One of our clients got hacked. Whenever you type in the company website you get the SpyKids hacked index page.
The site is hosted on an outside webserver and is completely normal to anyone outside the domain.
(INTERNALLY) If you type
www.mycompany.com/index.htm the page comes up fine but
www.mycompany.com is their hacked page.
There is a mix of 2000 and 2003 boxes. ISA firewall and dns, dhcp etc etc....
We have looked at the dns and the www record points to our webhost. Tried dumping the cache. Even set up a pc with static address pointing to the ISP dns servers and no luck.
We have looked at the ISA box and even tried to forward the HTTP to the .index.htm to make it work... But no luck.
Anyone know if there is an AD policy that can be configured to force HTTP redirection?
Any ideas on solutions (even stupid ones) will help me with other things to look into.