Alleged malicious code
-
Got this a few days ago from my host:
This notice is to inform you that we have detected malicious code in your website files. We have compiled a list of compromised files on your account, as well as the code injected, below.
In order to maintain a secure hosting environment, we will be automatically correcting these compromised files on your account; however, please be aware that you are responsible for verifying that the content hosted within your account is secure. We strongly advise that you update your installed scripts and software, as outdated scripts and software are the most frequently used method for accessing and gaining control of a targeted account.
If you need assistance updating the software on your hosting account, please do not hesitate to contact our Support department.
The compromised files detected are:
/home4/mademer1/public_html/globalindieauthor/wp-includes/js/tinymce/utils/ossdl-cdn.php
The malicious code detected is similar to:
Files with the following contents or MD5SUMs, which contain malicious code:
\$default_action\s*=\s*[‘”]FilesMan[‘”]\s*When I check the directory, the ossdl-cdn.php is absent. So I cannot tell if my host removed it because “we will be automatically correcting these compromised files on your account” or because the files are hidden.
I have looked this up and there are several examples of the same warning from one’s host provider but each time the alleged offending file is different.
Any ideas as to how I can verify and remove this code?
Thanks.
The topic ‘Alleged malicious code’ is closed to new replies.