Do you know what i found i last weekend?
They attack us again. I manage to trace down to the FILES they USED!
My situation is, almost 90% of the accounts on the server get affected.
I am SHOCKED TO KNOW that they have our server root password.
Basically, they are doing
ftp://username:ROOTPASSWORD@domain.com... to connect to every accounts on the server.
That explain WHY no matter how you change your ftp password, they still can login !
Along with that, they are connecting to external mysql db to retrieve the login details.
if you have mySQL port open TCP in/out, CLOSED IT!
And change your ROOT PASSWORD. set different pass for mysql root password.
till now, i am wondering how they got hold of the root pass.