Table of Contents
For iFRME injection, first search the all domains on the server using following command which are infected then remove it using following script.
find /home/*/public_html/ -type f -exec grep -Eil “iframedomain.com” {} \; >> scanresult.txt
Where iframedomain.com is injected domain. Now use following script to remove it.
vi remove.sh and add following
#!/bin/bash
for i in `cat scanresult.txt`;
do
replace -s ‘
done
———-

