Skip to content

Commit cff8657

Browse files
committed
explain locations
1 parent 70f1fea commit cff8657

File tree

1 file changed

+2
-2
lines changed
  • found_on_drupal/found_due_to_cve_2018_7600

1 file changed

+2
-2
lines changed

found_on_drupal/found_due_to_cve_2018_7600/README.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ They are the direct result of [CVE-2018-7600](https://www.drupal.org/sa-core-201
66

77
The pattern:
88

9-
- search.php, dump.php & wp-post.php: same filename everywhere
10-
- favicon_0ac3c0.ico: the `0ac3c0` part is a variable hash every time
9+
- search.php, dump.php & wp-post.php: same filename everywhere. Always in the root of the Drupal installation.
10+
- favicon_0ac3c0.ico: the `0ac3c0` part is a variable hash every time. The file gets dumped somewhere in the `/themes/` directory.
1111

1212
These can easily be found & detected through a combination of [Maldet](https://www.rfxn.com/projects/linux-malware-detect/) and regex-searches on functions like `eval`, `gzinflate`, etc.

0 commit comments

Comments
 (0)