Hello,
I have a cPanel server. Recently we had a user spamming arround from the server by uploading some scripts in /tmp. Since we had PHPSuExe enabled we were easily able to identify the user, spamming was in control as soon as we deleted the scripts from tmp.
Now the user claims that he has not uploaded any file..? So my question is.. Is there a way to find out which PHP file has been used from that users site to upload the scripts in TMP.
Any suggestion would be appreciated.
Thanks in advance.
I have a cPanel server. Recently we had a user spamming arround from the server by uploading some scripts in /tmp. Since we had PHPSuExe enabled we were easily able to identify the user, spamming was in control as soon as we deleted the scripts from tmp.
Now the user claims that he has not uploaded any file..? So my question is.. Is there a way to find out which PHP file has been used from that users site to upload the scripts in TMP.
Any suggestion would be appreciated.
Thanks in advance.