This man speaks troofs. You guys would be blown away at how many SSH/FTP/etc login failures the servers a
day.
Regardless, this "hack" (actually a ****ty script kiddie) was a drive by attack on vb, nothing deeper. VB didn't update like I thought it did, we were one version behind, they exploited.
How did they find us, you ask?
Well, take a look at:
http://www.bing.com/search?q=Powered+by+vBulletin+4.2.0+atheist+forum&go=&qs=n&pq=powered+by+vbulletin+4.2.0+atheist+forum&sc=0-0&sp=-1&sk=&cvid=64443d4496434b2d80a5937bdd016753&first=29&FORM=PERE1
Notice a result on that page? Yep. That's right. Because of that thread.
Anyway, it's resolved. I didn't see much evidence of the guy doing anything else other than ****ing with the forum a bit (he used a PHP shell after gaining admin access to the forum via the exploit). He didn't have access to anything else. To be safe I banned his admin account, banned his IP globally, wiped the forum directory completely and restored from backup, and updated vB manually. I also removed the version number from the footer, because **** vB. There's no reason for that **** to be public knowledge anyway.