<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://montebellopark.com/support/index.php?action=history&amp;feed=atom&amp;title=Rogue_PHP_Spam_Scripts</id>
	<title>Rogue PHP Spam Scripts - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://montebellopark.com/support/index.php?action=history&amp;feed=atom&amp;title=Rogue_PHP_Spam_Scripts"/>
	<link rel="alternate" type="text/html" href="https://montebellopark.com/support/index.php?title=Rogue_PHP_Spam_Scripts&amp;action=history"/>
	<updated>2026-06-03T20:06:54Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.37.2</generator>
	<entry>
		<id>https://montebellopark.com/support/index.php?title=Rogue_PHP_Spam_Scripts&amp;diff=43&amp;oldid=prev</id>
		<title>Scott: /* Wordpress (or other CMS) Maintenance */</title>
		<link rel="alternate" type="text/html" href="https://montebellopark.com/support/index.php?title=Rogue_PHP_Spam_Scripts&amp;diff=43&amp;oldid=prev"/>
		<updated>2022-03-27T17:39:26Z</updated>

		<summary type="html">&lt;p&gt;&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Wordpress (or other CMS) Maintenance&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 17:39, 27 March 2022&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l72&quot;&gt;Line 72:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 72:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;=== &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Wordpress &lt;/del&gt;(or other CMS) Maintenance ===&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;=== &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;WordPress &lt;/ins&gt;(or other CMS) Maintenance ===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;This is a great opportunity to update your &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Wordpress &lt;/del&gt;install. I also recommend updating any plugins and themes you use, and removing those you don&amp;#039;t. This will hopefully close whatever security holes may have existed and the fewer directories you have nested in your Wordpress install the harder it is for things to hide.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;This is a great opportunity to update your &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;WordPress &lt;/ins&gt;install &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;and check your [[WordPress Setup]] settings in WordPress Toolkit&lt;/ins&gt;. I also recommend updating any plugins and themes you use, and removing those you don&amp;#039;t. This will hopefully close whatever security holes may have existed and the fewer directories you have nested in your Wordpress install the harder it is for things to hide.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Scott</name></author>
	</entry>
	<entry>
		<id>https://montebellopark.com/support/index.php?title=Rogue_PHP_Spam_Scripts&amp;diff=42&amp;oldid=prev</id>
		<title>Scott: /* Solutions */</title>
		<link rel="alternate" type="text/html" href="https://montebellopark.com/support/index.php?title=Rogue_PHP_Spam_Scripts&amp;diff=42&amp;oldid=prev"/>
		<updated>2022-03-27T17:37:51Z</updated>

		<summary type="html">&lt;p&gt;&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Solutions&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 17:37, 27 March 2022&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l43&quot;&gt;Line 43:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 43:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Solutions ==&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Solutions ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;We recommend a multi pronged approach to remove the issue.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;We recommend a multi pronged approach to remove the issue.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;=== Imunify+ ===&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;This runs regularly on all our servers, but it is important to review the detections and clean any infected files regularly.&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;=== ClamAV ===&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;=== ClamAV ===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Scott</name></author>
	</entry>
	<entry>
		<id>https://montebellopark.com/support/index.php?title=Rogue_PHP_Spam_Scripts&amp;diff=6&amp;oldid=prev</id>
		<title>Scott at 00:44, 25 March 2018</title>
		<link rel="alternate" type="text/html" href="https://montebellopark.com/support/index.php?title=Rogue_PHP_Spam_Scripts&amp;diff=6&amp;oldid=prev"/>
