So it appears our webserver has had a visitor. Luckily, didnt cause any damage but left me a nice html/txt file in the root of most of our websites called Hitman with the instruction to improve my security.
Our webserver runs quite a few applications and I don't know exactly where to start with finding the root of the exploit. Are there any scans/tips/tricks I can use to see how this might have happened. All files were created at a similar time.
Funny thing is, we actually used a PCI scan for the web server not that long ago when we were thinking of holding transactions on it.. damn happy we don't now, but we didnt have any major holes show up IMO.
Any help is much appreciated.
Our webserver runs quite a few applications and I don't know exactly where to start with finding the root of the exploit. Are there any scans/tips/tricks I can use to see how this might have happened. All files were created at a similar time.
Funny thing is, we actually used a PCI scan for the web server not that long ago when we were thinking of holding transactions on it.. damn happy we don't now, but we didnt have any major holes show up IMO.
Any help is much appreciated.