He replaced my htaccess (amongst other things) to redirect to his website. So i sign up and asked them why they were hacking me. Its a german site so i didnt fully understand all their responses but at least i got on talk terms with them and eventually they released my site.
Previously to that no matter how many times i replaced the file system and database from various backup dates they simply got over written.
He doesnt want anything from me but im not about to name him either as it is obvious what actions he will take. He has told me that it is vbulletin that has been exploited and not and modifications.
I have some server logs but im not to clear on what i am looking for.
|