I was just contacted by someone I know who came to own a well visited site in the past few years. I was asked by him to do a little bit of work for him: to switch hosts and perform some minor updates to their existing site. No problem I thought. Well, I have since learned the cause for moving hosts. The site had been hacked over the holidays and now has a threat warning from Google. A backup has been restored by the host (which still includes some badware redirects) and there is no source control or revision history.
The site is very large and I am still trying to get organized. Media files, multiple copies of pages with php.bak etc everywhere, horrible horrible mess. He complained about their last 'webmaster' being a nut. Yeah... Can you guys please recommend site scanners or any tools you would use to find any threats on an unfamiliar code base? I am hooked up with Google Webmaster Tools which is alright but I have found threats on pages they don't have listed. Any tips would be very appreciated. Thanks