RayS wrote:
Lots of request for phpmyadmin and other setup scripts in the log files, and requests for odd domains.
Well
that's normal. Any public IP suffers a lot of attacks; the important part is whether or not they
succeed.
RayS wrote:
Also a persistent IRCD connection from a atw.hu domain.
In short - the server has been compromised. Backed everything up, and about to rebuild.
OK,
that's definitely not normal! Yikes.
(You're sure it's really compromised, not just an attacker
attempting to connect or something?)
RayS wrote:
Before I delete everything - I'd like to know how they got in though. Do you know where I could find the tell tale signs?
Sorry, that's not something I know much about.