A client's (state university) site (large site) has been hacked. I didn't discover the hack on the site, but actually on twitter. There are links on twitter to the client's domain but it references being able to download free software etc. So I investigated the entire site for any files that had been modified, looked for the hacked pages by the url, checked the config file, the http files etc. Nothing I can find has been changed. The URL isn't even located within the site, which is what puzzels me. The root URL is in fact correct but the rest of it is not right. The site is Joomla so the url lists the article id or content id etc, and the numbers in the url don't correspond to anything.
I'm trying to figure out if the hacker has cloaked the domain or something like that to make it appear like it's our site. I hate to post the link here because I don't want to give the hacker more traffic. But I can PM the info.
Thanks for your help! I'm pulling my hair out!