{"id":484,"date":"2014-07-31T16:17:22","date_gmt":"2014-07-31T16:17:22","guid":{"rendered":"https:\/\/qbytes.cloud\/?p=484"},"modified":"2014-07-31T16:17:22","modified_gmt":"2014-07-31T16:17:22","slug":"php-spam-scripts","status":"publish","type":"post","link":"https:\/\/www.qbytes.cloud\/index.php\/2014\/07\/31\/php-spam-scripts\/","title":{"rendered":"PHP Spam Scripts"},"content":{"rendered":"<p>PHP Spam Scripts<\/p>\n<p>I finally decided this topic deserves its own page.<br \/>\nTo find the script sending spam<br \/>\nPlesk<\/p>\n<p>Ver -11.0<\/p>\n<pre class=\"brush: bash; title: ; notranslate\" title=\"\">\n\ncat \/var\/www\/vhosts\/domain.com\/statistics\/logs\/access_log | grep POST &gt; \/tmp\/post.log\n\n<\/pre>\n<p>Ver 11.5+<\/p>\n<pre class=\"brush: bash; title: ; notranslate\" title=\"\">\n\ncat \/var\/www\/vhosts\/system\/domain.com\/statistics\/logs\/access_log | grep POST &gt; \/tmp\/post.log\n\n<\/pre>\n<p>WHM cPanel<\/p>\n<pre class=\"brush: bash; title: ; notranslate\" title=\"\">\n\ncat \/usr\/local\/apache\/domlogs\/domain.com | grep POST &gt; \/tmp\/post.log\n\n<\/pre>\n<p>View the results<\/p>\n<pre class=\"brush: bash; title: ; notranslate\" title=\"\">\n\ncat \/etm\/post.log\n\n78.138.118.128 - - &#x5B;02\/Jan\/2014:10:51:41 -0500] &quot;POST \/tmp\/sys09725841.php HTTP\/1.1&quot; 200 181 &quot;-&quot; &quot;-&quot;\n78.138.118.128 - - &#x5B;02\/Jan\/2014:10:52:54 -0500] &quot;POST \/tmp\/sys09725841.php HTTP\/1.1&quot; 200 181 &quot;-&quot; &quot;-&quot;\n78.138.118.128 - - &#x5B;02\/Jan\/2014:10:54:13 -0500] &quot;POST \/tmp\/sys09725841.php HTTP\/1.1&quot; 200 181 &quot;-&quot; &quot;-&quot;\n78.138.118.128 - - &#x5B;02\/Jan\/2014:10:55:18 -0500] &quot;POST \/tmp\/sys09725841.php HTTP\/1.1&quot; 200 181 &quot;-&quot; &quot;-&quot;\n78.138.118.128 - - &#x5B;02\/Jan\/2014:10:56:32 -0500] &quot;POST \/tmp\/sys09725841.php HTTP\/1.1&quot; 200 181 &quot;-&quot; &quot;-&quot;\n\n<\/pre>\n<p>Joomla<\/p>\n<p>This file often appears in \/tmp\/sysNNNNNNNN.php file<br \/>\n1. \/tmp is 777<br \/>\n2. the sysNNNNNNNN.php is usually accompanied by a .zip file<br \/>\n3. .php and .zip are owned by apache<\/p>\n","protected":false},"excerpt":{"rendered":"<p>PHP Spam Scripts I finally decided this topic deserves its own page. To find the script sending spam Plesk Ver -11.0 cat \/var\/www\/vhosts\/domain.com\/statistics\/logs\/access_log | grep POST &gt; \/tmp\/post.log Ver 11.5+ cat \/var\/www\/vhosts\/system\/domain.com\/statistics\/logs\/access_log | grep POST &gt; \/tmp\/post.log WHM cPanel cat \/usr\/local\/apache\/domlogs\/domain.com | grep POST &gt; \/tmp\/post.log View the results cat \/etm\/post.log 78.138.118.128 &#8211; &#8211; &#x5B;02\/Jan\/2014:10:51:41 &#8230; <a title=\"PHP Spam Scripts\" class=\"read-more\" href=\"https:\/\/www.qbytes.cloud\/index.php\/2014\/07\/31\/php-spam-scripts\/\" aria-label=\"Read more about PHP Spam Scripts\">Read more<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2,84,108],"tags":[],"class_list":["post-484","post","type-post","status-publish","format-standard","hentry","category-administration","category-php","category-spam"],"_links":{"self":[{"href":"https:\/\/www.qbytes.cloud\/index.php\/wp-json\/wp\/v2\/posts\/484","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.qbytes.cloud\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.qbytes.cloud\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.qbytes.cloud\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.qbytes.cloud\/index.php\/wp-json\/wp\/v2\/comments?post=484"}],"version-history":[{"count":0,"href":"https:\/\/www.qbytes.cloud\/index.php\/wp-json\/wp\/v2\/posts\/484\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.qbytes.cloud\/index.php\/wp-json\/wp\/v2\/media?parent=484"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.qbytes.cloud\/index.php\/wp-json\/wp\/v2\/categories?post=484"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.qbytes.cloud\/index.php\/wp-json\/wp\/v2\/tags?post=484"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}