Results 1 to 9 of 9

What's this file?

This is a discussion on What's this file? within the General Discussion forums, part of the vBSEO Google/Yahoo Sitemap category; This one: vbseo_sitemap/data/hits/files.php SOmeone told me it may be a malicious file, I would just like to make sure it ...

  1. #1
    Member
    Real Name
    Lorenzo
    Join Date
    Feb 2011
    Posts
    94
    Liked
    0 times

    What's this file?

    This one:
    vbseo_sitemap/data/hits/files.php

    SOmeone told me it may be a malicious file, I would just like to make sure it is not.

    Also, which should be the permission setting for that folder?


    Thank you.

  2. #2
    Member
    Real Name
    Lorenzo
    Join Date
    Feb 2011
    Posts
    94
    Liked
    0 times
    Sorry, wrong section… I reposted it here:
    What's this file?

    This one can be deleted if you want.

    Thank you

  3. #3
    vBSEO Staff Oleg Ignatiuk's Avatar
    Real Name
    Oleg Ignatiuk
    Join Date
    Jun 2005
    Location
    Belarus
    Posts
    25,744
    Liked
    169 times
    Hello,

    the file is not a part of vBSEO Sitemap Generator package, I would remove it asap.

    Also, which should be the permission setting for that folder?
    Permissions are set to 0777 for that folder by default, but there must be an .htaccess file in data/ folder that prevents direct access to any file there.

  4. #4
    Member
    Real Name
    Lorenzo
    Join Date
    Feb 2011
    Posts
    94
    Liked
    0 times
    Thank you. What about the permissions for that folder? I think now is 777…

  5. #5
    vBSEO Staff Oleg Ignatiuk's Avatar
    Real Name
    Oleg Ignatiuk
    Join Date
    Jun 2005
    Location
    Belarus
    Posts
    25,744
    Liked
    169 times
    Just edited my post above with reply to that.

  6. #6
    Member
    Real Name
    Lorenzo
    Join Date
    Feb 2011
    Posts
    94
    Liked
    0 times
    Thank you.
    What do you think this file was doing there?
    Attached Files

  7. #7
    vBSEO Staff Oleg Ignatiuk's Avatar
    Real Name
    Oleg Ignatiuk
    Join Date
    Jun 2005
    Location
    Belarus
    Posts
    25,744
    Liked
    169 times
    Hello,

    this looks like a hack attempt. If you are on shared server, possibly it was added from another account (folder is writable), but since http access to that folder is disallowed, it shouldn't have worked. You can check your access logs if there were any requests to that files.php URL though.

  8. #8
    Member
    Real Name
    Lorenzo
    Join Date
    Feb 2011
    Posts
    94
    Liked
    0 times
    Can you understand what that that file was supposed to do?

  9. #9
    vBSEO Staff Oleg Ignatiuk's Avatar
    Real Name
    Oleg Ignatiuk
    Join Date
    Jun 2005
    Location
    Belarus
    Posts
    25,744
    Liked
    169 times
    It looks like a "backdoor" script allowing to view files on server and/or run arbitrary code *if there would be open access to it*.

Similar Threads

  1. Css file
    By uaecasher in forum General Discussion
    Replies: 1
    Last Post: 09-16-2009, 07:23 AM
  2. Rewrite root/subfolder/file.php to root/file.php
    By shokmuzik.com in forum URL Rewrite Settings
    Replies: 1
    Last Post: 12-24-2008, 02:00 PM
  3. possible PSD of this file
    By sportsmedjosh in forum vBSEO.com Styles
    Replies: 3
    Last Post: 12-27-2007, 03:32 AM
  4. CSS in file
    By Przemysław Rejf in forum Template Modifications
    Replies: 3
    Last Post: 12-17-2006, 08:14 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •