/tinymce/jscripts/tiny_mce/plugins/template/css/themes.php
      ./assets/modules/docmanager/templates/view.php

      Fortunately they are all the same code and can be found using :
      grep -rl 'EHLO $v0897acf4' .

        • 9207 ☆ A M B ☆
        • 2,475 Posts
        Yep, that's part of it -- EHLO is a telnet command.... I think all the backdoor scripts were all keeping tabs on one script with that telnet command that was used to send spam email.
          • 9207 ☆ A M B ☆
          • 2,475 Posts
          For the record, here's a good tool for scanning for malware on Linux machines: http://www.rfxn.com/projects/linux-malware-detect/