Main
Index
Search
Posts
Who's
Online
Log
In

Home: Products: Classic Products - Community Support Forum:
AM 1 advice about suspicious files in the publish folder

 

 


tribulatio
User

Jan 7, 2012, 9:00 AM

Post #1 of 4 (6540 views)
Shortcut
AM 1 advice about suspicious files in the publish folder Can't Post

For a website that is not updated frequently, I continue to use... AM 1.2. And it works flawlessly, there are only a few hundreds of articles, a few more every year - so I do not see any need to change.

But anyway, the purpose of this post is not to advertise past versions of AM! I have come across something suspicious, and before attempting to delete the items, I would like to have expert opinion.

I do publish all the articles in one folder, called /p. Yesterday, as I was testing a cloud backup service for that website and other ones (myRepono.com, a quite interesting tool at affordable price), I noticed that it could not backup two files that are found in that folder. The names of those files are:
include.php
report.php
There is also a third file called: index.php
I attach a screen capture showing how they look in cPanel.

It is impossible to open include.php and report.php, impossible also to download them in order to analyze their content locally. And the backup system cannopt back them up.

The website was hacked a year ago (not first time), and I suspect those are legacy files from that hacking. This suspicion is reinforced by the content of index.php, the only one I am able to open. It reads:
"<!-- Placeholder file for previously hacked file that contained string HackeD By [hacker's name] -->
Lines of code follow.

Before attempting to remove those three files, or asking the webhost to remove them if it is impossible for me to erase them, I just want to be sure: there is no way AM 1.2 could produce in the publish folder such php files, correct?

Thank you for confirming that! The files must have been there for quite a long time, and I prefer to ask before erasing them.
Attachments: Capture d’écran 2012-01-07 à 17.46.04.png (10.0 KB)


tribulatio
User

Jan 13, 2012, 7:49 AM

Post #2 of 4 (6522 views)
Shortcut
Re: [tribulatio] AM 1 advice about suspicious files in the publish folder [In reply to] Can't Post

No comment... OK, I will go ahead and ask the hosting service to delete them, hoping it will be the right decision.


Dave
Staff


Jan 13, 2012, 12:54 PM

Post #3 of 4 (6517 views)
Shortcut
Re: [tribulatio] AM 1 advice about suspicious files in the publish folder [In reply to] Can't Post

Hi tribulatio,

If you change the permissions (chmod) on the files you should be able to download them. And if you email them to me at dave@interactivetools.com or attach them to this thread I can take a look. But you're probably safe deleting them.

Hope that helps!

Dave Edis - Senior Developer
interactivetools.com
 


tribulatio
User

Jan 13, 2012, 1:02 PM

Post #4 of 4 (6513 views)
Shortcut
Re: [Dave] AM 1 advice about suspicious files in the publish folder [In reply to] Can't Post

Thank you very much, Dave! Good suggestion that I should have changed the permissions. If it should happen again, I would do that.

Anyway, they have been deleted in the meantime - and everything seems to be working well on the website. In the publish folder of AM 1, where I have never put any other content, I just don't see any reason why .php files should be found.

For one of my websites, I might sooner or later go up to CMS Builder, while managing other articles with AM 1. I assume that both can run side by side, as long as I keep the published articles in clearly separated folders - but this would by a topic for another thread.

Thank you again for having shared your suggestions!