I've been doing some more searching and found some more files. I'm slowly combing through all the files to find the hidden ones. Here is what I've found so far and have deleted them.
forum/customavatars/sni.php
classifieds/uploads/sni.php
reviewpost/data/sni.php
gallery/files/sni.php
forum/imagehosting/sni.php
These appear to be for the Sniper-SA Shell.
forum/customavatars/libe.php
And I've at least got the IP address so I can search the log files to find out what they are accessing.
Is there another way to track down suspicious files? I haven't been able to find out how they are actually making it on my server. I retreived the contents of one file, sni.php but not of the libe.php.
I'm going to keep searching for files, but until I'm done I'm not going to log on to the forums.
What I've also done since then is made sure all the config files are 600 and the others are 644.
--------------- Added [DATE]1222817131[/DATE] at [TIME]1222817131[/TIME] ---------------
I've also noticed all the directories the files are showing up in are 777, mainly gallery directories and such.
|