Hi,
Someone was able to access one of our users and installed a back connect. With this back connect script, he was able to not only access the user's account but our entire server and defaced all websites ( root access ).
Any ideas of how this is possible? Is bruce-force an option or there might be another options?
We're currently recovering a backup but we need to find out what happened in order to prevent this from happening again.
Someone was able to access one of our users and installed a back connect. With this back connect script, he was able to not only access the user's account but our entire server and defaced all websites ( root access ).
Any ideas of how this is possible? Is bruce-force an option or there might be another options?
We're currently recovering a backup but we need to find out what happened in order to prevent this from happening again.