shell bypass 403

GrazzMean Shell

: /home/workvvfb/ [ drwx--x--x ]
Uname: Linux premium264.web-hosting.com 4.18.0-553.lve.el8.x86_64 #1 SMP Mon May 27 15:27:34 UTC 2024 x86_64
Software: LiteSpeed
PHP version: 8.3.21 [ PHP INFO ] PHP os: Linux
Server Ip: 69.57.162.13
Your Ip: 216.73.216.33
User: workvvfb (1129) | Group: workvvfb (1084)
Safe Mode: OFF
Disable Function:
NONE

name : scanreport-workvvfb-2025-02-15T09:10:08.744000.txt

----------- SCAN REPORT -----------
TimeStamp: Sat, 15 Feb 2025 04:10:10 -0500
(/usr/sbin/cxs --clamdsock /var/clamd --dbreport --defapache nobody --doptions Mv --exploitscan --nofallback --filemax 50000 --noforce --html --ignore /tmp/workvvfb.nomail --options mMOLfSGchexdnwZDRru --noprobability --qoptions Mv --report /home/workvvfb/scanreport-workvvfb-2025-02-15T09:10:08.744000.txt --sizemax 1000000 --ssl --summary --sversionscan --timemax 30 --unofficial --user workvvfb --virusscan --vmrssmax 2000000 --waitscan 0 --xtra /etc/cxs/cxs.xtra.manual)


Scanning /home/workvvfb:

'/home/workvvfb/.cagefs/opt/alt/php52/link/conf'
# Symlink to [/opt/alt/php52/etc/php.d]

'/home/workvvfb/.cagefs/opt/alt/php53/link/conf'
# Symlink to [/opt/alt/php53/etc/php.d]

'/home/workvvfb/.cagefs/opt/alt/php54/link/conf'
# Symlink to [/opt/alt/php54/etc/php.d]

'/home/workvvfb/.cagefs/opt/alt/php55/link/conf'
# Symlink to [/opt/alt/php55/etc/php.d]

'/home/workvvfb/.cagefs/opt/alt/php56/link/conf'
# Symlink to [/opt/alt/php56/etc/php.d]

'/home/workvvfb/.cagefs/opt/alt/php70/link/conf'
# Symlink to [/opt/alt/php70/etc/php.d]

'/home/workvvfb/.cagefs/opt/alt/php71/link/conf'
# Symlink to [/opt/alt/php71/etc/php.d]

'/home/workvvfb/.cagefs/opt/alt/php72/link/conf'
# Symlink to [/opt/alt/php72/etc/php.d]

'/home/workvvfb/.cagefs/opt/alt/php73/link/conf'
# Symlink to [/opt/alt/php73/etc/php.d]

'/home/workvvfb/.cagefs/opt/alt/php74/link/conf'
# Symlink to [/opt/alt/php74/etc/php.d]

'/home/workvvfb/.cagefs/opt/alt/php80/link/conf'
# Symlink to [/opt/alt/php80/etc/php.d]

'/home/workvvfb/.cagefs/opt/alt/php81/link/conf'
# Symlink to [/etc/cl.php.d/alt-php81]

'/home/workvvfb/.cagefs/opt/alt/php82/link/conf'
# Symlink to [/opt/alt/php82/etc/php.d]

'/home/workvvfb/.cagefs/opt/alt/php83/link/conf'
# Symlink to [/opt/alt/php83/etc/php.d]

'/home/workvvfb/.cagefs/opt/alt/php84/link/conf'
# Symlink to [/opt/alt/php84/etc/php.d]

'/home/workvvfb/.cagefs/tmp/.s.PGSQL.5432'
# Symlink to [/var/run/postgres/.s.PGSQL.5432]

'/home/workvvfb/.cagefs/tmp/mysql.sock'
# Symlink to [/var/lib/mysql/mysql.sock]

'/home/workvvfb/.cagefs/var/cache'
# World writeable directory

'/home/workvvfb/.cagefs/var/cache/php-eaccelerator'
# World writeable directory

'/home/workvvfb/.cagefs/var/php'
# World writeable directory

'/home/workvvfb/.cagefs/var/php/apm'
# World writeable directory

'/home/workvvfb/.cagefs/var/php/apm/db'
# World writeable directory

'/home/workvvfb/.cagefs/var/run/screen'
# World writeable directory

'/home/workvvfb/.nc_plugin/hidden'
# World writeable directory
# Scan Timeout (30 secs) while processing:
'/home/workvvfb/nexgenimpex.com/wp-content/ai1wm-backups/nexgenimpex-com-20241209-123029-h3vwpattc221.wpress'

'/home/workvvfb/nexgenimpex.com/wp-content/plugins/all-in-one-wp-migration/all-in-one-wp-migration.php'
# Script version check [OLD] [All-in-One WP Migration v7.87 < v7.88]

