1). Set yourself as the only administrator, don't promote any other user for the time being.
2). In config.php, insert your userid in the area to limit the editing of users. This way, if it is something gaining access via the admin cp, they at least will not be able to edit your admin account.
3). Make sure the tools.php folder isn't accessable or uploaded.
4). Rename your admincp and modcp folders and then .htaccess them for an extra layer of protection.
The above should stop anyone gaining access via software, however, if they still get through the above, chances are there's a security breach somewhere along your server and you would need to contact your host and have them check the logs and such.
|