a) security hole in a couple scripts allowed hacker to upload scripts to gain root access to server

b) update to latest 6.5.4 files to fix security holes.

Could be any file or directory - I'd first take a closer look at all .php and .pl files - I found one named l.php that gave shell access to the whole server. Another named mysql.php that gave access to databases. Another was dl.pl (or something similar) which was a perl shell app if I remember right. Also check .htaccess files for unusual entries.


- Allen
- ThreadsDev | PraiseCafe