It's cause they're using PHP and not scuring it right. PHP is easy as hell to hack and inject code into
Its because vBulletin sucks and the same exact thing can happen here too (SRs forums run on the same system but I use vb4 and SR is using vb3). Its some SQL injection through vBulletin they obviously isn't patched and the group of people slamming TRW obviously have the URL on their hit list.
Im going to be looking into options other than fixing the current site like moving away from vbulletin to a different system or moving in with someone else...
edit:i ran the upgrade script which fixed it before but no dice.
editedit: my bad brock on making a new thread i forgot this was here.