I maintain a server to host my files and a number of websites for hobbies and friends. I just noticed that the site summary being returned in google for one of my domains were all porn related (search "fringe.org", 1st result).
Checking the source, I found obfuscated php code (see here) I didn't recognize included in /index.php of that domain after the <\/html>. I deleted it and then also found and deleted it from the index.php of 5 other domains in my web root (although there were 3 or 4 without it).
Server details:
- LAMP with Ubuntu 10.10 fully updated very regularly
- PHPinfo: link
- My password is very secure, but I have given accounts with web-write access to 3 or 4 friends. I'm not sure how secure their passwords are.
- I believe access is only by ssh or sftp
My question is what steps I need to take now. Data and content are backed up off the server regularly. It makes me feel dirty so I would be inclined to wipe and rebuild the whole thing, but I am 10 days from the big annual event of my largest site.
Thanks so much in advance for any tips.
Well ... shit. Thanks for the feedback and info. It's tricky how easy it is to get yourself into trouble these days. I would have marked all of your answers as accepted if I could, they were all helpful. I'll be doing a full wipe and carefully reconstructing things asap.