To prevent idiots hacking your site, password protect your vbulletin admin area folder (admincp), google: password protect folder
They probably can go thru somehow normally, but they cant when you set additional non sql based (.htaccess .htpasswd based) password protection. I would also change hosting password + disvover latelly added/modiffied files if there are no bad files. There are also several other webpages showing tutorials on how to get rid of this hack. good luck
|