Thanks Everett.
Just tried it on a local copy of 1.0.8 the full results are :
./manager/actions/export_site.static.php
./manager/actions/files.dynamic.php
./manager/includes/document.parser.class.inc.php
./manager/media/browser/mcpuk/connectors/php/connector.php
./manager/media/rss/extlib/Snoopy.class.inc
./manager/media/rss/rss_cache.inc
./manager/processors/cache_sync.class.processor.php
All of which seem legit, off to test some live sites!
-
☆ A M B ☆
- 2,475 Posts
Yep, that's part of it -- EHLO is a telnet command.... I think all the backdoor scripts were all keeping tabs on one script with that telnet command that was used to send spam email.