First of all, Ultimare was also hit twice. Luckily I knew what to do and when to do it. Before I go into detail I would like to stat that I personaly do not believe Pandora had anything to do with it cause I have also talked to some Pandora staff. I believe they are being framed.
The hacker would use SQL injections on SQL port to gain access via existing GM's. They would make mass spawn, post notices (claiming to be "Lizzy"), and summon people to other factions.
The hacker made a mistake tho, he failed to disconnect from SQL port. As I do not allow remote assistance and server/SQL files are on same machine, this was easy to spot. Here is info on the wannabe hacker. Have fun.
nestat details..
58.240.220.91 was connected on 1433 with 13 process's.
58.240.220.91 details..
58.240.220.91 Whois Information
% [whois.apnic.net[Who Is Domain][trace][Reverse DNS Search] node-3]
% Whois data copyright terms

[Who Is Domain][trace][Reverse DNS Search]/db/dbcopyright.html
inetnum: 58.240.0.0[Who Is IP][trace][Reverse IP Search] - 58.241.255.255[Who Is IP][trace][Reverse IP Search]
netname: UNICOM-JS
descr: China Unicom Jiangsu province network
descr: China Unicom
country: CN
admin-c: CH1302-AP
tech-c: LL58-AP
remarks: -+-+-+-+-+-+-+-+-+-+-+-++-+-+-+-+-+-+-+-+-+-+-+-+-+-+
remarks: This object can only be updated by APNIC hostmasters.
remarks: To update this object, please contact APNIC
remarks: hostmasters and include your organisation's account
remarks: name in the subject line.
remarks: -+-+-+-+-+-+-+-+-+-+-+-++-+-+-+-+-+-+-+-+-+-+-+-+-+-+
mnt-by: APNIC-HM
mnt-lower: MAINT-CNCGROUP
mnt-lower: MAINT-CNCGROUP-JS
mnt-routes: MAINT-CNCGROUP-RR
status: ALLOCATED PORTABLE
changed: [Who Is Domain][trace][Reverse DNS Search] 20050603
changed: [Who Is Domain][trace][Reverse DNS Search] 20050621
changed: [Who Is Domain][trace][Reverse DNS Search] 20090508
source: APNIC
route: 58.240.0.0[Who Is IP][trace][Reverse IP Search]/15
descr: CNC Group Jiangsu province network
country: CN
origin: AS4837
mnt-by: MAINT-CNCGROUP-RR
changed: [Who Is Domain][trace][Reverse DNS Search] 20050603
changed: [Who Is Domain][trace][Reverse DNS Search] 20050622
source: APNIC
person: ChinaUnicom Hostmaster
nic-hdl: CH1302-AP
e-mail: [Who Is Domain][trace][Reverse DNS Search]
address: No.21,Jin-Rong Street
address: Beijing,100140
address: P.R.China
phone: +86-10-66259940
fax-no: +86-10-66259764
country: CN
changed: [Who Is Domain][trace][Reverse DNS Search] 20090408
mnt-by: MAINT-CNCGROUP
source: APNIC
person: Lan Li
nic-hdl: LL58-AP
e-mail: [Who Is Domain][trace][Reverse DNS Search]
address: No. 65 Beijing West Road,Nanjing,China
phone: +86257900060
fax-no: +86252900280
country: CN
changed: [Who Is Domain][trace][Reverse DNS Search] 20031117
mnt-by: MAINT-NEW
source: APNIC
-------------------
Hostname: 58.240.220.91
ISP: China Unicom Jiangsu province network
Organization: China Unicom Jiangsu province network
Proxy: None detected
Type: Broadband
Assignment: Static IP
Blacklist:
Geolocation Information
Country: China
State/Region: Jiangsu
City: Nanjing
Latitude: 32.0617
Longitude: 118.7778
--------------------------
Since I blocked the entire IP block I havnt had an issue.
Good Luck feelow Pservers
~Phish