Agreed about the sidebar issue - but it's not my site, I'm just helping them with it, and the whole site desperately needs an update.
As for the hacking - looks like they simply added a HTML file to the server, so will chase this up with the webhost.