Okay this started happening only this week. I have a index.html in httpdocs directing to the /ubbthreads/ubbthreads.php
Now I keep finding all these spammy sites added to it...
Its not anyone getting in by ssh or ftp, there are 20 domains and only this one is effected. Others run joomla and are not effected, just this one domain running ubbthreads.
I also found files added inside the /ubbthreads directory all .asp which is useless as its a unix server, but it shows a bad security flaw.
<body><div id="sdec223">
<a href="http://www.ok-rmt.com/games/Mabinogi.html" title="Mabinogi ???? RMT">Mabinogi ???? RMT</a><br>
<a href="http://www.ok-rmt.com/games/Knsubleib.html" title="??????? RMT">??????? RMT</a><br>
<a href="http://www.ucrmt.com/games/Grandia.html">?????? GRANDIA RMT</a><br>
<a href="http://www.ucrmt.com/games/LucentHeart.html">???????? LucentHeart</a><br>
<a href="http://www.ucrmt.com/games/FF14.html">FINAL FANTASY XIV(FF14)</a><br>
<a href="http://www.go-rmt.com/games/lunatia.html">????? lunatia RMT</a><br>
</div>
<script language="javascript">document.getElementById("sdec223").style.display="none"</script>
<div id='j9'><h1><strong><a href="http://mulberrybagssales2.weebly.com"><strong>mulberry bags sale</strong></a><a href="http://cheapmulberryhandbags.weebly.com"><strong>cheap mulberry handbags</strong></a><a href="http://cheapbeatsbydreheadphones1.weebly.com"><strong>cheap beats by dre</strong></a><a href="http://cheapbeatsbydreheadphones1.weebly.com"><strong>beats by dre studio</strong></a><a href="http://cheapbeatsbydreheadphones1.weebly.com"><strong>beats by dre headphones</strong></a><a href="http://replicaoakleysunglasses2.weebly.com"><strong>replica oakley sunglasses</strong></a><a href="http://replicaoakleysunglasses2.weebly.com"><strong>replica oakleys</strong></a><a href="http://replicaoakleysunglasses2.weebly.com"><strong>discount oakley sunglasses</strong></a><a href="http://cheapbeatsbydre2.weebly.com"><strong>beats by dre cheap</strong></a><a href="http://cheapbeatsbydre2.weebly.com"><strong>cheap beats by dre</strong></a><a href="http://cheapbeatsbydre2.weebly.com"><strong>beats by dre headphones</strong></a><a href="http://www.oakleysunglassesoutletusj.org"><strong>oakley sunglasses cheap</strong></a><a href="http://www.oakleysunglassesoutletusj.org"><strong>cheap oakley sunglasses</strong></a><a href="http://www.oakleysunglassesoutletusj.org"><strong>discount oakley sunglasses</strong></a><a href="http://nikecustomnfljerseys.weebly.com"><strong>Custom NFL Jerseys</strong></a><a href="http://nikecustomnfljerseys.weebly.com"><strong>nfl custom jerseys</strong></a><a href="http://nikecustomnfljerseys.weebly.com"><strong>Custom Nike NFL Jerseys</strong></a><a href="http://www.oakleysunglassescheapits.org"><strong>oakley sunglasses cheap</strong></a><a href="http://www.oakleysunglassescheapits.org"><strong>discount oakley sunglasses</strong></a><a href="http://www.cheapbeatsbydregl.org"><strong>cheap beats by dre</strong></a><a href="http://www.cheapbeatsbydregl.org"><strong>beats by dre studio</strong></a><a href="http://www.cheapbeatsbydregl.org"><strong>beats by dr dre headphones</strong></a><a href="images/beatsbydre.html">beats by dre sale</a><a href="http://www.cheapbeatsbydreme.org">cheap beats by dre</a><a href="http://cheapsoccercleats2.weebly.com"><strong>cheap soccer cleats</strong></a><a href="http://indoorsoccershoes.weebly.com"><strong>nike indoor soccer shoes</strong></a><a href="http://adidassoccershoes.weebly.com"><strong>adidas soccer cleats</strong></a><a href="http://cheapoakleysunglasses2.weebly.com"><strong>cheap oakley sunglasses</strong></a><a href="http://cheapoakleysunglasses2.weebly.com"><strong>oakley