not sure what this is all about.
the hosting company (bluehost) of one of my clients suspended the account.
they referenced files from the expression engine (1.6.8) installation.
the files have not been touched since 2009.
files listed in the report:
./public_html/system/core/core.messages.php
./public_html/system/core/core.regex.php
./public_html/system/core/core.spellcheck.php
./public_html/system/cp/cp.communicate.php
./public_html/system/cp/cp.messages.php
./public_html/system/cp/cp.publish.php
./public_html/themes/profile_themes/default/profile_theme.php
i checked through them and found nothing weird other than Pinky and the Brain ascii graphic following
[code core.messages.php]at the end of the code:
return <<<Dirt
......
Dirt;
Quiet, Paul, I’m pondering. | \\ l\\l_ // |
_ _ | \\/ `/ `.| | Err…right, Rick! Narf!
/ \\ \ //\ | Y | | || Y |
| \\ \ // | | \| | |\ / | /
[ || || ] \ | o|o | > / /
] || || [ \___\_—_ /_/__/
| \_|l,———.l|_/ | /.-\(____) /—.\
| >’ `< | `—(______)——’
\ (/~’—____—’~\) / U// U / \
`-_>-__________-<_-’ / \ / /|
/(_*(__)*_)\ ( .) / / ]
\___/__\___/ `.`’ / [
/__`—‘__\ |`-’ |
/\(__,>-~~ __) | |__
/\//\\\ / _l |—:.
‘\/ <^\ /^> | ` ( | \\
_\ >-__-< /_ ,-\ ,-~~->. \ `:.___,/
(___\ /___) (____/ (____) `—-’
SRKmHWgK 6HP
WRWWQWm yQgX
zWQQqRRWT rqQqB
gqQqRtWR fbXn16hs XXRQq0
gXkQ8X pkSb b04 RQQXXK
QXXQkQ7 aDahC XSO RbXQQRQ
R88kXXQ PZFwX kkk bQkQkRQLt
QdXkkdXt rYOZ4Vt 4bd6 qXk8X8QR
gQQQd8kp G6TuTy 3khP tXQQQQRQa
Q888Xdb2 1TuL6 pkS Q RX8QQRQH
Kb88kSd8 YZZZ6yF6 4h zk888RQR
QQQ8bdbV ywyn k X8b8RRg
uQXb8Qb6 zFDD X4 XQbQXbQ
gRb8Qkh apX wQ t8QXQQW
bR8QbE hSF 1bA bQbR8W
zBXQRa zDDf2 KqQRqRbgy
tGEgQh aQRRqXXW
CmWQ KRRQgqQ
wqC HmQpYj</code></pre>
Downloading the 1.7.1 skript shows this as well ... is this funny, I am not quite sure. I know though that this is surely not a malware/virus even though it seems like it the first time you come across it!
Why do these files yield a flag at their end in the first place? As long as they are red flagged the site is suspended ... any ideas ?