Remote code execution attempt: will insert this binary data into the menu_router table: #drupalsa05


This attack will add file_put_contents() as the access_callback in your menu_router table.

Subsequently, that path is used attempt to drop more exploit code.

Look in menu router for file_put_contents and remove it if found.

There was a file in the codebase. I found the file when I tried to git pull my Drupal update and git complained of this file. Sites updated. Scary one though!

tamerzg commented Oct 18, 2014

It seems that the file has random name and randomly gets inserted in one of the modules subdirectory, as i seen in in different directories on couple of my sites.
More info on how to find it and delete it:

