Trace how malware was uploaded to server
Posted: 18 Mar 2021, 11:48
Hello,
I've been struggling with this for a while now, I have wordpress sites where everything is up to date but attackers are still able to upload files to the server. One such person has been trying to upload a backdoor since 1am in the morning. I can see 5 files with the same name quarantined.
Is it possible to identify how these files were uploaded?
I'm starting to loose my mind here, I even put up cloudflare to see if that would help but the files are still being uploaded.
Any help would be greatly appreciated, thank you.
I've been struggling with this for a while now, I have wordpress sites where everything is up to date but attackers are still able to upload files to the server. One such person has been trying to upload a backdoor since 1am in the morning. I can see 5 files with the same name quarantined.
Is it possible to identify how these files were uploaded?
I'm starting to loose my mind here, I even put up cloudflare to see if that would help but the files are still being uploaded.
Any help would be greatly appreciated, thank you.