PHP Backdoor Has Another Backdoor Inside


Is there no honor among thieves anymore? The other day I was looking at a remote access Trojan written in the PHP scripting language. The bot loads into memory on a victim’s computer when an unsuspecting user, for example, stumbles upon an iframe pointing to the PHP script embedded in a Web page. The code isĀ  nicely appointed with such desirable features as the ability to execute shell commands on the host server, send a flood of data packets at another computer, and scan remote computers. Once loaded into a victim’s browser, the bot connects to, and is capable of […]

