.htaccess Injector on Joomla and WordPress Websites

.htaccess Injector on Joomla and WordPress Websites

During the process of investigating one of our incident response cases, we found an .htaccess code injection. It had been widely spread on the website, injected into all .htaccess files and redirecting visitors to the http[:]//portal-f[.]pw/XcTyTp advertisement website.

Taking a Look at the .htaccess Injector Code

Below is the code within the ./modules/mod_widgetread_twitt/ index.php file on a Joomla website. This code is responsible for injecting the malicious redirects into the .htaccess files:

This code is searching for an .htaccess file.

Continue reading .htaccess Injector on Joomla and WordPress Websites at Sucuri Blog.

Via Sucuri.net

Tags: , ,