yes in root, I've never seen it beforeWhere is this file located? if it's in your root directory, it might be an add-on file,
Sorry our posts crossed.when I read in the file, at the top it says: 3Turr, I google on 3Turr this is coming https://toolspro.io/shell/3turr-webshell-php-script/
same image as on my file
okIt hasn’t come from XF.
It may be worth posting the contents of the file so we can try and identify what it’s for and maybe where it’s come from.
No danger, I talk to the cough at the same time, they also checked now and said that I should delete it immediately. Which I didSorry our posts crossed.
If that is indeed what the script is then you must remove it from your server immediately and attempt to identify how it got on your server.
This suggests your server has been compromised in some way.
Try wrapping it in BB code tags. Should do that anyway when posting any code, if only just for the reader. It looks like a hacker defacing page, to me.The whole code could not be pasted, it was too long
If the host has been compromised you can't trust it's output.Is there anyone here who can log in to my host and see if there are any other malicious files, or modified files?
XML sitemaps are often stored this way.Someone who knows or knows of a file that ends up xml.gz?
Ok, uploading a "secure" backup also means that all written posts until now will disappear?If the host has been compromised you can't trust it's output.
So even if the files do look clean, they might in fact me modified.
The only way to be pretty certain would be to completely wipe the server (including to OS) and reload a "known clean" backup, and this still requires trust that the firmware has not been compromised.
XML sitemaps are often stored this way.
We use essential cookies to make this site work, and optional cookies to enhance your experience.