Hacker replaces default page

Every few months a hacker replaces a home page on on of the sites on my server.
No other file damage.

It is a windows server with a Gnat box firewall in front.

How the heck is this done ,someone said they can get in on port 80.

Any ideas?

 

 

 

 

Top