How to find a backdoor and block IP

Discussion in 'PHP' started by TheSyndicate, Dec 25, 2007.

  1. #1
    The creator of a script I bought said he seen some unusual activity on my log for admin.
    He said there might be some “script kiddie” that planted a script backdoor or something in my script so they can come inside even after I changed the pass.

    1. How can I find a backdoor in my script?
    2. What “free” script CGI PHP can block all IP but my country IP from getting into the admin page?
     
    TheSyndicate, Dec 25, 2007 IP
  2. wisdomtool

    wisdomtool Moderator Staff

    Messages:
    15,826
    Likes Received:
    1,367
    Best Answers:
    1
    Trophy Points:
    455
    #2
    You may want to install Rkhunter http://rootkit.nl/ to see if there is any back doors. You may also want to update or patch your kernels etc which are vulnerable.
     
    wisdomtool, Dec 25, 2007 IP
  3. TheSyndicate

    TheSyndicate Prominent Member

    Messages:
    5,410
    Likes Received:
    289
    Best Answers:
    0
    Trophy Points:
    365
    #3
    This program looks trough the files on my server or i download the files and then go let the program scan them?
    Does it work for WordPress blogs as well?

    thanks alot for the advice
     
    TheSyndicate, Dec 25, 2007 IP
  4. wisdomtool

    wisdomtool Moderator Staff

    Messages:
    15,826
    Likes Received:
    1,367
    Best Answers:
    1
    Trophy Points:
    455
    #4
    It will check the system but it will not be going through individual cgi programs unless it is a rootkit. What I suggest is maybe update your run the rkhunter and in the meantime update your wordpress to the latest version.
     
    wisdomtool, Dec 25, 2007 IP
  5. TheSyndicate

    TheSyndicate Prominent Member

    Messages:
    5,410
    Likes Received:
    289
    Best Answers:
    0
    Trophy Points:
    365
    #5
    Ok this is not WP i was just asking. What i need to know how i can find out if there is a hack or something on my script.
     
    TheSyndicate, Dec 25, 2007 IP
  6. coches

    coches Peon

    Messages:
    41
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #6
    check the source code.
    if u dont understand the language , show it to someone that does and that u trust.
     
    coches, Dec 26, 2007 IP
  7. TheSyndicate

    TheSyndicate Prominent Member

    Messages:
    5,410
    Likes Received:
    289
    Best Answers:
    0
    Trophy Points:
    365
    #7
    Yea ok but what to look for?
     
    TheSyndicate, Dec 27, 2007 IP