Someone phished my site by uploading westpac.co.nz.zip to the admin/backup directory. I am not sure how that was done as the host told me this was not done via FTP. What areas do I need to plug in order to prevent this from happening again? Please help ASAP.