Thanks for all the comments. I think I finally think I found the method used, if this helps anyone. Apparently one of my forum's was accessible for non registered, and an article that was created on the forum also had comments (replies) enabled. So the spammer took advantage of making a comment, that somehow even changed the forum title. HTML was allowed on the comment box. So it could be that these contributing factors led to how my site was infiltrated without a password being necessary.
Thanks
cammot
|