yea FLG. Also many people don't know what to do when he's got in. As people make the same mistakes.
So to kick him out of your server.
1.Change all FTP, cPanel passes (doesn't normally get those but still)
2.Backup your MySQL Database then make a new user use a diff pass and make a new database using a different name and import your database to that.
3.Change your file settings to it goes to your new database.
4.(For Forums) Check the last line of all vbulletin files. If it starts like this <? after a ?> (meaning his inserted another code) it's a webshell. Reup all vbulletin files.
For more info on step 4. See what he added to TiendaDDL:
http://clairvoyantcss.info/wazowned/Waz-Host-Owned.html
It's a webshell.
5.Don't reuse your pass.
6.If your index says Hacked By Boxhead even after you reupped your files. Go to
http://ur-website.com/admincp and login, navigate to any templates it says u recently edited when u didn't, revert them back as he removes all the original code and put's hacked by boxhead.
7.Tell all Admins to change their passes.
8.Change email passes aswell as he sometimes get's into them if they're the same pass as your forum admin account pass (see step 5)
9.use cPanel's "Password protect directories" to password protect your admincp, just for added security.
(Do Not Put The Login The Same As your or any admins Forum Account username/pass, Do NOT Even Put The Username The Same)
10. Another Good Tip Is To Use .htaccess To Only Allow Certain Ip's To Access your admincp. e.g All The Admins. Same With ModCP so nobody can hack a mod's account and prune all posts.
Then he should be out of your server
