I am having trouble with a series of EVO websites that got hacked in the last two weeks.
On this website, I had done the following things:
- Removed all the files from the server
- backupped the database
- Created a new database
- Reinstalled MODx 1.1 from scratch using the new database
- Applied the security patch
- Updated the database with my saved version
- Reuploaded the files in the /assets directories, making sure every one of them was safe (no .php files)
I have found (again) files on this one, despite the above actions.
What I am now doing is checking which files have been uploaded at a given date (28th of november in this case) and deleting them on every Evo website I own.
Am I missing something?
Have I forgotten any action?
How can I spot the file or process they are using to upload the hacking files?