Here is an update on this particular attack. Access logs show that an attempt to call a non-existent page happens every minute from a different ip address. The page is something like FaqJEd.php (of course we have faq.php, but not this file) This file WAS on our server when it was compromised. We are weeks out from having that file removed and they are still attempting to hit it. Hopefully they will notice they are getting nowhere and cease.
I also noticed a second file AWal.php or Awor.php that did not belong, again this was present during the compromise.
We have ceased using any unnecessary hacks or add-ons because of the security issues.
|