My site (
supermensa.org) is being hacked with the hackers gaining access to admin and presumably the sql database. The first hack was, I assume since they have a walkthrough on their site on how to do it, due to the /install/ folder exploit. I've since upgraded to 4.2.1 and deleted /install/, and they still came back and nuked the place. (changing my admin email and altering the visual appearance of the site to give the generic "you've been hacked lulz" message.
I have it set in config that my admin account cannot be altered, yet things like email get changed when they strike.
any ideas? anything someone can see that's open on my site? should i leave hooks/plugins off for the time being?