I figured out what it was. Apparently I didnt realize that AWStats was that exploitable. AWStats has some loop holes that allow the person to get in via SSH. Thus I have removed it. I have been planning a server move for quite a while, so as soon as thats done we should be set.
So basically the fruitcake that got in, lacks any real skill, just the ability to follow some instructions to get into SSH where they opened the file and edited to say that crap it did.
The router maintains a log of transmissions so when I get a chance to go through I will be having a field day
Thanks for your concern,
Nik
P.S once that server change is done... expect some goodness
http://img522.imageshack.us/img522/8907/monkeymaximus2ph.jpg


