We still get regular attempts at hacking here (I log every attempt at any non-standard URL accessed on this domain). So more than likely their entry point would be in the log file. I just wored on one yesterday that was believed to be a .threads exploit, since the config file was hacked, but it turned out to be a hole in another script entirely that they used to overwrite the threads config file.