Location, I have analyzed this about 40-50 times in the last 3 months, it seems google is the tool of choice, don’t ask me how google finds it.
As for the root of the site, it can get there easily using asp scripting, it can only go up to the root level of the user in the path, many times when this happens every domain in the users account is affected, that is why it is so important to have the asp upload capabilities secured.
Once I sw the hack becasue someone left an install file for an asp based portal, with that install file they were able to issue some commands that allowed them to find other files something like: Login | HSTS Redirection Community etc, so there was some file searchbrowse function to the installer that they knew about and exploited.
interesting.
i have now noticed, that it isnt in fact just the root - they managed to get their stuff into ALL the folders (and subfolders) in the site, including the default ones installed with a new site.
snooper, I hope you have requested a restore from the support team. If you do this too late, your hacked files could become a part of our backup images
[QUOTE=Yash]
snooper, I hope you have requested a restore from the support team. If you do this too late, your hacked files could become a part of our backup images
[/QUOTE]
Thanks Yash, i havent actually asked, most of the files i deleted myself.
but i did submit a ticket to find out what happened, and i havent heard anything yet…[RS #BOU-80294-773]
I just never could understand the mentality of proving a point and destroying (or attempting to) someone’s work. Maybe these people are just sick..I wonder why they don’t use their “talent” to try and earn some honest money.
I am happy to hear the way Jodo is helping out with this though for you snooper!