aress

Active Member
May 5, 2004
30
0
156
Hello,

I have a cPanel server. Recently we had a user spamming arround from the server by uploading some scripts in /tmp. Since we had PHPSuExe enabled we were easily able to identify the user, spamming was in control as soon as we deleted the scripts from tmp.

Now the user claims that he has not uploaded any file..? So my question is.. Is there a way to find out which PHP file has been used from that users site to upload the scripts in TMP.

Any suggestion would be appreciated.

Thanks in advance.
 

chae

Well-Known Member
Apr 19, 2003
145
0
166
Auckland, New Zealand
If it helps any we have a dose of that last month and it ended up that the script were being uploaded through an old version of PHPBB. As soon as we disabled the board loads dropped and no more scripts were being uploaded.