Did you remember to change your passwords to both the server and the bbs after the rollback?
If they're changing the unmodifiable users list, it sounds like they hacked into the server, not just the BBS, at which point they could manually hack the config file where you set the umodifiable users.
You may wish to ask your hosting provider to check the server for exploit code as well.
If that config file is set to mod 777, ( -rwxrwxrwx), you probably should log into a terminal to the server, and chmod the file to 555 (-r-xr-xr-x).
|