Mush
Joined: 06 Apr 2005 Posts: 2 Location: Batavia, IA US
|
Posted: Mon Apr 10, 2006 8:48 am Post subject: Hacked through L10Apps? Request for discussion |
|
|
My domain was recently hacked and turned into a Bank of America phishing site.
I found a Bank of America subdirectory in my L10Apps folder, along with a virus called htaccess.php.
I was running WordPress, which was also compromised, and Gallery, in addition to the LevelTen Hit counter.
Query is this: is there any known way to use this app to compromise a server? I mean, it doesn't seem to allow uploads or anything, so I'm assuming the compromise came through another app. I just couldn't figure out why they'd have put files in the L10Apps directory if they already had root on the domain. So the existence of malicious files in that directory had me wondering.
Any thoughts/comments/teasing would be appreciated.
Cheers,
Mush |
|