Easy: have a user that has a part of php like:ljweb said:yep, any file with the word index,default,home etc was hacked. I found iroffer in the /tmp folder, it was hidden in a folder called ... .It was owned by apache.
I removed it and took execute permissions off the temp folder.
how would it be possible for someone to get iroffer into the tmp folder? would this have to be done via a hole in a php script?
qlsys said:Hi,
Try to use chkrootkit to check for some known rootkits installed. Most of them installas a patched ps,ls and many others programs so You cant find anything unusual.
Kind Regards,