Having gone through most everything (which is like trying to find a needle in a haystack) I can't seem to locate how it happened. It does have the feel of a user account level breach as no one touched root or ftp other then my own ip address. I suspect some automated tool found a flaw in an old plugin or such then went to work, it managed to get the file in the directory and probably wanted to redirect all traffic to that file but could not get any further. I spent the day looking for any other changes, my rsync to off site logs show that file as the only new addition or change to my file system. Host found no indication of root access or access by any ip address other than mine and theirs. Since the incident no new files have appeared. I removed 2 domains off the server running lesser known scripts, i updated an old tapatalk. Today I plan to target and remove any old or uneeded plugins. One question, if a plugin is disabled can it still be vulnerable? Thanks
|