Ok so I did a Suspect File check and found this file on the server:
modevfration.php >> apparently it is a php.backdoor trojan
I am going to check into the other mods to see if there are any security breaches. Plus I got some info from the vbulletin.com forums on how to secure vb much more so I will be doing that. Thanks for the help so far and I will report back on my progress.
I think I may know why the worm slipped in. I had HTML enabled for a forum where only I could post but I think having HTML is a bad idea period so it's disabled as well.
|