This sort of thing happens quite frequently. Generally a hacker will use an open port of the server to gain access to the webserver, mostly to introduce a little application that will overwrite all the html index pages with their tags.
To prevent this happening, you have to make sure your server is up to date with all the software patches from the supplier and operating system developers.
You can run anti intrusion software which will monitor port activity and notify you if any attack is taking place.