Quote:
Originally Posted by Dismounted
Errr, plenty of "legit" PHP files use those functions. Take str_replace() for example - I'm willing to bet this is one of the most used PHP functions...
|
Right, but we could log files that are added or when files are changed that include some of these functions. If an Admin didn't upload new scripts, then a report of new files with a number of these woud certainly be worth looking at.
Just because you have a tool that sends a notice doen't mean the sky is falling but if you don't have a tool and you don't get a notice doesn't mean the sky isn't falling too
The goal is to have a configurable list and match rules could be added or removed. These are just a sample and sure not all of these are necessary to look for to identify a potential hack tool.