I'm very new to using SSH and my server has been hacked, someone has gone onto a website of mine and made modifications. I have the time which they did it (29/07/2013 18:14:30), but cannot see how they go into the website.
I have tried tail /var/log/messages and tail /var/log/secure but cannot see any activity at this time.
I just want to know if they came via control panel/ssh/ftp so that I can change the passwords and perhaps ports to stop them.
Any help is greatly appreciated.
Thank you