View Single Post
Old 01-10-2013, 11:47 PM   PM User | #1
Azam.net
New Coder

 
Join Date: Nov 2003
Location: Bloomsbury, London
Posts: 96
Thanks: 3
Thanked 0 Times in 0 Posts
Azam.net is an unknown quantity at this point
Exclamation How to identify security loopholes in a website that has been hacked to send spam?

I've been informed by our webhost that one of our sites has been hacked. By gaining unauthorised access to the site, hackers have been able to send out spam using our domain name (using from: xyz@ourdomainname.com in the spam).

We've been asked to remove these violated files and close any security vulnerabilities before the webhost can restore the site. We've been able to identify the files and removed them.

However, how can we specifically pinpoint and close any security loopholes so that it doesn't happen again? The site is using lots of scripts etc. so we don't know where the vulnerability could lie.

We've ran lots of sites since the 1990s and never had a single security violation, so this situation is a new one to us.

Thanks a million for any advice.
__________________
Domain Exhibit - premium domain names and websites with significant traffic | quote Coding Forums for additional 15% discount!
Coding Freebies - free scripts and software worth hundreds of dollars
Azam.net is offline   Reply With Quote