		<updated>2018-03-25T00:44:09Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 00:44, 25 March 2018&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l60&quot;&gt;Line 60:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 60:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;=== Adjusting Mail Limits ===&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;=== Adjusting Mail Limits ===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;If you use mail from a third party such as Google or Microsoft and don&amp;#039;t have any contact forms on your website that use email, you can crank down your email send limits. While this won&amp;#039;t prevent re-infection, it will alert you sooner when it occurs.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;If you use mail from a third party such as Google or Microsoft and don&amp;#039;t have any contact forms on your website that use email, you can crank down your email send limits. While this won&amp;#039;t prevent re-infection, it will alert you sooner when it occurs.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;There are details on setting email limits on cPanel [https://documentation.cpanel.net/display/CKB/How+to+Set+Email+Send+Limits here].&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;* To manage domain-level limits, you must manually edit /var/cpanel/users/username.&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;* To manage account-level limits, set the “Maximum Hourly Email by Domain Relayed” field in the Modify an Account interface in WHM.&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;* To manage global limits, set the “Max hourly emails per domain” option in the Tweak Settings interface in WHM.&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;=== Wordpress (or other CMS) Maintenance ===&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;=== Wordpress (or other CMS) Maintenance ===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;This is a great opportunity to update your Wordpress install. I also recommend updating any plugins and themes you use, and removing those you don&amp;#039;t. This will hopefully close whatever security holes may have existed and the fewer directories you have nested in your Wordpress install the harder it is for things to hide.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;This is a great opportunity to update your Wordpress install. I also recommend updating any plugins and themes you use, and removing those you don&amp;#039;t. This will hopefully close whatever security holes may have existed and the fewer directories you have nested in your Wordpress install the harder it is for things to hide.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Scott</name></author>
	</entry>
	<entry>
		<id>https://montebellopark.com/support/index.php?title=Rogue_PHP_Spam_Scripts&amp;diff=5&amp;oldid=prev</id>
		<title>Scott: Created page with &quot;One of the most common issues we have had here at Montebello Park are roque PHP scripts that sneak themselves into web apps such as WordPress. Usually these scripts send email...&quot;</title>
		<link rel="alternate" type="text/html" href="https://montebellopark.com/support/index.php?title=Rogue_PHP_Spam_Scripts&amp;diff=5&amp;oldid=prev"/>
		<updated>2018-03-24T22:36:09Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;One of the most common issues we have had here at Montebello Park are roque PHP scripts that sneak themselves into web apps such as WordPress. Usually these scripts send email...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;One of the most common issues we have had here at Montebello Park are roque PHP scripts that sneak themselves into web apps such as WordPress. Usually these scripts send email, but occasionally they are mining crypto currency. &lt;br /&gt;
&lt;br /&gt;
== Identification ==&lt;br /&gt;
Usually the SPAM variety of these scripts first shows via the mail queue or a notification of an account exceeding its hourly send limit. On occasion you will notice the email script via processor usage, but more often, that is a symptom of the crypto mining scripts. These scripts are often surprisingly smart. They usually limit themselves to a fairly reasonable amount of processor utilization to avoid detection.&lt;br /&gt;
&lt;br /&gt;
== Troubleshooting ==&lt;br /&gt;
Once you&amp;#039;ve determined you have an infection, you need to find where the scripts are. We&amp;#039;ve found a few ways to locate the scripts in question.&lt;br /&gt;
&lt;br /&gt;
=== Email Headers ===&lt;br /&gt;
This is the easiest and most obvious way to find the source. The email server inserts &amp;lt;code&amp;gt;X-&amp;lt;/code&amp;gt; headers that provide the script location.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;For example:&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
 &amp;#039;&amp;#039;&amp;#039;X-Mailer:&amp;#039;&amp;#039;&amp;#039; PHPMailer 5.2.23 (https://github.com/PHPMailer/PHPMailer)&lt;br /&gt;
 &amp;#039;&amp;#039;&amp;#039;X-PHP-Originating-Script:&amp;#039;&amp;#039;&amp;#039; 1010:bwqgvgbw.php(1189) : runtime-created function(1) : eval()&amp;#039;d code(1) : eval()&amp;#039;d code&lt;br /&gt;
