It's hard to know how someone gained access to your server without having access to your vBulletin forum/logs.
Anything is possible such as: shared webhost breach, insecure vBulletin plugins, bad vBulletin configuration, other vulnerable software hosted on the server, etc.
You could start out by posting all of your plugins here.
i contact my server, don`t have any log hack .. they said hack from script, not from sever attack
this my plugin
Adam's Subscribed Thread Notifications
Advanced Application Forms (INACTIVE)
BT - Social Group Message Quote
Change Posts Owner
Chip2love.9xpro - Limit new thread/post per day
First Post on all pages (INACTIVE)
Forum Category Icons (Advanced)
Forum Runner (INACTIVE)
GeekyDesigns Default Avatar
Global Threads: The Next Generation FREE by BOP5
GlowHost - Spam-O-Matic
Helpful Answers (INACTIVE)
iTrader (INACTIVE)
Limit Posts Per Day in Threads by BOP5
Make Prefixes Clickable to Filter Forumdisplay
Mark Thread As 'Sold'
Minimum Post Count Required To Post Blog Entries
Mod-Mall BB Code Spoiler
More Share Options for VB4 by BOP5 Light (INACTIVE)
Nested Quotes
Advanced User Tagging (DBTech)
DBSeo (DBTech) (INACTIVE)
Panjo (INACTIVE)
PB Usergroup Choice on Registration (INACTIVE)
Ajax Point System
PostRelease (INACTIVE)
ProvB - Extra Threadfields
Rotating Banner System
Skimlinks Plugin (INACTIVE)
Subscription Notification System
Tapatalk (INACTIVE)
Thread Participants - by rellect
Threads Started by User in Postbit & Profile
User Article Count (INACTIVE)
Usergroup Allow HTML
vBadvanced CMPS
vBulletin Blog (INACTIVE)
vBulletin CMS (INACTIVE)
vFcoders - Ajax First Post Collapsable Hack (INACTIVE)
View your Threads or Posts from the Navbar
VSa - Sub-Forum Manager (INACTIVE)
WS vBulletin Tweet Poster
XenForo Style Avatars
[OzzModz] Exclude Forums From Activity Stream (INACTIVE)