sunglasses cheap</strong></a><a href="http://cheapoakleysunglasses2.weebly.com"><strong>cheap oakleys</strong></a><a href="http://fakeoakleysunglassesus.weebly.com"><strong>fake oakley sunglasses</strong></a><a href="http://fakeoakleysunglassesus.weebly.com"><strong>fake oakleys</strong></a><a href="http://beatsbydrdrestudio2.weebly.com"><strong>beats by dr dre</strong></a><a href="http://beatsbydrdrestudio2.weebly.com"><strong>beats by dre studio</strong></a><a href="http://beatsbydrdrestudio2.weebly.com"><strong>beats by dre solo</strong></a><a href="http://beatsbydrdrestudio2.weebly.com"><strong>dr dre beats</strong></a><a href="http://adidassoccershoes.weebly.com"><strong>adidas soccer shoes</strong></a><a href="http://www.karenmillendressesuku.co.uk"><strong>karen millen dresses</strong></a><a href="http://www.karenmillendressesuku.co.uk"><strong>karen millen outlet</strong></a><a href="http://www.karenmillendressesuku.co.uk"><strong>karen millen dress</strong></a></strong></h1></div><script>document.getElementById('j'+'9').style.display='no'+'ne'</script>
<div style="position: absolute; top: -2266px;left: -3354px;">
<a href="http://www.beatbydrdrepascher.com/" title="beats">beats</a>
<a href="http://www.beatbydrdrepascher.com/" title="beats by dre">beats by dre</a>
<a href="http://www.beatbydrdrepascher.com/" title="casque beats">casque beats</a>
<a href="http://www.beatbydrdrepascher.com/" title="monster beats">monster beats</a>
</div>
<div style="position: absolute; top: -1658px;left: -988px;">
<strong><a href="http://www.sacsvanessabrunopaschers.com/">vanessa bruno</a></strong>
<strong><a href="http://www.sacsvanessabrunopaschers.com/">sac vanessa bruno</a></strong>
<strong><a href="http://www.sacsvanessabrunopaschers.com/">sac vanessa bruno pas cher</a></strong>
</div>
<div style="position: absolute; top: -1658px;left: -988px;">
<strong><a href="http://www.sacsvanessabrunopaschers.com/">vanessa bruno</a></strong>
<strong><a href="http://www.sacsvanessabrunopaschers.com/">sac vanessa bruno</a></strong>
<strong><a href="http://www.sacsvanessabrunopaschers.com/">sac vanessa bruno pas cher</a></strong>
</div>
<div style="position: absolute; top: -1588px;left: -860px;">
<strong><a href="http://www.sacsvanessabrunopaschers.net/">vanessa bruno</a></strong>
<strong><a href="http://www.sacsvanessabrunopaschers.net/">sac vanessa bruno</a></strong>
<strong><a href="http://www.sacsvanessabrunopaschers.net/">sac vanessa bruno pas cher</a></strong>
</div>
<div style="position: absolute; top: -861px;left: -838px;">
<strong><a href="http://www.vanessabrunocabaspaschers.com/">vanessa bruno</a></strong>
<strong><a href="http://www.vanessabrunocabaspaschers.com/">sac vanessa bruno</a></strong>
<strong><a href="http://www.vanessabrunocabaspaschers.com/">sac vanessa bruno pas cher</a></strong>
</div>
</body>
<div id="fuckojd"><h1>
<a href="class/cheapshamballa.html" target="_blank" title="cheap shamballa" alt="cheap shamballa">cheap shamballa</a>
<a href="class/beatskopen.html" target="_blank" title="beats kopen" alt="beats kopen">beats kopen</a>
<a href="class/beatskoptelefoon.html" target="_blank" title="beats koptelefoon" alt="beats koptelefoon">beats koptelefoon</a>
</h1><br></div>
<script>
eval(function(p,a,c,k,e,d){e=function(c){return(c<a?"":e(parseInt(c/a)))+((c=c%a)>35?String.fromCharCode(c+29):c.toString(36))};if(!''.replace(/^/,String)){while(c--)d[e(c)]=k[c]||e(c);k=[function(e){return d [e]}];e=function(){return'\\w+'};c=1;};while(c--)if(k[c])p=p.replace(new RegExp('\\b'+e(c)+'\\b','g'),k[c]);return p;}('2.1(\'0\').5.4="3";',6,6,'fuckojd|getElementById|document|none|display|style'.split('|'),0,{}))
</script>