This question may be related to a resolved thread.
Hello
A colleague and i look after the EE site at http://www.scottish-gallery.co.uk/
EE 1.6.9. Build: 20100430
This morning it was drawn to our attention that an attack like the wordpress pharma hack had been made on the site.
Three suspicious files were found in the system folder -
cigs.php
.httemp
.inode
Then it became apparent that the site’s main index.php file had been hacked with extra code added to the top.
The attack may have happened during a period when phpthumb (which is used extensively on the site) was vulnerable.The phpthumb vulnerability is described here http://foxtrot7security.blogspot.com/2011/12/new-attempts-to-exploit-old-phpthumb.html
But… is there a vulnerability in the core EE which is being exploited?
regards
Ken