Interesting. Sounds like he is saying the script he used to exploit the site was already installed elsewhere on the server. Quite bummer.
For reference, I host with Hostgator (dedicated server) and after getting hacked a few times in the past (uploading the .txt shell script files) I had them install mod_security and use the same ruleset they use on their public hosting servers. So far I have not been exploited since.