They didn't alter anything else because those scriptkiddies usually only do it to deface your site so they can brag about it to their other scripkiddy friends.
What I would do is change the passwords of all your stuff, just to be sure.
- Delete those suspicious files and re-upload the index.php file of vBulletin. (wso.php is a web-shell by the way, a backdoor. Delete that file asap)
- Be sure all of your plugins are up to date.
- Change the admincp folder to something else.
I can help you out in private if you need help, but of course understandable if you have some trust issues now.
|