Re: htaccess replaced by malicious script
Date: February 15, 2012 03:31PM
I would suggest an ip/isp log.
Also Go on the offensive and throw some malicious shit of your own on your own website. Not for your users but specifically targeting the compromised path to your .htaccess files. Then get your buddies together and attack.
Or just iplocate them and call there isp, with logged proof of there actions and, you've got yourself the permanent solution your looking for, but there probably routing there attack through 20 different pc's all over the world so make sure you get them to download something, so you can actually trace it, or perhaps embed your .htaccess files because there obviously getting to those, not sure if you could get away with a renaming action file but its worth a shot.
By just changing your passwords, or hosts, your not doing anything, chances are there not taking the password route. Your probably being attacked by an advertising company with 20 different hackers at there disposal, they may be using a cracker program but they are not crackers(crackers are those that guess at passwords, where-as Hackers find vulnerabilities and exploit them through various methods), and I can tell you that for sure due to the sophisticated methods there using.
If you attack they will just disappear, because there trying to make money, and if your slowing that process down, then there not making as much, so there is no point in a counter-attack from where the stand, because it would just not make financial sense.
If you want some help, I could use the practice.