well it depends on what kind of backdoor access he had..it was probably more than just your account/password. it was probably administrative user.
you should contact your hosting provider and discuss it with them. or if you don't feel secure them perhaps you should look for another provider.
__________________
[Sig removed by Administrator: Signature can not exceed 20GB]
|