• mvvvmd

    (@mvvvmd)


    Hello,

    Since yesterday attackers have been uploading webshells to my /tmp directory using POST requests to /wp-admin/admin-ajax.php. I have WP and all plugins fully patched and am trying to figure out how to block these uploads. My AV scanner is so far deleting the files which does stop the attacks.

    What I am seeing in the logs is a 4 second burst of these POST requests from the same IP with a different user agent for every request.

    POST /wp-admin/admin-ajax.php HTTP/1.0" 403

    Then right away my AV software reports it deleted a file like this about 60 times

    /tmp/php6cs0t9 Generic.PHP.WebShell.X.A18DB3F0

    What is strange is that the requests does return a 403, there are no other POST request at the time of the AV reports. I do run Wordfence, possibly this blocks the request after the upload takes place. Does anyone have a ideas on how to deal with this?

Viewing 3 replies - 1 through 3 (of 3 total)
  • Moderator threadi

    (@threadi)

    You mentioned WordPress and the plugins – what about your theme?

    Also, check if you have any “must-use” plugins. If any look unfamiliar, delete them.

    Examine the wp-config.php file to see if it contains anything that looks suspicious.

    Check the entire uploads directory to see if there are any PHP files inside. Some plugins write files there, but if you don’t recognize them, delete them.

    Also, go ahead and delete all language files in wp-content/languages/. Hackers often hide code inside their PHP files. Once deleted, WordPress will download fresh copies.

    If you have a wp-content/cache directory, delete that as well; the plugins that need it will recreate it.

    In general, keep an eye out for any files that don’t seem to belong to anything.

    Delete the wp-admin and wp-includes directories and re-upload their contents from a fresh download (matching your specific WordPress version) obtained from https://wordpress.org/download/releases/.

    If you’d rather avoid that effort, check if you have a clean backup and restore it.

    Afterward, you should take a look at this resource: https://developer.wordpress.org/advanced-administration/security/hardening/

    Thread Starter mvvvmd

    (@mvvvmd)

    I have not seen any indication of the attack being successful, my AV software is stopping the attempts. I also have done various checks to see if anything is out of order, this is not the case.

    I would like to know if there is a way to block these uploads to /tmp. Idealy I would like to figure out what they are exactly doing to get the files written /tmp.

    Moderator threadi

    (@threadi)

    If you want to know how to stop this, you need to figure out the path the request takes. You can send all sorts of things to the AJAX endpoint, but only a function that exists in your project could cause data to be stored in the /tmp directory. That function, in turn, could come from any part of your project. You need to find it. My list above can be a helpful tool for that. WordPress itself doesn’t do this.

Viewing 3 replies - 1 through 3 (of 3 total)

You must be logged in to reply to this topic.