LOL, I'm certainly happy to see that everybody is so concerned about the Ruffdogs site.
The site was hacked through the sanitizer script inhereted from myPHPNuke. It was Social MPN (a web application) that got hacked, not the server that it's on. The server that it's on is not an SME box but a debian box running a modified version of DTC (
http://www.gplhost.com/?rub=softwares&sousrub=dtc) of which Ruffdogs has contributed a number of patches and code to.
So folks, it's the same old story with a PHP app, (if they try long enough they will find a way in) nothing more.
They got no further into the system than replacing the index.php page.
And BTW, the hacker has agreed to test our PHP based apps for us. What's the old saying, "keep your friends close and your enemies closer"?

And please remember, I am not aware of any CMS that has been around for any extended period of time, that hasn't been exploited in one manner or another. This was the first for Social MPN.
Garret