rszkutak
Verified User
we have one site on our server that was hacked or something. It was used in a "phising" scheme, we were alerted to this each time by different security org's that do this sort of thing for clients like Bank of America, Chase, Washington Mutual, and so on.
Initially it was WM that had a phising site there, the pages were basic PHP, so we removed them and moved on. Within a few hours it came back again, once again we removed them and looked deeper into the site. Once again, hacked. This time we disalbed the site, removed everything from it and re enabled it. Finally it got hacked the last time, and we disabled it and re routed DNS to 192.168.1.1 which as we know will go nowhere fast.
We have changed all admin accounts passwords, ROOT PW, and the DA admin & resleer passwords yet it still got "compromised".
Any thoughts as to where i can look, or what i can do here to get this rolling again ?
thanks,
Rob
Initially it was WM that had a phising site there, the pages were basic PHP, so we removed them and moved on. Within a few hours it came back again, once again we removed them and looked deeper into the site. Once again, hacked. This time we disalbed the site, removed everything from it and re enabled it. Finally it got hacked the last time, and we disabled it and re routed DNS to 192.168.1.1 which as we know will go nowhere fast.
We have changed all admin accounts passwords, ROOT PW, and the DA admin & resleer passwords yet it still got "compromised".
Any thoughts as to where i can look, or what i can do here to get this rolling again ?
thanks,
Rob