i have a customer whose php web site has been hacked.
the index.php in a forum starts to load the page but then comes up with a black screen with Whackerz-Pakistan on it.
First, you need to see the extent of the damage done. The hackers may not have stopped with defacing a website. They may have added or modified programs or data elsewhere on your system.
Second, you need to figure out how they got in.
Third, you need to lock down your operating system and services on this machine to stop them from getting in again.
If and only if you have done all of the above is it time to look at PHP.
All of that is very true. Also, it may depend on what kind of "php web site" it is. Some of the packaged CMS's (Nukes, e107, drupal, etc.) allow for file uploads. There have been vulnerabilities in the past with some of these.
Hacker: "I'd like to upload a file called index.php to /var/
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.