'/home/workvvfb/nexgenimpex.com/wp-content/plugins/coming-soon/coming-soon.php'
# Script version check [OLD] [Coming Soon Page, Maintenance Mode, Landing Pages & WordPress Website Builder by v6.18.12 < v6.18.14]

'/home/workvvfb/nexgenimpex.com/wp-content/plugins/coming-soon/app/routes.php'
# Universal decode regex match = [universal decoder]

'/home/workvvfb/nexgenimpex.com/wp-content/plugins/elementor/elementor.php'
# Script version check [OLD] [Elementor v3.21.4 < v3.26.5]

'/home/workvvfb/nexgenimpex.com/wp-content/plugins/elementskit-lite/elementskit-lite.php'
# Script version check [OLD] [ElementsKit Lite v3.1.3 < v3.3.7]

'/home/workvvfb/nexgenimpex.com/wp-content/plugins/essential-addons-for-elementor-lite/essential_adons_elementor.php'
# Script version check [OLD] [Essential Addons for Elementor v5.9.18 < v6.1.0]

'/home/workvvfb/nexgenimpex.com/wp-content/plugins/header-footer-elementor/header-footer-elementor.php'
# Script version check [OLD] [Elementor Header & Footer Builder v1.6.28 < v2.0.6]

'/home/workvvfb/nexgenimpex.com/wp-content/plugins/jet-elements/includes/modules/jet-dashboard/jet-dashboard.php'
# Universal decode regex match = [universal decoder]

'/home/workvvfb/nexgenimpex.com/wp-content/plugins/litespeed-cache/litespeed-cache.php'
# Script version check [OLD] [LiteSpeed Cache v6.5.3 < v6.5.4]

'/home/workvvfb/nexgenimpex.com/wp-content/plugins/loginizer/loginizer.php'
# Script version check [OLD] [Loginizer v1.9.4 < v1.9.6]

'/home/workvvfb/nexgenimpex.com/wp-content/plugins/premium-addons-for-elementor/premium-addons-for-elementor.php'
# Script version check [OLD] [Premium Addons for Elementor v4.10.31 < v4.10.78]

'/home/workvvfb/nexgenimpex.com/wp-content/themes/astra/admin/includes/class-astra-menu.php'
# Universal decode regex match = [universal decoder]

'/home/workvvfb/nexgenimpex.com/wp-includes/version.php'
# Script version check [OLD] [Wordpress v6.7.1 < v6.7.2]

'/home/workvvfb/nexgenshop.pk/wp-content/plugins/all-in-one-wp-migration/all-in-one-wp-migration.php'
# Script version check [OLD] [All-in-One WP Migration v7.87 < v7.88]

'/home/workvvfb/nexgenshop.pk/wp-content/plugins/classic-editor/classic-editor.php'
# Script version check [OLD] [Classic Editor v1.6.3 < v1.6.7]

'/home/workvvfb/nexgenshop.pk/wp-content/plugins/facebook-for-woocommerce/facebook-for-woocommerce.php'
# Script version check [OLD] [Facebook for WooCommerce v3.2.0 < v3.3.1]

'/home/workvvfb/nexgenshop.pk/wp-content/plugins/imagify/imagify.php'
# Script version check [OLD] [Imagify v2.2.2 < v2.2.4]

'/home/workvvfb/nexgenshop.pk/wp-content/plugins/insert-headers-and-footers/ihaf.php'
# Script version check [OLD] [WPCode Lite v2.1.12 < v2.2.5]

'/home/workvvfb/nexgenshop.pk/wp-content/plugins/litespeed-cache/litespeed-cache.php'
# Script version check [OLD] [LiteSpeed Cache v6.5.3 < v6.5.4]

'/home/workvvfb/nexgenshop.pk/wp-content/plugins/loginizer/loginizer.php'
# Script version check [OLD] [Loginizer v1.9.4 < v1.9.6]

'/home/workvvfb/nexgenshop.pk/wp-content/plugins/woocommerce/woocommerce.php'
# Script version check [OLD] [WooCommerce v8.8.3 < v9.5.2]

'/home/workvvfb/nexgenshop.pk/wp-content/plugins/woocommerce/includes/admin/class-wc-admin-menus.php'
# Universal decode regex match = [universal decoder]

'/home/workvvfb/nexgenshop.pk/wp-content/plugins/woocommerce/src/Internal/Admin/WcPayWelcomePage.php'
# Universal decode regex match = [universal decoder]

'/home/workvvfb/nexgenshop.pk/wp-content/plugins/woocommerce/vendor/maxmind-db/reader/ext/maxminddb.c'
# Suspicious file type [application/x-c]

