This morning i found movies inside my server (debian VPS, apache,webmin/virtualmin), files are located in /var/log/roundcube/./ and the user/group is www-data
I looked in my log (apache,proftp,auth) and i didn t found weird lines. rkhunter found nothing bad.
how can i check the history of a file (in hidden folder) or the way that the user uploaded movies in this folder.
i guess it s a backdoor but when i scan my website i found nothing bad.
i think i ll cut my website for a while and see if there is new movies in folder, if yes it means that the user have ftp/ssh access or that the backdoor is not in my var/www/
Thanks by advance