The hack was the result of an known exploit in the message board software. I hadn't upgraded or patched the message board since I installed it 5 years ago. My fault. The hack was totally preventable but I didn't patch it because I had heavily modified it and felt everything would break if I upgraded to the latest version.
I've decided to do two things:
- Upgrade to the most recent release of the message board (version 3.0.0). It works exactly the same as the old version, but it has a few new features and is more secure.
- I'm going to try to prevent search engines from looking at the posts. From looking at the logs I can tell that the hacker first visited our site from a search engine. I really don't know why the message board needs to be visited by non-MTFFLers anyway.
I don't think member passwords were exposed but feel free to change yours. I've already changed all the system passwords just in case.