Hi,
My zenphoto gallery has been hacked too. I have been lucky so far because only a few files have been infected. Therefore, I have been able to delete all the code and files added by the hacker (well at least that’s what I think).
However, I have studied the statistics of my website visitors. I have noticed that every time I change something in the ajaxfilemanager directory, a visitor is coming a few hours later. The IP address is different each time but the visitor always comes from a URL (referring URL) such as “mail.yahoo.net” or “mail.yahoo.com” and is trying to have a look at something in the ajaxfilemanager/inc/ directory.
Therefore I think that someone is monitoring my FTP and can be somehow alerted by email every time I try to change something. I guess some files are still infected.
I wonder if deleting the ajaxfilemanager directory and upgrading zenphoto will change anything since the hacker will be alerted by email...
I currently use Zenphoto version 1.3.1.2
Has anyone noticed the same problem?
Thank you in advance for your help.
PS: I apologize for my poor English; you might have noticed that English is not my native language