A client's website stopped serving her content and started serving a Japanese e-commerce storefro...A client's website stopped serving her content and started serving a Japanese e-commerce storefro...
The network for creativity
Join 1.25M professional creatives like you
Connect with clients, get discovered, and run your business 100% commission-free
Creatives on Contra have earned over $150M and we are just getting started
A client's website stopped serving her content and started serving a Japanese e-commerce storefront instead. She runs a coaching practice, speaks only English, and sells no physical products, so the pages had nothing to do with her business. Something had taken over the site's output.
I started with the file system and the logs rather than the front end, since defacement is usually a symptom. Scanning for recently added and recently modified files turned up several that had been named to pass as part of the core installation. The code inside them was obfuscated, which is not on its own proof of anything, but combined with the timestamps and the placement it was enough to keep pulling. The files turned out to be doing two jobs: injecting the spam content, and hiding themselves from the server so nothing looked wrong from the inside.
Removal was the careful part. Injected code sits alongside legitimate files and deleting broadly takes the site down with it, so I traced each added and modified file individually and restored the originals rather than clearing wholesale. Once the payload was out I closed the backdoor that allowed the initial access, then locked down file permissions so the same write path could not be used again.
The site came back clean. The client recorded a thank you video afterwards, which I still have.
Back to feed
The network for creativity
Join 1.25M professional creatives like you
Connect with clients, get discovered, and run your business 100% commission-free
Creatives on Contra have earned over $150M and we are just getting started