I have client that we built a Joomla 1.015 site for using the forest fire theme. They just brought to my attention that the site was compromised with about 200 line of viagra URL's at the end of the index.php file.
Any thoughts on how someone could write to that file? The server does run suPHP. I have currently set the index.php file to permission 444 but it makes me wonder if there is anything else lurking on the site unseen at this time.