il y a une heure, ploaie a dit :I suspect a module, but I found nothing in logs.
Very hard to find where the issue is. You can analyse web server logs for POST request (most of the time, the way attackers use a hole), but very long and difficult. That the reason we made a simple small script which alert you for any file creation or change. Here is the free script.