aargh…

that’s <A2RGH> for you purists out there…

but yes, aargh. i discovered that my entire site had the .php files appended with the code i discovered the other day, not just my wordpress installation.

furthermore, although tech support has no evidence of a hack and says it was that way when i uploaded it, i checked my backup from last month and there were no modifications to any of the files a month ago.

aargh… 8/

[EDIT] after having been confronted with evidence (the backup that wasn’t modified) they claim to have found evidence of an account breach on 23 august, and recommended that i change my password… duh… 8/

[FURTHER EDIT] it turns out that the “evidence” was a known (to me) IP address, logging in to check their mail. however, i did find another IP address from renton logged in as root on the 20th and 21st of august, and when i suggested that someone had the root password, suddenly all the servers wend down and just recently came back up… all of them except the tech support site… very interesting…