3
I noticed an unusual activity on my site (e-commerce opencart 2.0.2.0)
this is the command they used
I don’t know exactly what it looks like exploiting a php fault and entering a backdoor I have the code q was injected or not yet apparently he deleted the text from the server he was on but I made a copy in case someone wants to analyze me let me know I send.
Now my question how to know if his attack was successful how to fix the problem?
This was the file that he inserted http://49.212.157.58/policy/r.txt, it seems to be a PHP function, you noticed some different file?
– KhaosDoctor
It is not a security flaw in PHP. It is merely a ridiculous attempt at "php Injection". It happens thousands of times every day on every website.. In your case, the parameters themselves do absolutely nothing.
– Daniel Omine
@Danielomine this should be for "old things" php.
– Wallace Maxters