And be sure to use a good host. Not some kid or man who started a hosting company without any experience.
If the hacker keeps coming back, even when you change the admincp directoryname, they can read your config file. Some hosts have not provided decent protection on their servers, and if you know the location of the config file (which is always in /forums/includes with vBulletin) you can read it out via ssh or via a self made php file.
All the hacker needs is an account on the same server.
|