Site Hacked and Code Injection

I found my site hacked by the gaza-hacker, they have add their index pages but in the very root of the account not in the domain folder so it does not replaced my actual index.aspx file, that is why even though those files were added on 25 Dec 2011 i come to know today only.

Does any one had same issue? or its only me.

I also have issue of code injection in another two account which has added to the all the index page of all the sites in that account. This is already reported by one more user.

I am alone who knows all ftp password and i have no virus on my laptop, I did full scan using Microsoft Security Essential and AVG.

I have site with FCKeditor in all these affected account but there is no file-manager connectors available to support upload functionality.

How secure our servers are against such hacking attempts?

FCKeditor has vulnerability which can be exploited. Just google for ‘FCKeditor vulnerability’ and you will get loads of it

I found all of the ‘FCKeditor vulnerability’ are related to filemanager connectors and i don’t use it, it is not uploaded on server.

Also I checked ftp log and found that affected file (link to jumpcb.com added) is not changed from ftp, unless it is affected since long.