Hello,
Since config.inc.php permissions is required  to be 0666, the hacker was able to inject an iframe hack into it, infecting the rest of my files.
When I set the permission to 644, my site is safe from any attacks but then I can't use the script. What is the solution for this?
Thank you all, please help me