course the person doing it, from my reading on the matter was using the same netblock to login to the compromised systems more then once daily. which IMHO would mean this person was NOT overly sophisticated and probably didn't hack up templates and leave stuff on systems like some people might have.
|