<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
<channel>
<title>Question2Answer Q&amp;A - Recent questions tagged zp</title>
<link>https://www.question2answer.org/qa/tag/zp</link>
<description>Powered by Question2Answer</description>
<item>
<title>Got hacked by Russians. New files in qa-include, qa-plugin and theme folder discovered</title>
<link>https://www.question2answer.org/qa/26227/hacked-russians-files-include-plugin-theme-folder-discovered</link>
<description>

&lt;p&gt;
	File 1 discovered: &lt;strong&gt;stats.php&lt;/strong&gt;&lt;/p&gt;


&lt;p&gt;
	&amp;nbsp;&amp;nbsp; in folder /&lt;strong&gt;qa-include&lt;/strong&gt;/stats.php&lt;/p&gt;


&lt;p&gt;
	File 2 discovered: &lt;strong&gt;zp.php&lt;/strong&gt;&lt;/p&gt;


&lt;p&gt;
	&amp;nbsp;&amp;nbsp; in folder: /qa-plugin/&lt;strong&gt;q2a-edit-history&lt;/strong&gt;/zp.php&lt;/p&gt;


&lt;p&gt;
	&amp;nbsp;&amp;nbsp; in folder: /qa-theme/&lt;strong&gt;mobiles&lt;/strong&gt;/zp.php&lt;/p&gt;


&lt;p&gt;
	File 3 discovered: apps/facebook/&lt;strong&gt;class.php&lt;/strong&gt;&lt;/p&gt;


&lt;p&gt;
	&amp;nbsp; (it is a folder holding only an index.html, nothing else, so the hacker must have used a &quot;filemanger&quot; to find it)&lt;/p&gt;


&lt;p&gt;
	
&lt;br&gt;
	I uploaded all files to the github repository: &lt;a href=&quot;https://github.com/echteinfachtv/q2a-various&quot; rel=&quot;nofollow&quot;&gt;https://github.com/echteinfachtv/q2a-various&lt;/a&gt;&lt;/p&gt;


&lt;p&gt;
	File zp.php states &quot;&lt;span class=&quot;cm&quot;&gt;c99shell.php v.1.0 beta (îò 16.02.2005)&lt;/span&gt;&lt;/p&gt;


&lt;pre&gt;
&lt;span class=&quot;cm&quot;&gt;CCTeaM.&lt;/span&gt;&lt;/pre&gt;


&lt;pre&gt;
&lt;span class=&quot;cm&quot;&gt;WEB: ccteam.ru&lt;/span&gt;&lt;/pre&gt;


&lt;pre&gt;
&lt;span class=&quot;cm&quot;&gt;© Captain Crunch Security TeaM&lt;/span&gt;&lt;/pre&gt;


&lt;p&gt;
	&lt;span class=&quot;cm&quot;&gt;&quot;&lt;/span&gt;&lt;/p&gt;


&lt;p&gt;
	Please help.&lt;/p&gt;


&lt;p&gt;
	&amp;nbsp;&lt;/p&gt;


&lt;p&gt;
	@Scott: Could it be that they came throught the q2a edit plugin?&lt;/p&gt;


&lt;p&gt;
	@gidgreen: How could they write to the theme folder? Seeing the logs it seems that they came via &lt;span style=&quot;color:#ff0000;&quot;&gt;qa-include/stats.php&lt;/span&gt; ! But they did not put the stats.php by ftp. Seems that class.php is a filemanger, but could not find a trace yet how they put this file. Any tip?&lt;/p&gt;


&lt;p&gt;
	---&lt;/p&gt;


&lt;p&gt;
	I have not found any FTP access, so they must have been using a script. This is what I found in the server logs from 2013-07-19 (IP &lt;span style=&quot;color:#ff0000;&quot;&gt;128.72.113.203&lt;/span&gt; from Moscow, Russia): &lt;a href=&quot;https://github.com/echteinfachtv/q2a-various/blob/master/2013-07-19-log.txt&quot; rel=&quot;nofollow&quot;&gt;https://github.com/echteinfachtv/q2a-various/blob/master/2013-07-19-log.txt&lt;/a&gt;&lt;/p&gt;


&lt;p&gt;
	--&lt;/p&gt;


&lt;p&gt;
	&lt;strong&gt;What could that mean? What is the purpose of this attack?&lt;/strong&gt;&lt;/p&gt;


&lt;p&gt;
	&lt;strong&gt;PLEASE CHECK your own server files!&lt;/strong&gt;&lt;/p&gt;</description>
<category>Q2A Core</category>
<guid isPermaLink="true">https://www.question2answer.org/qa/26227/hacked-russians-files-include-plugin-theme-folder-discovered</guid>
<pubDate>Tue, 30 Jul 2013 05:38:16 +0000</pubDate>
</item>
</channel>
</rss>