now a bit more clear about your environment.
one more question: is this account belonging to this hacker ? so he can edit .htaccess file. yes, if someone can edit .htaccess, it's very difficult to prevent him to do anything bad further.
not clear about your environment.
what's the relationship between "they" and you.
just for an suggestion: you can set /usr/bin/perl 's permission to disable the ability of user running perl cgi script.
I tried to reproduce your issue on latest wp-3.3.2 + lsws 4.1.12 + php 5.2.11 at our lab, but failed. using "multi-file uploader".
can you suggest how to reproduce the issue quickly?