It's tough to tell how they are doing it.
If you changed your password, then they probably aren't guessing it. They could just be getting access to your database. Do you have an insecure version of phpmyadmin installed, one with out a password? (if it has a password, change it)
List off what hacks you have installed, one may be vulnerable.
Last case would be to look through your Apache access logs, it's a pain, but it'll let you know what IP has been accessing certain admin only files.
-Modin
|