Fascinating. Looking for a hackable system and finding someone beat you to it.

The author and Facebook, Inc are lucky that the earlier hacker was just a regular spam criminal, not some bigtime "Nation-State Hacker". The Nation-State Hacker probably would have been a great deal more careful and not left easy-to-spot PHP backdoors lying around.

This also points out a weak area in our knowledge of hacking - how often does a given exploit get rediscovered? This and other anecdotes show that it happens at least once in a while. Prevalence of rediscovery could put lie to the NSA's "NOBUS" assumption, though. So we're likely to never see the results of such research.

