{"id":1018,"date":"2016-04-22T15:17:22","date_gmt":"2016-04-22T15:17:22","guid":{"rendered":"https:\/\/antivirus.comodo.com\/blog\/?p=1018"},"modified":"2020-09-23T13:37:42","modified_gmt":"2020-09-23T08:07:42","slug":"how-to-protect-your-websites-and-visitors-against-evalbase64_decode","status":"publish","type":"post","link":"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/how-to-protect-your-websites-and-visitors-against-evalbase64_decode\/","title":{"rendered":"How to protect your websites and visitors against eval(base64_decode ( ))"},"content":{"rendered":"<p style=\"text-align: justify;\">WordPress is perhaps very popular as a CMS among those who are not that tech savvy. It&#8217;s easy to use and of course inexpensive too. But many who use WordPress never realize that this easy, inexpensive CMS is quite dangerous too. This because it&#8217;s mostly used by people who are not that tech savvy and not too concerned about <a href=\"https:\/\/enterprise.comodo.com\/blog\/what-is-virus-removal\/\" target=\"_blank\" rel=\"noopener\">Virus Protection<\/a>, Virus Removal etc. Hence it&#8217;s easily prone to virus attacks. One of the most popular virus attacks that happen on WordPress is the eval(base64_decode ( )). Every single index.php file will be changed so that the opening php tag of these files would read like &lt;?php eval(base64_decode( followed by some gibberish. Repeated attempts to clean the virus, even by restoring from a back-up wouldn&#8217;t work and the files just would go on getting infected. This kind of hacking is usually done to redirect sites somewhere else on the Internet (for example to an online ad) and make money.<\/p>\n<p style=\"text-align: justify;\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1123\" src=\"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/RF-8562_9.jpg\" alt=\"Comodo Antivirus Protection\" width=\"650\" height=\"300\" srcset=\"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/RF-8562_9.jpg 650w, https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/RF-8562_9-300x138.jpg 300w, https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/RF-8562_9-225x104.jpg 225w\" sizes=\"auto, (max-width: 650px) 100vw, 650px\" \/><\/p>\n<p style=\"text-align: justify;\">So, how to <a href=\"https:\/\/cwatch.comodo.com\" target=\"_blank\" rel=\"noopener\">protect your website<\/a> and website visitors against this virus? Here are some <a href=\"https:\/\/enterprise.comodo.com\/blog\/what-is-virus-removal\/\" target=\"_blank\" rel=\"noopener\">Virus Protection<\/a> and Virus Removal tips&#8230;<\/p>\n<p style=\"text-align: justify;\"><strong>Virus Protection Tips<\/strong><\/p>\n<ul style=\"text-align: justify;\">\n<li>Harden WordPress using .htaccess file modifications, security plugin installations etc.<\/li>\n<li>Do regular <a title=\"WordPress Security\" href=\"https:\/\/webinspector.com\/blog\/website-scanner\/wordpress-website-security-scan\/\" target=\"_blank\" rel=\"noopener\">WordPress Security<\/a> updates.<\/li>\n<li>Harden your PHP installation. Use very secure passwords for SSH, SCP and FTP.<\/li>\n<li>Use a trusted, effective antivirus program.<\/li>\n<li>Install an <a href=\"https:\/\/www.instantssl.com\/ssl-certificate.html\" target=\"_blank\" rel=\"noopener\">SSL Certificate<\/a>; always use SSL certificate.<\/li>\n<\/ul>\n<p style=\"text-align: justify;\"><strong>Virus Removal Tips<\/strong><\/p>\n<ul style=\"text-align: justify;\">\n<li>Begin with blocking or shutting down the site. This is for two reasons. First, it will protect site visitors from getting the infection. Second, it will prevent the hacker from acessing the site when the repair is being done.<\/li>\n<li>Download copy of all your files from your backup, which would be uninfected. Download and install a File\/Folder Comparison Utility.<\/li>\n<li>Run the File\/Folder Comparison Utility, check the differences and resolve them. Detect infected files and overwrite them with files saved from the back-up.<\/li>\n<li>Before unblocking your site, it&#8217;s imperative to review your security precautions, in detail.<\/li>\n<li>Now unblock the site and check if it works fine.<\/li>\n<li>Keep watch on the site; check if some intrusion happens again or not.<\/li>\n<\/ul>\n<p style=\"text-align: justify;\">Well, once you have removed the eval(base64_decode ( )) infection, it would be advisable to think of preventing further malware strike. Act fast and go for a trusted, effective <a href=\"https:\/\/antivirus.comodo.com\/\" target=\"_blank\" rel=\"noopener\">antivirus software<\/a>, one that has some real good features. <a href=\"https:\/\/antivirus.comodo.com\/\" target=\"_blank\" rel=\"noopener\">Antivirus<\/a> is something that is mandatory for all computer\/internet users in this age of malware and malware attacks. You should also make sure each site you own (individually or for a company) has been protected with SSL certificates. Prevention, no doubt, is better than cure&#8230;<\/p>\n<p style=\"text-align: justify;\"> <a href=\"https:\/\/antivirus.comodo.com\/download\/thank-you.php?prod=cloud-antivirus&#038;track=16678&#038;af=16678\" target=\"_blank\" rel=\"noopener\" onclick=\"ga('send', 'event', {eventCategory: 'Antivirus Blog', eventAction: 'Download', eventLabel: 'Bottom FREE DOWNLOAD banner Product AV'});ga('nT.send', 'event', {eventCategory: 'Antivirus Blog', eventAction: 'Download', eventLabel: 'Bottom FREE DOWNLOAD banner Product AV'});\"><img