Today I was informed by my host about some spamming activity taking place on my site, attack seemingly sent from www.mysite.com/tell_a_redacted.php. I searched the whole of my site but couldn't find that file. I thought maybe tell_a_friend.php had been corrupted but didn't look like it had.
Having no help from host except being told to "update to the latest version of oscommerce as outdated third party software is not safe", I took the following steps to clean the site:
Wiped the whole site, restored from a clean backup, removed tell a friend box, set tell_a_friend.php permissions to 0000, checked all folder and files permissions.
I run 2.2ms2 version and already had applied the following security measures long ago: site monitor, IP trap, security pro, all permissions set correctly, admin renamed and pw protected, file_manager.php and define_language.php removed long ago, htaccess protection.
My problem is I don't know where they came in from, in case it's from a place other than tell_a_friend.php, it could happen again.
Any advice would be greatly appreciated.
Thank you for reading.
Isabella
Edited by Biancoblu, 08 January 2011, 18:30.















