Maverick340
Ambassador of Buzz
I recevied an email today from RSA saying that my server had some fraud pages. I pointed to those pages and it was true. There were fake login pages to Novascotia Bank and Abbey
I deleted those pages but am now wondering how was the security breach took palce. Absolutely no one knows my password and anonymous ftp was off. There was also no FTP traffic log. I however saw lots of 404 HTTP requests from cetain IP addresses.
This is what i could find : *paste2.org/p/66817 | *paste2.org/p/66818 | *paste2.org/p/66820
Also there were tons of unresolved IP address that had consumed bandwitdh in excess of 10megabytes in the last 10 days.
I am pretty new at all this so please help me out. My website address is fudge dot co dot in
I deleted those pages but am now wondering how was the security breach took palce. Absolutely no one knows my password and anonymous ftp was off. There was also no FTP traffic log. I however saw lots of 404 HTTP requests from cetain IP addresses.
This is what i could find : *paste2.org/p/66817 | *paste2.org/p/66818 | *paste2.org/p/66820
Also there were tons of unresolved IP address that had consumed bandwitdh in excess of 10megabytes in the last 10 days.
I am pretty new at all this so please help me out. My website address is fudge dot co dot in