Our admin team is aware of a possible spam outbreak from this server. This server is business critical and can not be disabled. However we have immediately disabled the email SMTP SERVER that is sending these emails pending further investigation
Please be assured that:
Further information will be posted here as soon as we are able to provide information.
We have located the hacked script to two files one named .index.php and one named ..index.php which have been injected into the template folder and system folder on one of our development configurations.
Those scripts are being disabled immediately
We have also identified the IP address which accessed those scripts which will immediately and permanently be barred from access to our servers without negotiation. Its internet provider will be notified.
We now know that more significant hacking has been undertaken than just an email spam injection. A trojan script capable of significant server damage has occurred. We are taking urgent steps to deal with this and trace its actions previously run.
We know which site was vulnerable. We now also know which piece of code was vulnerable (known vulnerability). Code removed.
Growing list of IP addresses to be barred.