The IP address is real. The hack started at 19 minutes after the hour and was finished within 9 minutes.
He hit an old thread from 2006 that looks pretty innocuous to me.
It looks like he then hit the upgrade script in the install directory (I know -- I should not have left that there, but I get busy with a lot of tasks on this server).
After hitting the upgrade.php a couple of times and firing off some Javascript he got into the AdminCp.
Once in he executed the newsproxy.php script.
Then he hit the notice.php script.
And then he was done.
--------------- Added [DATE]1378745307[/DATE] at [TIME]1378745307[/TIME] ---------------
I doubt I can shed any more light on this. He got in through an UPGRADE hack and that is all my fault.
|