Some exploits are hard to track down, its could be as simple as a shell script disguised as an image, the one thing most of these exploits have in common is that they attack world writable files, not many files need to be world writable but some virtual hosting setups create lots of them due to the way the virtual accounts are managed
if you can ssh to your account, you can run
find /your/directory -perm +o=w -follow
and get a list of world writable files, Im betting the files that keep getting defaced are world writable
You can remove the world writable bit with this command
chmod o-w file.name
__________________
“Ours is a world of nuclear giants and ethical infants. We know more about war than we know about peace, more about killing than we know about living. If we continue to develop our technology without wisdom or prudence, our servant may prove to be our executioner.” ― Omar Bradley (1948)
|