A client’s site was hacked. I think a vulnerability in the CMS they are running was the vector. We’ve restored the altered files and I’m upgrading the CMS as I write this.
Should I submit a ticket anyway? Do you track these things or want to investigate?
We don’t exactly ‘track’ them but do like to have a ticket when such happens. however if the file was deleted that was modified, it becomes a very time intensive thing for us to find the logs to tell you how it was done.
Most cases it is code vulnerability as you mentioned, and most likely that, but if the file is not there, I am not sure we can do much with it to tell you how it happened.
Best in these cases to rename the file like index.htmhacked or index.phphack so the time stamps stay the same for us.