Hosting revoked, what's this file? public_html/auth/WellsFargo/web/system/blocker.php

Zakch93

Elite Member
Joined
Mar 7, 2020
Messages
2,307
Reaction score
855
"Hello,

please explain how this file was uploaded to your account .
/home/naqexeac/public_html/auth/WellsFargo/web/system/blocker.php

--
Best regards"

And hosting suspended. I have no idea what this file is and where it came from. If I had to guess, it's either from a nulled theme/plugin or a php script/CPA network landing page. A google search on it showed a chinese result and it's obviously malicious.

Can I detect which plugin did this, or do I have to erase everything from my site and start from scratch?

And can someone tell us what exactly it is? Curious.
 
Looks like you have been pwned. The path name looks like a fake bank login page to me.
 
Looks like you have been pwned. The path name looks like a fake bank login page to me.
Indeed. Has it ever happened to you? Do you check plugins for backdoor before using even when taken from trusted places?
 
Indeed. Has it ever occured to you? Do you check plugins for backdoor before using even when taken from trusted places?
Nopes never, because I don't use wp. Wp is the root of all evils lol. I assume a plugin you used had RFI vulnerability (google it for more).
 
Nopes never, because I don't use wp. Wp is the root of all evils lol. I assume a plugin you used had RFI vulnerability (google it for more).
All right thanks, what do you use for you sites?
 
All right thanks, what do you use for you sites?
Yii2 framework mostly. It runs like a sports car, and you can have your own db structure due to the loosely coupled architecture. You could also use laravel if you want. You can achieve the same with laravel.
 
Back
Top