Any idea of how a hacker manages to gain access to put malicious code in my header.tpl file?

I have taken out Front page extensions and changed the admin passwords but it still keeps happening.

Any ideas?


UBB user since 1998