Anyone run into this hacker? "Owned by Mr BenLaden Moroco CRAcK3r" One of my wordpress installs redirected via htaccess to index.php in subfolder I can understand htaccess being changed...its possible wrong permissions left.But to write another php file does that mean he had ftp access? Thanks for your advice
Hacker is Hacker..! He may Have Got into your Files through some backdoors..! WP is getting hacked a lot nowadays..! anyway keep the file permissions as said in the WP guide to have some security for yourself..!
To write another PHP file does not mean he has FTP access. He can get it anyhow. First, it is possible that he used an exploit for a vulnerability that exists on WordPress. Sometimes a certain vulnerability can enable a "hacker" to include files such as what they call a shell (like c99) that gives them full control on the server. Such as browsing ALL the files even if they're restricted, writing new files, creating FTP users, changing passwords, and accessing all of these sensitive data. Check your WordPress security for vulnerabilities.
He could have hacked the server which means if you don't own it you can't do anything about it, only contact the company and tell them to secure there servers much better and check why it was hacked and how.
probably some kid playing with toys, true hackers don't leave their location, nor logs, check apache accesslogs. the better hackers are from the white side and they will make your server more secure and email you instead of hacking whatever they can. after you get his IP, call his ISP