Posted by Seanybob on Apr 26
Just an update to the previous post on this topic. The attacker has
been moving around his datafile containing the list of urls with shell
scripts installed.
His old one:
http://xmors.byethost7.com/mynameisahmed..html
has been shutdown.
Did some investigating, and found some other places this guy has
hidden his data he collected.
This link is one he used before the first one I posted. It was working
until a few days ago, when it looks like he…




