A spam hacker got into a site today and created dozens of php files with names like albertus.php, alphonso.php and amada.php in various folders. Now Im trialing Imunify360 to see what it can do.
I dont know if these files would have been picked up by the Malware Scanner (I hope/assume so) because I had deleted them all before we installed Imunify360.
Assuming the scanner does identify the files, is there any way to set something up so that if any IP address tries to access one of these quarantined files then that IP is grey or black listed?
And can a file be manually flagged as malicious and then quarantined?
There is a 100% chance that anyone trying to access one of these files needs to be blocked and if that could be done by the firewall this would have kept the attacked website operational today. The website got so many requests for these deleted files that any legit users got a resource not available message or no response at all.
Thanks,
Phil
I dont know if these files would have been picked up by the Malware Scanner (I hope/assume so) because I had deleted them all before we installed Imunify360.
Assuming the scanner does identify the files, is there any way to set something up so that if any IP address tries to access one of these quarantined files then that IP is grey or black listed?
And can a file be manually flagged as malicious and then quarantined?
There is a 100% chance that anyone trying to access one of these files needs to be blocked and if that could be done by the firewall this would have kept the attacked website operational today. The website got so many requests for these deleted files that any legit users got a resource not available message or no response at all.
Thanks,
Phil
Comment