Have you talked to your host about this at all? Perhaps it is a problem with their security, not yours. I just reread this thread and I don't think you ever said whether you looked through your access_logs. You asked where they were, which leads me to think No and also makes me think that you may need some help from your host in finding out how these guys are getting into your files.
|