Please, please, please stop recommending me on what to do, I'm not incompetent at what I do, I appreciate your comments but saying "Prob should have made sure this wouldn't happen" doesn't help. I think it is very clear to most people that obviously I did make sure I put all the anti-hack, anti-exploit, anti-ddos etc software on the server when I was setting it up, I'm not incompetent at this, the fact that Sony's website was being DDoS'd a few months back and that their whole entire network was down for weeks proves that this isn't an easy task to stop.
If you don't understand what is happening, please don't comment on the situation, I am gaining very tired and do not wish to explain every detail of what I am doing to prevent this attack, obviously if I explain too much the DDoSer could see what I have done and find a work around.
To everyone who wants refunds, you'll be refunded, you just need to wait.