Re: Server Hacked

I am almost certain that the system was compromised due to b2evolution (phpBB, too, if it uses xmlrpc). Many PHP applications are vulnerable due to issues within XML RPC, specifically http://<host>/xmlrpc.php .. There are readily available exploits available that will give the attacker a command line via this vector. With that said - if you configured Apache to run as a restricted user (ie: nobody), then the attacker would have only modified pages in which the restricted account had access to write.

There are mass autorooter worms traveling around that perform this automatically: successfully exploit, change all index.* pages, drop an IRC/DDos Daemon into a hidden (or not so hidden directory. hint: check /tmp for weird binaries and other files).

Run a find command to look for all modified files within the last N hours.

for all files owned by nobody and modified within the lat 24 hours ( N x 24)
find / -user nobody -mtime -1 -print

run this perl script to exploit yourself:

