iframe hack command Bash search replace injection line ssh safe removal malware browsing

commands to remove code that was added as a result of an iframe injection

Be sure to backup your data! Also be sure to secure whatever broken PHP allowed this to happen.

First command can be used to search for affected files. Second command to does search and replace on matched iframe text only.

Adjust contents of iframe to suit, here it is:



  1. # FIND
  2. find . -type f | xargs grep -l '<iframe.**iframe'
  4. # REPLACE
  5. find . -type f -exec sed -i 's/<iframe.**iframe>//g' {} \;

