09-19-2017, 06:20 PM
I think it was a genuine attack, since the provider then shut the site down until I removed the offending scripts. No idea how they got through, I have a feeling they could have found some kind of a weakness in Apache's fancy directory listing, because everywhere where the directory was listed by Apache itself, there was a malicious script there, and nowhere else.