My client said to me that the domain is being hosted on a private server, so no ‘other domains’ could have caused this. So basically this could be narrowed down to two possible causes, the FTP password got compromised, or there is some vulnerability in our EE installation (1.6.8).
Thank you for reporting this. We take security very seriously and will do our best to work with you to figure out what’s going on. To that, we need some additional information from you:
What version and build are you running? Are there any other scripts on your account, whether in use or not (php, etc…)? While we work through this, please check through these files:
- path.php
- config.php
- index.php
to ensure that there is no unusual code such as iFrames or Javascript includes; if you do find such code, please back-up the file and remove said code. If you are unsure of what does or doesn’t belong in these files, do not hesitate to ask. You may also wish to refresh your files by following the build update instructions, upgrading to the most recent version / build in the process.
Any thoughts? We are currently in the process of fixing this, but still need to determine the cause so we can prevent this in the future, any help would be greatly appreciated.
Is that a managed server? Your host should be able to pinpoint the vector of attack so that steps can be taken to prevent this in the future. My suggestion would be to replace all of EE’s files, and change all passwords (EE, MySQL, FTP).