Skip to content

Commit 164deae

Browse files
committed
modules too
1 parent cff8657 commit 164deae

File tree

1 file changed

+1
-1
lines changed
  • found_on_drupal/found_due_to_cve_2018_7600

1 file changed

+1
-1
lines changed

found_on_drupal/found_due_to_cve_2018_7600/README.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,6 @@ They are the direct result of [CVE-2018-7600](https://www.drupal.org/sa-core-201
77
The pattern:
88

99
- search.php, dump.php & wp-post.php: same filename everywhere. Always in the root of the Drupal installation.
10-
- favicon_0ac3c0.ico: the `0ac3c0` part is a variable hash every time. The file gets dumped somewhere in the `/themes/` directory.
10+
- favicon_0ac3c0.ico: the `0ac3c0` part is a variable hash every time. The file gets dumped somewhere in the `/themes/` or `/modules/` directory.
1111

1212
These can easily be found & detected through a combination of [Maldet](https://www.rfxn.com/projects/linux-malware-detect/) and regex-searches on functions like `eval`, `gzinflate`, etc.

0 commit comments

Comments
 (0)