Quote:
Originally Posted by mathewka010
another preventative measure to take is to add ftp.allow, ftp.deny and ftp.log
|
Won't help much. Usually PHP Backdoors / Injections are the problem to care about. Bruteforcing FTP accounts is rather time-consuming compared with a simple XSS / Injection etc.
And - I would recommend to take the site offline and reinstall all files checking them twice for security problems.
Since the site was infected, how you can be sure that every file is really clean and nothing has been modified to fool your scanners ?
Additionally - there was a security problem so by keeping everything as it was, the problem isn't fixed, just the results but the problem maybe is still present.
Oh - and maybe upgrade your outdated PHP 4.4.9 to a newer version.