PHP Code Obfuscation

info Nessus Network Monitor Plugin ID 6926

Synopsis

NNM detected a suspicious PHP file using obfuscation.

Description

NNM Detected a suspicous PHP file using obfuscation.

Solution

Remove any instances of the script and conduct a forensic examination to determine how it was installed as well as whether other unauthorized changes were made.

See Also

http://www.sophos.com/security/analyses/viruses-and-spyware/phpc99shella.html

Plugin Details

Severity: Info

ID: 6926

Family: Backdoors

Published: 7/9/2013

Updated: 1/16/2019

Vulnerability Information

CPE: cpe:/a:php:php