Last night i've found suspicious url in the Apache Status for one of my Evo site:
mydomainmame.com/viagra.html
mydomainmame.com/cialis-pastilla.html
following these url, there's a redirect to a "farmacy" store (edwebstock
dot com )
:( the site was obviously hacked
Evo has been updated to 1.08, over a month ago, when I moved the site to a new server.
I suspect they used the Forgot Manager bug, because
i've found a new admin user (named
support - support@
mydomain.com).
Now i'm cleaning up:
- deleted the new account
- changed evo admin password
- changed DB password
- deleted all evo files and replaced/updated with a clean 1.0.9
Any suggestions?