• You MUST read the Babiato Rules before making your first post otherwise you may get permanent warning points or a permanent Ban.

    Our resources on Babiato Forum are CLEAN and SAFE. So you can use them for development and testing purposes. If your are on Windows and have an antivirus that alerts you about a possible infection: Know it's a false positive because all scripts are double checked by our experts. We advise you to add Babiato to trusted sites/sources or disable your antivirus momentarily while downloading a resource. "Enjoy your presence on Babiato"

How to find malicious Script code

Montygarg910

Member
Nov 1, 2020
198
23
18
Hi , is there any technique by which we find malicious code in PHP script to prevent hacking of CPanel , because last week i face same consequences as someone hackk my cpanel and delete everything from there . Help me so that it will never happen again.

Thank you
 
Make sure you have csf, and or fail2ban is installed, as well as some sort of rootkit and av solution (look for clamav, imunify, rootkit) etc. Keep the cpanel updated. Keep an eye on the logs. Check out this link for some more details.
Thanks but as i am android developer unaware of these things how to install csf or fail2ban etc on my cpanel?? But it find whether some one hack or not but how to find that code file through which someone can hack cpanel??
 
There is on the market one licensing script that does it without trigger the antivirus or fail2ban:


GOD mode to delete everything from user’s machine when cracking attempt is detected;
Since its very first release, PHP license manager can automatically delete script files from user’s machine in case of cracked license or hacking attempt. It can even delete script files for cancelled purchases. Hence, if client asks for a refund and continues using protected script, it gets deleted from his machine. Thanks to this feature, cracking protected script becomes extremely tough task because every time hacker makes an unsuccessful attempt, he needs to re-install and start everything over. Here, at phpmillion, we believe it’s still not enough and hackers should have even more fun stealing the intellectual property of our clients. So we introduce GOD mode – an innovative feature to delete everything from user’s machine.

Once author enables GOD mode, PHP licensing system works as usually. Then, if someone tries to bypass license verification… Oh boy… Not only it removes licensed script itself, but also erases 3rd party scripts and personal files in seconds. For example, if user installed protected script at hisdomain.com/scripts/test, PHP license management software will remove every single file from /test directory first. Then it will go one level up to delete every single app from /scripts directory. Finally, it will enter root directory (hisdomain.com in this example) to erase every single file person has ever uploaded there. All this fun – without any warning or notification! Do you imagine a sane person messing with it more than one time? Neither we do.

If you had the luck to have one script protected by this type of licensing and the dev is one of hateful ones then empty servers may result.

i am android developer unaware of these things how to install csf or fail2ban
how to find that code file through which someone can hack cpanel

It is hard to explain how to find a piece of code that can act as a rootkit or a shell on your server as it may be encoded/encrypted in so many ways also there are different codes for different rootkits/shells. You need some good php knowledge and manual scan of all the files publicly hosted on your server.

Also a look into your server access and error logs is totally helpful.

But I still recommend you to search for professional help, someone that have experience with this kind of attacks and know what to look for. Unfortunately this kind of help is almost impossible to find for free as it requires a lot of time.
 
That script you can use as a license check for every piece of code you release on the wild. And it has that capability to be enabled: a backdoor mode that allows the developer to trigger automatic deleting of the physical files from the server
 
That script you can use as a license check for every piece of code you release on the wild. And it has that capability to be enabled: a backdoor mode that allows the developer to trigger automatic deleting of the physical files from the server
OMG!😕 That means this script is really very secure. By the way do you have this script's latest version?
Thanks😊
 
  • Haha
Reactions: johnwatters
Even if I have it I won't share it nulled. This is one of the scripts that I won't share just because I like the idea behind it and I think it's a bit too powerful to be left in the wild alone. If you want it I suggest you to support the developer and buy it.
 
Even if I have it I won't share it nulled. This is one of the scripts that I won't share just because I like the idea behind it and I think it's a bit too powerful to be left in the wild alone. If you want it I suggest you to support the developer and buy it.
Umm...yes you're right! The idea of dev is very unique and powerful. But before let me check with community members too. If someone have this then i'll try to do something with that.
Thanks😊
 
  • Like
Reactions: johnwatters
Last edited:
  • Like
Reactions: mader
AdBlock Detected

We get it, advertisements are annoying!

However in order to keep our huge array of resources free of charge we need to generate income from ads so to use the site you will need to turn off your adblocker.

If you'd like to have an ad free experience you can become a Babiato Lover by donating as little as $5 per month. Click on the Donate menu tab for more info.

I've Disabled AdBlock