The reason i stated you didnt need to restore from a back up is that you could of just removed the code they injected, which was likely a base64 code into a template, most likely spacer_open.
As stated, you haven't plugged the hole and your not going to stop him from revisiting your forum doing a IP block or symlinking your config file.
Unless you know for sure that everything on your site/server is secure, your at risk
@Carlito, excellent point on the WP, thats why i told him everything needs to be upgraded.
|