decoding=\"async\" class=\"aligncenter size-full wp-image-8604\" src=\"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2018\/04\/Comodo-Free-Antivirus.png\" alt=\"comodo antivirus\"\/><\/a><\/p>\n<p><a href=\"https:\/\/secure.nurd.com\/home\/purchase.php?pid=109&#038;af=16166\" target=\"_blank\" rel=\"noopener\" onclick=\"ga('send', 'event', {eventCategory: 'Antivirus Blog', eventAction: 'Click', eventLabel: 'GET COMPLETE PROTECTION banner Product CIS Pro'});ga('nT.send', 'event', {eventCategory: 'Antivirus Blog', eventAction: 'Click', eventLabel: 'GET COMPLETE PROTECTION banner Product CIS Pro'});\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-8604\" src=\"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2020\/08\/complete-antivirus.png\" alt=\"comodo antivirus\" width=\"650\" height=\"83\" \/><\/a><\/p>\n<p><strong>Related Resources:<\/strong><br \/>\n<strong><a href=\"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/best-antivirus-of-2019\/\" target=\"blank\">https:\/\/antivirus.comodo.com\/blog\/computer-safety\/best-antivirus-of-2019\/<\/a><strong><br \/>\n<strong><a href=\"https:\/\/cwatch.comodo.com\/website-backup\/\" rel=\"noopener\" target=\"_blank\">Website Backup<\/a><\/strong><br \/>\n&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>WordPress is perhaps very popular as a CMS among those who are not that tech savvy. It&#8217;s easy to use and of course inexpensive too. But many who use WordPress never realize that this easy, inexpensive CMS is quite dangerous too. This because it&#8217;s mostly used by people who are not that tech savvy and [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":1122,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[62,14],"class_list":["post-1018","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-comodo-news","tag-evalbase64_decode","tag-internet-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Protect your websites and visitors against evalbase64 decode<\/title>\n<meta name=\"description\" content=\"Protection of websites, visitors against the very common eval(base64_decode ( )) malware. Using antivirus and other preventive, protective measures\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/how-to-protect-your-websites-and-visitors-against-evalbase64_decode\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Protect your websites and visitors against evalbase64 decode\" \/>\n<meta property=\"og:description\" content=\"Protection of websites, visitors against the very common eval(base64_decode ( )) malware. Using antivirus and other preventive, protective measures\" \/>\n<meta property=\"og:url\" content=\"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/how-to-protect-your-websites-and-visitors-against-evalbase64_decode\/\" \/>\n<meta property=\"og:site_name\" content=\"Comodo Antivirus Blogs | Anti-Virus Software Updates\" \/>\n<meta property=\"article:published_time\" content=\"2016-04-22T15:17:22+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2020-09-23T08:07:42+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/RF-8562_thb_9.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"180\" \/>\n\t<meta property=\"og:image:height\" content=\"136\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"seo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"seo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/how-to-protect-your-websites-and-visitors-against-evalbase64_decode\/\",\"url\":\"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/how-to-protect-your-websites-and-visitors-against-evalbase64_decode\/\",\"name\":\"Protect your websites and visitors against evalbase64 decode\",\"isPartOf\":{\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/how-to-protect-your-websites-and-visitors-against-evalbase64_decode\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/how-to-protect-your-websites-and-visitors-against-evalbase64_decode\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/RF-8562_thb_9.jpg\",\"datePublished\":\"2016-04-22T15:17:22+00:00\",\"dateModified\":\"2020-09-23T08:07:42+00:00\",\"author\":{\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/#\/schema\/person\/e534eccce9a7e6ced088443c73329462\"},\"description\":\"Protection of websites, visitors against the very common eval(base64_decode ( )) malware. Using antivirus and other preventive, protective measures\",\"breadcrumb\":{\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/how-to-protect-your-websites-and-visitors-against-evalbase64_decode\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/how-to-protect-your-websites-and-visitors-against-evalbase64_decode\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/how-to-protect-your-websites-and-visitors-against-evalbase64_decode\/#primaryimage\",\"url\":\"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/RF-8562_thb_9.jpg\",\"contentUrl\":\"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/RF-8562_thb_9.jpg\",\"width\":180,\"height\":136,\"caption\":\"Antivirus Protection\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/how-to-protect-your-websites-and-visitors-against-evalbase64_decode\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/antivirus.comodo.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"How to protect your websites and visitors against eval(base64_decode ( ))\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/#website\",\"url\":\"https:\/\/antivirus.comodo.com\/blog\/\",\"name\":\"Comodo Antivirus Blogs | Anti-Virus Software Updates\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/antivirus.comodo.