There is several ways a account can be hacked, If it's web air then other accounts would be hacked and the server would be taken offline. Once a server is hacked from root it's toast.
They couldn't risk running it if it was the server.
Most likly some php somewhere on your site, maybe even with your pasword.
I would love to tell you otherwise and to switch over to us but php is a hackers playground and has to be carefully watched.
On the other hand there is additional security to detour hackers like removing telnet and trace route whois details. Makeing apache look like it's not running from a basic ping and ect.. brute force protection might help too..
|