Don't know exactly, but many hours...
They are using an outdated nginx version with some known vulnerabilities.
We are using intermediary to be protected against DDOS. The "outdated nginx version" has no known security flaws we are aware of (in the configuration we have in use, e.g., we are not affected by the "heartbleed bug" that was discovered in later versions). If you know about any vulnerabilities we appreciate to hear from you. We are taking the security of our users very serious.
Cheers,
Marco