yeh...my little dating site got hacked couple of weeks back, i didnt bother reporting it, Had some typical hackers logo image like the one here etc, only mine had guns and blood...lol and middle eastern looking writing { im sure youre with me} now years ago I'd have just deleted my site asap, but as it was a amatuer installation I realised I 'might ' not be able to reinstall again, so I thought..... then noticed at bottom of page there was some error pointing to my config.php file...... so I downloaded the site quickly to my HD, antivirus went off on one saying PHP virus, so deleted that, then dleeted version on server,THEN reuploaded my original config.php and low and bwhold the site came back......Phew I was lucky but it'll certainly teach me NOT to leave permissions set wrongly again... its just so easy to get lazy and think ' oh yeah ill change them permissions back later' lol.... too late...... could they have been using some kinda php injection thing ? like maybe even just typing in a naughty URL that had the right syntax to allow stuff to happen ? or is it far simpler or more complex ? anyone got any ideas ? {god this speed works.....lol}