If I was hacked and files were placed on my server, including a 'web shell' I would be very afraid I don't catch everything and it just gets re-hacked.
Unless this is just a pure curiosity adventure in deobfuscation... then nevermind :)
If I was hacked and files were placed on my server, including a 'web shell' I would be very afraid I don't catch everything and it just gets re-hacked.
Unless this is just a pure curiosity adventure in deobfuscation... then nevermind :)
I spent a bit of time messing around with that approach, and came up with this: https://github.com/sgentle/hackcache
From my own experience, when one of my sites with username www-data was hacked (default apache installation), the client-side malware JS was injected into .htaccess file and added to ALL folders www-data had write access to.
What I am saying is, assume the worst, what other data could the cracked unix account do on the system.
Douse it with gasoline and toast some marshmallows as I spin up a new instance imo :)
Then you do have a reasonable idea of what's actually been modified after the fact.
The attacker could then arrange for any activity during the time they were active to be filtered - including the change to afick itself...
Do attackers ever try a double bluff and make an attack look like a "standard" script-kiddie attack - which might be regarded as something that can be recovered from without scrubbing the server and starting again, leaving the more sophisticated main attack in place?
[NB Been reading a lot of John le Carré recently, which probably explains the paranoia].
More to the point I don't use afick as a detection system but more as a cleanup tool. Typically in most wordpress hacks (I've probably dealt with about 8-10) you'll find that the attackers will target the theme because typically if you "replace all the files on the site" you can't replace the theme, it's unique, unless you've got a clean copy from a backup (assuming you know when the hack took place) then you can't easily replace it with known good code.
But the theme is also the part of the site that changes least, so even an afick database from the first day of the site is sufficiently useful in seeing what files (php, js) have been altered.
Typically, I end up installing afick after I get called in to clean up an existing hack. If it's been hacked once, it may well get hacked again, so I install afick to make the cleanup job easier the second time around.