Mine got hacked too. I was using some recent version of Drupal (really just an experiment site, so I don't remember which version). I hadn't logged in for days/weeks/months/don't remember, so I highly doubt they'd intercepted a session. Sounds like they would be targetting heliohost.org?
I did set an image folder to 777. really not sure about cgi scripting so can't comment.