The security team at my ISP (dreamhost) found yet more infection in my blog. The appearance of a wordpress blog can vary by installing different themes. In the directory of one of these themes they found a file containing tool for giving a remote user a shell prompt (there is a version of the script here). The theme in question is not a standard wordpress theme; it is a variant I wrote up a while back. I used it for a while a long time ago. Which means the URL to access this was obscure.
…php
…php?d=/home/<myusername>/enthusiasm.cozy.org/
…php?d=/home/<myusername>/enthusiasm.cozy.org/&ef=wp-settings.php&edit=1
…php?d=/home/<myusername>/enthusiasm.cozy.org/&ef=wp-settings.php&edit=1
…php?d=/home/<myusername>/enthusiasm.cozy.org/&e=wp-settings.php
…php?d=/home/<myusername>/
…php?d=/home/