I was going to post about a security issue I ran into but I figured it out, so hopefully this will help others.
This is a good reminder to all that sometimes hackers don't just attack the website framework and server, but they also leave open holes on the computer for third parties to manipulate. Lesson learned. Don't install upgrades or download software even if it's from a trusted source unless one knows exactly what is being installed (i.e. Adobe Flash update automatically installs McAfee, Nchsoftware Videopad installs NCH/Conduit toolbar).
Problem:
I recently put up my website a month ago. In this example I used Firefox to test my site. I noticed that my taxonomy path from my website points to a website (nchsoftware) that kind of looks like a search engine. The weird thing is that taxonomy/term/foo was fine.
See screenshot if you're interested: http://i.imgur.com/F6CCE.jpg
Security Steps:
1) I don't have redirects for that path anywhere in Drupal or on my server.
2) I have the Path Access module installed that only allows a few paths that does not include taxonomy, but somehow the taxonomy path still shows up and doesn't show access denied.
3) I have a robot.txt that doesn't allow search engines to look in certain areas.
4) I have a spam filter and blacklisted words.
5) My forms only allow plain text with limited HTML.
Solution Steps: