logo.png
Guided Website Threat Review

Foregenix Blog

Benjamin Hosack

Web Security Alert: Filesman:02 Backdoor

web security, Magento

,24/03/15 12:10

This last week we have assisted a number of online clients having been compromised via the “Filesman” backdoor. This backdoor is not a new attack – in fact, it’s been very well publicized and documented over the last few years.

Who does it affect?

Filesman can affect any PHP site – that includes, Magento, WordPress, Drupal, Joomla, osCommerce etc. Usually it affects older versions of the website frameworks.

What does Filesman do?

It allows an attacker to easily access your site, make modifications and to plant additional malware infections/backdoors elsewhere on your website.

The compromised websites that we have been working with have all had their customer data stolen – including transaction data (credit and debit card details), which means that their clients are likely to see fraud on their credit/debit cards imminently.

How to identify this malware on your website

There are a great deal of examples available on many security websites - the file names may vary slightly, however this is what we have found this week:

$auth_pass = "";

$color = "#df5";

$default_action = "FilesMan";

$default_charset = "Windows-1251";

Slight variants of the content have been seen but the spelling of "FilesMan" within the first few lines of the malware clearly identify this threat.

What to do if you identify this malware on your site

You have a few options:

1. The do-it-yourself route

a. Remove the malware – delete it.

b. Run a scan of your website using FGX-Web Alert (its free for 30 days) to identify whether you have any other known nasties.

c. Update your website framework/CMS/plugins/extensions.

d. Remove inactive files/plugins/extensions.

e. Change your passwords (have a read of our Password blog post if you want some help developing a strong password).

f. Put up a Web Application Firewall – we offer this protection through FGX-Web Protect.

2. We can assist you:

a. Get in touch with our support team.

b. They will help you to get FGX-Web onto your website, remove the malware and check for other backdoors.

How to prevent being infected by this type of attack

Backdoors are usually uploaded once a vulnerability in the website has been exploited – this means that once the backdoor is on your site, your business has been hacked and compromised.

  • If you are using any of the frameworks mentioned above (Magento, WordPress, Drupal, osCommerce, Joomla) then make sure you are using the latest version.
  • Remove any inactive files/plugins/extensions.
  • If you can’t update to the latest version, we would recommend using FGX-Web Protect to provide the web application firewalling and security monitoring of your website.
  • Passwords – change your passwords and ensure that you are using strong passwords – not your mother’s maiden name!

TRENDING POSTS

Kirsty Trainer
The "Key" to Secure Data - P2PE - Derived Unique Key Per Transaction (DUKPT)

Written by Andrew McKenna, PCI QSA, PCIP at Foregenix The encryption key infrastructure usually ...

Read More
Duncan Slater
Alert: Major UK Payment Service Provider iFrame Man-In-The-Middle Breach

The Foregenix Digital Forensics and Incident Response Team recently reported a man-in-the-middle ...

Read More

Cyber Security Insights

Jake Dennys
17/10/17 10:33

Foregenix Highly Commended at Fraud Awards 2017

Earlier this year we were shortlisted for a prestige award at Fraud Awards 2017, presented by Retail Risk. Judges had selected Foregenix as a ...

Read More

Jake Dennys
09/10/17 14:24

Why an SSL certificate won’t protect your website, but FGX-Web will.

Having an SSL (Secure Sockets Layer) certificate on your website is important and it's also a good thing to have. The little green padlock in the ...

Read More

Mike Hinton
04/10/17 10:55

Is My Hosting Provider Protecting My Website?

Recently, it was discovered that over 14 million Verizon customers data, including PIN’s, had been exposed on an unprotected web server.  Three ...

Read More

Jake Dennys
28/09/17 10:21

We're Showcasing Cybersecurity at Ecommerce Expo 2017!

Flyers printed, banners set up, scanners prepped, we are officially at Ecommerce Expo 2017! It’s our first year at the show and we’ve hit the road to ...

Read More

Paul Taylor
25/09/17 12:09

Responsible Disclosure of Zero-Day Vulnerabilities Discovered in NfSen and AlienVault OSSIM

Part 1 of 2 – Introduction and Background NfSen is an open source netflow data capture and analysis module which can be used as a standalone product, ...

Read More