 &amp;#039;&amp;#039;&amp;#039;X-PHP-Script:&amp;#039;&amp;#039;&amp;#039; domain.com/wp-content/gallery/government/thumbs/bwqgvgbw.php for 198.100.100.100&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;X-Mailer&amp;lt;/code&amp;gt; describes the engine used to process the emails from the script.&lt;br /&gt;
* &amp;lt;code&amp;gt;X-PHP-Originating-Script&amp;lt;/code&amp;gt; provides the file name of the script, in this case &amp;lt;code&amp;gt;bwqgvgbw.php&amp;lt;/code&amp;gt;. This is a common type of name for these scripts. They will usually be a seemingly random set of characters. Sometimes they will be a .php script in a folder where .php files tend not to be. I&amp;#039;ve found most of the scripts that do the actual heavy lifting are about the same size as well (which is why the &amp;lt;code&amp;gt;find&amp;lt;/code&amp;gt; command can be useful to find scripts that aren&amp;#039;t yet active.&lt;br /&gt;
* &amp;lt;code&amp;gt;X-PHP-Script&amp;lt;/code&amp;gt; provides the full path of the script. In this case it was hiding within the gallery folders in the Wordpress installation.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== maldet ===&lt;br /&gt;
[https://github.com/rfxn/linux-malware-detect maldet] tends not to detect these sorts of issues, but is good to run occasionally in any case.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== find ===&lt;br /&gt;
The [https://kb.iu.edu/d/admm find] command can be useful once you&amp;#039;ve identified the characteristics of your infection. You can use it to search for similar files based on type, size, and even modification date.&lt;br /&gt;
&lt;br /&gt;
==== Size ====&lt;br /&gt;
The find command I&amp;#039;ve used to fins a particular size file is:&lt;br /&gt;
 find /home/ -type f -ipath *.php -size 85k -exec ls -lh {} \;&lt;br /&gt;
&lt;br /&gt;
This looks for &amp;#039;&amp;#039;&amp;#039;85 K&amp;#039;&amp;#039;&amp;#039; &amp;#039;&amp;#039;&amp;#039;php&amp;#039;&amp;#039;&amp;#039; files in all subdirectories of the &amp;#039;&amp;#039;&amp;#039;home&amp;#039;&amp;#039;&amp;#039; directory. &lt;br /&gt;
&lt;br /&gt;
==== Date ====&lt;br /&gt;
A similar find command for dates is:&lt;br /&gt;
 find /home/ -type f -ipath *.php -newermt 2018-01-28 ! -newermt 2018-01-29 -exec ls -lh {} \;&lt;br /&gt;
&lt;br /&gt;
This looks for &amp;#039;&amp;#039;&amp;#039;php&amp;#039;&amp;#039;&amp;#039; files that were modified between &amp;#039;&amp;#039;&amp;#039;2018-01-28&amp;#039;&amp;#039;&amp;#039; and &amp;#039;&amp;#039;&amp;#039;2018-01-29&amp;#039;&amp;#039;&amp;#039; (really after &amp;#039;&amp;#039;&amp;#039;2018-01-28&amp;#039;&amp;#039;&amp;#039; but not after &amp;#039;&amp;#039;&amp;#039;2018-01-29&amp;#039;&amp;#039;&amp;#039;) in all subdirectories of the &amp;#039;&amp;#039;&amp;#039;home&amp;#039;&amp;#039;&amp;#039; directory.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Solutions ==&lt;br /&gt;
We recommend a multi pronged approach to remove the issue.&lt;br /&gt;
&lt;br /&gt;
=== ClamAV ===&lt;br /&gt;
You should run this regularly anyway, but especially now. If you&amp;#039;ve been compromised by something that can upload a php script, it&amp;#039;s probable that isn&amp;#039;t the only thing that&amp;#039;s been uploaded to your server.&lt;br /&gt;
&lt;br /&gt;
Simply go to your cPanel and run the Virus Scanner.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Deleting Identified Scripts ===&lt;br /&gt;
Once you have identified the &amp;lt;code&amp;gt;php&amp;lt;/code&amp;gt; files that are causing issues, simply delete them. I tend to just use the built in file manager in cPanel, but you can do it all via SSH or sFTP as well.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Change your Passwords! ===&lt;br /&gt;
I would change your cPanel account passwords &amp;#039;&amp;#039;&amp;#039;and&amp;#039;&amp;#039;&amp;#039; the Admin &amp;amp; user passwords for your CMS.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Adjusting Mail Limits ===&lt;br /&gt;
If you use mail from a third party such as Google or Microsoft and don&amp;#039;t have any contact forms on your website that use email, you can crank down your email send limits. While this won&amp;#039;t prevent re-infection, it will alert you sooner when it occurs.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Wordpress (or other CMS) Maintenance ===&lt;br /&gt;
This is a great opportunity to update your Wordpress install. I also recommend updating any plugins and themes you use, and removing those you don&amp;#039;t. This will hopefully close whatever security holes may have existed and the fewer directories you have nested in your Wordpress install the harder it is for things to hide.&lt;/div&gt;</summary>
		<author><name>Scott</name></author>
	</entry>
</feed>