[quote1242403424=ZoD]
PHP code cannot change by its self. Hence, this was injected via. 1. Some upload script that allowed someone to upload a web script (like php) onto the server
Or the more likely reason
2. you were on a shared host with absolute shit security. someone who had an account on your box ran a script to search all index.php files on the server and modify it. Index.php because its the most common (hence why this is the most likely reason, its a general attack, not specific to td I'm guessing)
Only way to stop that is....get off your homo host.
[/quote1242403424]
Wrong and wrong. The box is tight, it's a VPS account, so it's seperated.
I think the homo password they gave me on the new account, which was a very basic dictionary word, was sniffed out and a script was installed that infected all the index.php files.