KHer0
Elite Member
- Mar 22, 2011
- 2,465
- 2,981
Trouble is you need to compare it to the original clean file, which the author supplies.
Yep, that's what I thought, now I'm looking the way to see the official checksum. Also could be that although being from different no official sources could be the same infected file
No aaaaaaaaaaaaaaaaaaaaaaaaaand no -_-
Like I said, you don't need a clean version. You just need two copies from two different sources. Two different nulled websites or 1 website and 1 Forum or whatever. All you need is two different sources. So, even if both of them were infected, there is no way they are infected with EXACT SAME code. So, when compared, they both will show their difference, which is the backdoor php code.
When I was younger, I used to look for each nulled website backdoor, create a fingerprint and find all the websites they infected. Good Days