check the append/prepend fields in rv_banners, rv_zones ... i'm still very curious on how they got access, since as far as i know there are no vulnerabilities for this version.
if you are unable to find out, could you please let me know? maybe i can take a look with you.
Login as system administrator
Go to http://rsv.londynek.net/rserver/www/admin/account-settings-user-interface.php
Tick
Force SSL Access on User Interface
Click save.
You need the same FQDN for all instances in the loadbalancer pool. data-revive-id is a hash of the hostname tags are served from, if it doesn't match, no data gets served.