CFM <script> injection hack...
Our servers have been hacked and we're having trouble finding the point of entry for the trojan.
What we're seeing is essentially every web file (.htm(l),.cfm,.php,.js, etc) being appended with a script code trying to load a swf from "chanm.3322.org/flash/".
We've cleaned it up once and then restarted the server and it got infected again.
Is this familiar to anybody else here yet? Any tips on cleaning this up??
Ugh, headache!
Thanks
Paul
