I don't know either, that's kind of fucked up.
You didn't ask anything illegal, you just didn't ask the question in very good English.
To answer, I think logs would be your best bet.
You have to find out how they got in, was it sql injection? Did they already have a password? Did they social engineer an administrator?
Logs will be your friend, if they haven't deleted them.
There should be logs for alot of aspects to the website including the admin panel.
Using the process of reduction you can find the suspicious log entries.
The hacker may have used anonymizing proxies or something similar but it is worth a try.
Also you may want to delete everything and start fresh because they will have put additional backdoors everywhere.
good luck.