'/home/workvvfb/nexgenshop.pk/wp-content/plugins/wordpress-seo/wp-seo.php'
# Script version check [OLD] [Yoast SEO v22.6 < v24.2]

'/home/workvvfb/nexgenshop.pk/wp-content/uploads/cache/.f6d5b886.ico'
# ClamAV detected virus = [{HEX}php.inject.miner2a2.490.UNOFFICIAL]

'/home/workvvfb/public_html/wp-content/plugins/all-in-one-wp-migration/all-in-one-wp-migration.php'
# Script version check [OLD] [All-in-One WP Migration v7.87 < v7.88]

'/home/workvvfb/public_html/wp-content/plugins/coming-soon/coming-soon.php'
# Script version check [OLD] [Coming Soon Page, Maintenance Mode, Landing Pages & WordPress Website Builder by v6.18.12 < v6.18.14]

'/home/workvvfb/public_html/wp-content/plugins/coming-soon/app/routes.php'
# Universal decode regex match = [universal decoder]

'/home/workvvfb/public_html/wp-content/plugins/elementor/elementor.php'
# Script version check [OLD] [Elementor v3.25.11 < v3.26.5]

'/home/workvvfb/public_html/wp-content/plugins/elementskit-lite/elementskit-lite.php'
# Script version check [OLD] [ElementsKit Lite v3.3.3 < v3.3.7]

'/home/workvvfb/public_html/wp-content/plugins/essential-addons-for-elementor-lite/essential_adons_elementor.php'
# Script version check [OLD] [Essential Addons for Elementor v6.0.11 < v6.1.0]

'/home/workvvfb/public_html/wp-content/plugins/gt3-themes-core/core/meta-box/inc/about/about.php'
# Universal decode regex match = [universal decoder]

'/home/workvvfb/public_html/wp-content/plugins/happy-elementor-addons/plugin.php'
# Script version check [OLD] [Happy Elementor Addons v3.15.0 < v3.15.2]

'/home/workvvfb/public_html/wp-content/plugins/happy-elementor-addons/classes/notice.php'
# Universal decode regex match = [universal decoder]

'/home/workvvfb/public_html/wp-content/plugins/happy-elementor-addons/classes/review.php'
# Universal decode regex match = [universal decoder]

'/home/workvvfb/public_html/wp-content/plugins/happy-elementor-addons/inc/functions.php'
# Universal decode regex match = [universal decoder]

'/home/workvvfb/public_html/wp-content/plugins/litespeed-cache/litespeed-cache.php'
# Script version check [OLD] [LiteSpeed Cache v6.5.3 < v6.5.4]

'/home/workvvfb/public_html/wp-content/plugins/loginizer/loginizer.php'
# Script version check [OLD] [Loginizer v1.9.4 < v1.9.6]

'/home/workvvfb/public_html/wp-content/plugins/mailchimp-for-wp/mailchimp-for-wp.php'
# Script version check [OLD] [MC4WP: Mailchimp for WordPress v4.9.19 < v4.9.21]

'/home/workvvfb/public_html/wp-content/plugins/otter-blocks/otter-blocks.php'
# Script version check [OLD] [Otter – Page Builder Blocks & Extensions for Gutenberg v3.0.8 < v3.0.9]

'/home/workvvfb/public_html/wp-content/plugins/otter-blocks/inc/plugins/class-dashboard.php'
# Universal decode regex match = [universal decoder]

'/home/workvvfb/public_html/wp-content/plugins/premium-addons-for-elementor/premium-addons-for-elementor.php'
# Script version check [OLD] [Premium Addons for Elementor v4.10.67 < v4.10.78]

'/home/workvvfb/public_html/wp-content/plugins/royal-elementor-addons/wpr-addons.php'
# Script version check [OLD] [Royal Elementor Addons v1.7.1004 < v1.7.1007]

'/home/workvvfb/public_html/wp-content/plugins/royal-elementor-addons/admin/plugin-options.php'
# Universal decode regex match = [universal decoder]

'/home/workvvfb/public_html/wp-content/plugins/w3-total-cache/CdnEngine_Ftp.php'
# Regular expression match = [\n(?!\s*(//|\#|\*)).*\.ssh/]

'/home/workvvfb/public_html/wp-content/plugins/w3-total-cache/w3-total-cache.php'
# Script version check [OLD] [W3 Total Cache v2.8.0 < v2.8.2]

----------- SCAN SUMMARY -----------
Scanned directories: 10469
Scanned files: 224057
Ignored items: 264
Suspicious matches: 71
Viruses found: 1
Fingerprint matches: 0
Data scanned: 6219.08 MB
Scan peak memory: 424688 kB
Scan time/item: 0.029 sec
Scan time: 6881.689 sec

© 2025 GrazzMean