I’ve sent yet another request for help to Dreamhost but no reply so far.
To clarify: *what* strikes you as a good indication that the attack is coming from somewhere else? The replacement of the file “core.system.php”?
I was thinking the opposite: that it suggested that a hacked file was being stored somewhere in the hosting account and periodically moved into the system folder (which is NOT named “system” on my EE installation).
It’s definitely a file replacement. My current 1.7.1 build 20110520 version of core.system.php has a copyright of “2003 - 2011” in the comment block at the top; when the file is hacked, the copyright date is “2003 - 2010”.
Another peculiar thing: I’ve already reported that when the core.system.php file is hacked, my EE control panel footer reports EE 1.7.1, but with an earlier, incorrect build number. However, I never had that earlier build of 1.7.1 installed. I went straight from 1.7.0 to 1.7.1 build 20110520.
So the modified “core.system.php” is possibly not a hacked version of a file found in my own installation and then stored for later re-use. If that’s true, it might suggest that the attackers modified their own copy of EE’s core file.
I’ll let you know what Dreamhost says. As I’ve already noted, they’re complaining about my having directories set to 777, but this is what the EE installation guidelines call for. I’d like some advice about stricter permissions that will work for such directories as cache and images.