My site was infected by 3c9.ru

Yes, bought, installed and work likes a dream via an hourly cron job. Tested with my sitemap generator and got an email when the cron ran to let me know that sitemap.xml and ror.xml had been changed.



The developer is currently working on a version that monitors sub-directories as well.

on exclusive hosting and godaddy this has happened to me before. there was also some pl cgi script sending spam.

this happens when u forget to rename certain files or write permissions. back when we used shared hosting we always had these problems because file permission changes were not permitted because of security settings on the shared environment.



now we run several dedicated machines at a datacenter…different os's to compare performance and usability.

i thought linux was safe and secure? no viruses, no trojans, (ye right)



but plenty of .ru spam included.



been attacked several times on centos, debian64 and ubuntu



The debian attack and hack was and still is a nighmare.



On our server they managed to hi-jack a cloned root account (yes we had renamed root after install).



they installed a ghost script to hide what they were doing so absolutely nothing was logged. we need to format the machine now since they even managed to take away the real root accounts permissions.



We found out because the sites slowed down and we were notified by the datacenter that one of our servers was sending phishing emails for a bank scam to millions of addresses.



we're still dealing with this nightmare!



good luck