That is exactly what it was. After some fighting and them telling me it was an XSS attack multiple times, they finally (apparently) have fixed it. Ironic, because their support website was also affected by this issue.
This is what they told me (They said "Dear Blair".. I've got no clue who Blair is.):
Quote:
Dear Blair,
We have investigated the root cause of the issue and it is a type of iframe hacking from an Serbian IP which got into one of the customised php scripts of one of the clients and then got FTP access of domains and modified the pages.
We have removed that script and the banned the IP and process of removing that hacked script from the domains in under process.
We have also added some strong mod_security and firewall rules to prevent this .
Please feel free to contact us back in case of any other information.
Please feel free to contact us back in case of any other information.
Regards,
Alan
|