View Single Post
Old 05-11-2006, 06:51 PM  
Linkster
Confirmed User
 
Join Date: Feb 2003
Location: DeltaHell
Posts: 3,216
Can your host provide logs as to how the script initially got on your server? This sounds like something that a lot of WMs have been experiencing lately that seems to be connected to a compromised sponsors affiliates password file where some have used the same password for a sponsor as they use on their server (not smart but it has happened).
What I would be looking for is an initial PUT where the guy just used ftp to get in with no real hack attempts(already knew the pass)
Linkster is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote