That's what scares me about the attack/hack/etc -- when I went into the Edit Options in the control panel, me changing the paypal address back to what it should be was logged in the Control Panel Log. There's no log of it being changed the first time which makes me think it's either a PHP or SQL injection that it completely bypassed the Admin CP. Either that or whoever edited the options somehow knew how to remove ONLY that entry from the log since the rest of the log is intact.
|