• Resolved meregha

    (@meregha)


    Dear,
    the script is not able to scan this header.

    <?php if(!isset($GLOBALS[“\x61\156\x75\156\x61”])) { $ua=strtolower($_SERVER[“\x48\124\x54\120\x5f\125\x53\105\x52\137\x41\107\x45\116\x54″]); if ((! strstr($ua,”\x6d\163\x69\145″)) and (! strstr($ua,”\x72\166\x3a\61\x31”))) $GLOBALS[“\x61\156\x75\156\x61”]=1; } ?><?php
    /**
    * Edit plugin editor administration panel.
    *
    * @package WordPress
    * @subpackage Administration
    */

    /** WordPress Administration Bootstrap */

    https://wordpress.org/plugins/gotmls/

Viewing 2 replies - 1 through 2 (of 2 total)
  • Plugin Author Eli

    (@scheeeli)

    This is leftover from a threat that my plugin already removed from that file. The remaining code in the header is not a threat. I am working on a cleaner approach to removing this type of threat that will be released soon.

    If you have any other questions about this please feel free to ask.

    Aloha, Eli

    Thread Starter meregha

    (@meregha)

    Thanks Eli.

Viewing 2 replies - 1 through 2 (of 2 total)

The topic ‘Malware code’ is closed to new replies.