this morning an admin account was compromised on our forum. They then sent out a mass email stating that the forum was promoting a website (which we do not), made changed to allow uploading of php, and then uploaded a php script, this is the script that was uploaded
http://binibrahim.com/shells/godshell.txt
we have removed the files that were uploaded, dealt with the account, and think we have set everything back to normal, but are worried what exactly what this script may have done.
has anybody seen this script before, or can see what its meant to do, as we dont want to have missed any back doors that may have been left behind by it