Skip to main content

You are not logged in. Your edit will be placed in a queue until it is peer reviewed.

We welcome edits that make the post easier to understand and more valuable for readers. Because community members review edits, please try to make the post substantially better than how you found it, for example, by fixing grammar or adding additional resources and hyperlinks.

Required fields*

3
  • Have you seen this question? It looks similar. Commented Mar 25, 2015 at 16:10
  • @QuestionOverflow Thanks, that link was very helpful. Do you think it is likely that the code sample here (if unobfuscated) would be similar to the one you posted, or could it be a completely different backdoor just obfuscated in a similar manner? The apache log does seem to show attempts to exploit the MailPoet plugin, but apache returned code 200 for those attempts rather than the 302, the code that sample logs I found online show. I also didn't find any attempts to access the themes folder. Commented Mar 26, 2015 at 2:03
  • Looking at the structure, it is most likely the same polymorphic code encrypted differently to evade detection. This code is not a backdoor. The backdoor is likely from the plugin. You could edit your question to include the relevant access log so that others may be able to help you. Commented Mar 29, 2015 at 12:18