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/#\/schema\/person\/e534eccce9a7e6ced088443c73329462\",\"name\":\"seo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/3b7714e98dafc3a3b391832c0f5e2b406856b62c8e81ad94382c197cdb380790?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/3b7714e98dafc3a3b391832c0f5e2b406856b62c8e81ad94382c197cdb380790?s=96&d=mm&r=g\",\"caption\":\"seo\"},\"url\":\"https:\/\/antivirus.comodo.com\/blog\/author\/seo\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Protect your websites and visitors against evalbase64 decode","description":"Protection of websites, visitors against the very common eval(base64_decode ( )) malware. Using antivirus and other preventive, protective measures","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/how-to-protect-your-websites-and-visitors-against-evalbase64_decode\/","og_locale":"en_US","og_type":"article","og_title":"Protect your websites and visitors against evalbase64 decode","og_description":"Protection of websites, visitors against the very common eval(base64_decode ( )) malware. Using antivirus and other preventive, protective measures","og_url":"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/how-to-protect-your-websites-and-visitors-against-evalbase64_decode\/","og_site_name":"Comodo Antivirus Blogs | Anti-Virus Software Updates","article_published_time":"2016-04-22T15:17:22+00:00","article_modified_time":"2020-09-23T08:07:42+00:00","og_image":[{"width":180,"height":136,"url":"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/RF-8562_thb_9.jpg","type":"image\/jpeg"}],"author":"seo","twitter_card":"summary_large_image","twitter_misc":{"Written by":"seo","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/how-to-protect-your-websites-and-visitors-against-evalbase64_decode\/","url":"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/how-to-protect-your-websites-and-visitors-against-evalbase64_decode\/","name":"Protect your websites and visitors against evalbase64 decode","isPartOf":{"@id":"https:\/\/antivirus.comodo.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/how-to-protect-your-websites-and-visitors-against-evalbase64_decode\/#primaryimage"},"image":{"@id":"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/how-to-protect-your-websites-and-visitors-against-evalbase64_decode\/#primaryimage"},"thumbnailUrl":"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/RF-8562_thb_9.jpg","datePublished":"2016-04-22T15:17:22+00:00","dateModified":"2020-09-23T08:07:42+00:00","author":{"@id":"https:\/\/antivirus.comodo.com\/blog\/#\/schema\/person\/e534eccce9a7e6ced088443c73329462"},"description":"Protection of websites, visitors against the very common eval(base64_decode ( )) malware. Using antivirus and other preventive, protective measures","breadcrumb":{"@id":"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/how-to-protect-your-websites-and-visitors-against-evalbase64_decode\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/antivirus.comodo.com\/blog\/comodo-news\/how-to-protect-your-websites-and-visitors-against-evalbase64_decode\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/how-to-protect-your-websites-and-visitors-against-evalbase64_decode\/#primaryimage","url":"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/RF-8562_thb_9.jpg","contentUrl":"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/RF-8562_thb_9.jpg","width":180,"height":136,"caption":"Antivirus Protection"},{"@type":"BreadcrumbList","@id":"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/how-to-protect-your-websites-and-visitors-against-evalbase64_decode\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/antivirus.comodo.com\/blog\/"},{"@type":"ListItem","position":2,"name":"How to protect your websites and visitors against eval(base64_decode ( ))"}]},{"@type":"WebSite","@id":"https:\/\/antivirus.comodo.com\/blog\/#website","url":"https:\/\/antivirus.comodo.com\/blog\/","name":"Comodo Antivirus Blogs | Anti-Virus Software Updates","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/antivirus.comodo.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/antivirus.comodo.com\/blog\/#\/schema\/person\/e534eccce9a7e6ced088443c73329462","name":"seo","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/antivirus.comodo.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/3b7714e98dafc3a3b391832c0f5e2b406856b62c8e81ad94382c197cdb380790?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/3b7714e98dafc3a3b391832c0f5e2b406856b62c8e81ad94382c197cdb380790?s=96&d=mm&r=g","caption":"seo"},"url":"https:\/\/antivirus.comodo.com\/blog\/author\/seo\/"}]}},"post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/posts\/1018","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/comments?post=1018"}],"version-history":[{"count":36,"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/posts\/1018\/revisions"}],"predecessor-version":[{"id":15508,"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/posts\/1018\/revisions\/15508"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/media\/1122"}],"wp:attachment":[{"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/media?parent=1018"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/categories?post=1018"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/tags?post=1018"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}