View Single Post
Old 11-18-2012, 06:19 AM   #6
bmvw
Senior Member
 
Join Date: Apr 2006
Location: San Diego
Posts: 231
iTrader: (0)
Default

It is very important to look for the backdoor!

Look thru the logs for a POST to an odd-named file. The datestamp on the altered PHP files will help you find it in the raw logfile

also, htaccess ban the offending IP ranges
bmvw is offline   Reply With Quote