Re: [SLUG] Customer site hacked with brut.php - what to do?

2012-08-21 Thread David Lyon
I have changed the password on the hosting account. It won't be possible to reload everything else because it is an ISP hosted machine. -- SLUG - Sydney Linux User's Group Mailing List - http://slug.org.au/ Subscription info and FAQs: http://slug.org.au/faq/mailinglists.html

Re: [SLUG] Customer site hacked with brut.php - what to do?

2012-08-21 Thread Robert Collins
On Wed, Aug 22, 2012 at 2:54 PM, Mark Walkom wrote: > On 22 August 2012 12:00, David Lyon wrote: > >> I have a customer with a hacked website. >> >> When I ftp'd to their web-server I found this wart (listed below - saved as >> brut.php): >> >> How did the hacker put it on my system ? What could

Re: [SLUG] Customer site hacked with brut.php - what to do?

2012-08-21 Thread Mark Walkom
On 22 August 2012 12:00, David Lyon wrote: > I have a customer with a hacked website. > > When I ftp'd to their web-server I found this wart (listed below - saved as > brut.php): > > How did the hacker put it on my system ? What could it have comprimised ? > What > can I do to stop further conseq

[SLUG] Customer site hacked with brut.php - what to do?

2012-08-21 Thread David Lyon
I have a customer with a hacked website. When I ftp'd to their web-server I found this wart (listed below - saved as brut.php): How did the hacker put it on my system ? What could it have comprimised ? What can I do to stop further consequences? --- brut.php (don't run this) --- #  GaStRo -Dz