My .htaccess file has been hacked and I doubt that my very long computer generated password was the attack vector. The specific hack was that a RewriteCond %{HTTP_REFERER} was added that points back to featurepackedsteampowered.ru. My hunch is that the hackers exploited a weakness in my Drupal installation, or in Site5. My reason for posting here is that I haven’t found this exploit on the net so it may be quite new.
It is very likely that an out of date Drupal install could have been the weakness. I highly recommend that you contact our support team directly regarding this issue. You can open a ticket by clicking the following link.
Answer #1
a very good resource for this information is Jeff Star’s new website
http://htaccessbook.com
his regular website is
http://perishablepress.com/category/web-design/htaccess/
I am assuming that you have secured your Htaccess file and that something else is amiss.