26 Янв 2012
Привет всем. Проблема такая: сайт взломали, изменили только index.php... Это уже второй раз, после первого изменил все пароли... Версия дле 9.8, применил баг-фикс от 10.0... Кто нибудь сталкивался этим взломом? Что делать...?
Содержимое index.php после взлома:
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"><head>
  <meta http-equiv="Content-Type" content="text/html; charset=utf-8" />

  <meta charset="utf-8" />

  <meta name="viewport" content="initial-scale = 1.0, maximum-scale = 1.0, user-scalable = no, width = device-width" />

  <meta name="description" content="Hacked By Egyptian Ghosts Contact To https://www.facebook.com/egyptians.ghosts" />

  <meta name="keywords" content="Hacked By Egyptian Ghosts Contact To https://www.facebook.com/egyptians.ghosts" />

  <meta name="keywords" content="Hacked By Egyptian Ghosts  Contact To https://www.facebook.com/egyptians.ghosts" />

  <meta name="description" content="Hacked By Egyptian Ghosts  Contact To https://www.facebook.com/egyptians.ghosts" />

  <meta name="copyright" content="Egyptian Ghosts Copyright 2015" />

html, body { font-family: Segoe UI Light;  }
h1 {
  color: #09F
    margin-top: 20px;
            text-decoration: none;
      font-family: 'Helvetica Neue', Helvetica, sans-serif;
            color: #FFF;
            background: #7F8C8D;
            padding: 15px 30px;
            white-space: nowrap;
            -webkit-border-radius: 5px;
            -moz-border-radius: 5px;
            border-radius: 5px;
            margin: 10px 5px;
            -webkit-transition: all 0.2s ease-in-out;
            -ms-transition: all 0.2s ease-in-out;
            -moz-transition: all 0.2s ease-in-out;
            -o-transition: all 0.2s ease-in-out;
            transition: all 0.2s ease-in-out;
  background: #3498DB;

  background: #2980B9;
  <title>[#] Hacked Egyptian Ghosts [#]</title>

  <link href="http://fonts.googleapis.com/css?family=Cantarell" rel="stylesheet" type="text/css" />

  <link rel="stylesheet" href="http://codersleet.cum.ir/Css/style.css" media="screen" type="text/css" />

  <link href="http://fonts.googleapis.com/css?family=Cantarell:400,200" rel="stylesheet" type="text/css" />

  <link href="//netdna.bootstrapcdn.com/font-awesome/4.1.0/css/font-awesome.min.css" rel="stylesheet" />

</head><body style="background: black url(https://fbcdn-sphotos-h-a.akamaihd.net/hphotos-ak-xpa1/v/t34.0-12/10994795_1405027403137045_1372025589_n.jpg?oh=15cffc804f1532a580846117147e2f0d&amp;oe=54ECBB60&amp;__gda__=1424747313_8788b71f61776af38cca0207cc10e931) no-repeat fixed center; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" marginheight="0" marginwidth="0">
<nav class="social">


<center><a href="http://www.gulfup.com/" target="_blank" title="مركز تحميل الصور">&nbsp;</a><!-- Messages --> <font color="white" face="Cantarell" size="6">[<font color="#3df500">#</font>]
HACKED BY Egyptian Ghosts [<font color="#3df500">#</font>]</font><br />
<font color="#3df500" face="Cantarell" size="+1"><font color="#3df500" face="Cantarell" size="4">[<font color="#FFFFF">#</font>] We Are
Arabian Ghosts [<font color="#FFFFF">#</font>]</font><br />
<font color="#33ccff" face="Cantarell" size="+1">[<font color="#FFFFF">#</font>]
Contact Us :[<font color="#FFFFF">#</font>]<br />
<br />
</font><a href="https://www.facebook.com/egyptians.ghosts" class="boton azul" target="_blank">Facebook</a>
<footer id="det" style="border-top: 1px solid rgb(61, 245, 0); border-bottom: 1px solid yellow; background: rgb(0, 0, 0) none repeat scroll 0% 50%; position: fixed; left: 0px; right: 0px; bottom: 0px; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; text-align: center;"><font color="3DF500" face="Cantarell" size="4">[<font color="white">#</font>]
Message : We Are Arabian Ghosts We Are Legion We Do Not Forgive We Do
not Forget Expact Us ! [<font color="white">#</font>] </font><font color="white" face="Cantarell" size="4">
● </font></footer>
<embed src="https://www.youtube.com/v/watch?v=VHNSgNfm7mk&amp;autoplay=1" type="application/x-shockwave-flash" wmode="transparent" height="1" width="1" /></center>

Смотри файлы шаблона, скорее всего в них шелл сидит, или в модах скачанных с левых сайтов... Других вариантов в общем то почти быть не может.