Synopsis
The remote web server contains a PHP backdoor script.
Description
At least one instance of r57shell is hosted on the remote web server. This is a PHP script that acts as a backdoor and provides a convenient set of tools for attacking the affected host.
Solution
Remove any instances of the script and conduct a forensic examination to determine how it was installed as well as whether other unauthorized changes were made.
Plugin Details
Configuration: Enable thorough checks (optional)
Supported Sensors: Nessus
Vulnerability Information
Required KB Items: www/PHP
Excluded KB Items: Settings/disable_cgi_scanning