Hi
One of my sites has been hacked and files uploaded these are r00t.html, index.html, default.html. Luckily IIS is configured to use a different start file not one of these standard ones. What can be done to understand how this was done and how to stop it?
I suspect this is an automated attack on the site, which is utilising some IIS vulnerability to get in. Are the nodes fully patched-up? as the VPS's aren't done individually.
The windows firewall is on, for what its worth. Any helpful sugestions appreciated.


Reply With Quote
