Anyone have a problem with the guy still having access after you delete the
timthumb.php file, change your passwords and restore .htaccess?
My sites all got their .htaccess played with and all search engine traffic on my
sites are being redirected. I believe the person got in through the timthumb
file as I found it on one of my sites in the server, but I have since deleted the
file and changed all my passwords to very long complicated ones and he still
has access. Every time I change my .htaccess back, his bot just changes
them again, seems to be on an hourly basis. I believe he has just put a (or
many) .php file in my server somewhere and that is allowing him access now
since I have deleted the timthumb. Having my hosting guys and my tech guy
look around but havn't found anything yet.
Anybody have the same problem?
EDIT: found the php shell he was using and deleted it.