>>6139i honestly have no idea
the hacker claims he had multiple undisclosed exploits but he might've been just talking out of his ass and it was just this and he somehow gotten cookies from a mod account, he does seem he had access to modify other accounts
fact of the matter it was used and it seems it allowed a great deal of control over the instance, this is where i found about it:
soyjakwiki.org/Vichan_crisis
>Probably not that big of a deal, although whitelisted /inc/mod* would probably be good security, also inconvenient for me though.well do whatever you feel would be best, wouldn't the easiest way be to just password protect the path in apache?