<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Trojan on this website</title>
	<atom:link href="http://photocritic.org/wordpress-exploit-iframe-gen-c/feed/" rel="self" type="application/rss+xml" />
	<link>http://photocritic.org/wordpress-exploit-iframe-gen-c/</link>
	<description>The Photocritic DIY photography projects blog</description>
	<lastBuildDate>Sun, 14 Mar 2010 20:05:03 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: site fr</title>
		<link>http://photocritic.org/wordpress-exploit-iframe-gen-c/#comment-314728</link>
		<dc:creator>site fr</dc:creator>
		<pubDate>Sun, 24 Jan 2010 16:25:15 +0000</pubDate>
		<guid isPermaLink="false">http://photocritic.org/?p=1482#comment-314728</guid>
		<description>Toujours de tres bonne info , merci</description>
		<content:encoded><![CDATA[<p>Toujours de tres bonne info , merci</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jeremy</title>
		<link>http://photocritic.org/wordpress-exploit-iframe-gen-c/#comment-296921</link>
		<dc:creator>jeremy</dc:creator>
		<pubDate>Tue, 17 Feb 2009 05:48:41 +0000</pubDate>
		<guid isPermaLink="false">http://photocritic.org/?p=1482#comment-296921</guid>
		<description>Another reason to read by rss, I guess.  Best of luck getting it all worked out, but don&#039;t hold off on new posts too much.  The last one on breaking photographers block was fantastic.</description>
		<content:encoded><![CDATA[<p>Another reason to read by rss, I guess.  Best of luck getting it all worked out, but don&#8217;t hold off on new posts too much.  The last one on breaking photographers block was fantastic.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lee Hampton-Whitehead</title>
		<link>http://photocritic.org/wordpress-exploit-iframe-gen-c/#comment-296636</link>
		<dc:creator>Lee Hampton-Whitehead</dc:creator>
		<pubDate>Tue, 10 Feb 2009 19:06:45 +0000</pubDate>
		<guid isPermaLink="false">http://photocritic.org/?p=1482#comment-296636</guid>
		<description>i am not convinced this is related to the XSS pre 2.6.5

http://wordpress.org/development/2008/11/wordpress-265/ says 

&quot;only affects IP-based virtual servers running on Apache 2.x.&quot;

and (in my opinion) does not seem to allow code to be written back to the web server

my setup is name-based-virtual hosted 2.7 and it still got in !!</description>
		<content:encoded><![CDATA[<p>i am not convinced this is related to the XSS pre 2.6.5</p>
<p><a href="http://wordpress.org/development/2008/11/wordpress-265/" rel="nofollow">http://wordpress.org/development/2008/11/wordpress-265/</a> says </p>
<p>&#8220;only affects IP-based virtual servers running on Apache 2.x.&#8221;</p>
<p>and (in my opinion) does not seem to allow code to be written back to the web server</p>
<p>my setup is name-based-virtual hosted 2.7 and it still got in !!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Donncha O Caoimh</title>
		<link>http://photocritic.org/wordpress-exploit-iframe-gen-c/#comment-296634</link>
		<dc:creator>Donncha O Caoimh</dc:creator>
		<pubDate>Tue, 10 Feb 2009 18:46:09 +0000</pubDate>
		<guid isPermaLink="false">http://photocritic.org/?p=1482#comment-296634</guid>
		<description>Glad you got your site fixed.

WP-Super-Cache allowed a different bug to happen, but so would any other caching plugin. Security Focus mentioned that plugin because it&#039;s the most used..

Can you email security@wordpress.org with everything you&#039;ve found? I have a feeling it&#039;s an old bug though.</description>
		<content:encoded><![CDATA[<p>Glad you got your site fixed.</p>
<p>WP-Super-Cache allowed a different bug to happen, but so would any other caching plugin. Security Focus mentioned that plugin because it&#8217;s the most used..</p>
<p>Can you email <a href="mailto:security@wordpress.org">security@wordpress.org</a> with everything you&#8217;ve found? I have a feeling it&#8217;s an old bug though.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lee Hampton-Whitehead</title>
		<link>http://photocritic.org/wordpress-exploit-iframe-gen-c/#comment-296633</link>
		<dc:creator>Lee Hampton-Whitehead</dc:creator>
		<pubDate>Tue, 10 Feb 2009 18:14:12 +0000</pubDate>
		<guid isPermaLink="false">http://photocritic.org/?p=1482#comment-296633</guid>
		<description>My wife&#039;s site (wordpress as a CMS) is a self hosted wordpress 2.7 on an easyspace Virtual private server, where i control the security, and left the themes folder writable to apache after tweaking her latest theme of choice</description>
		<content:encoded><![CDATA[<p>My wife&#8217;s site (wordpress as a CMS) is a self hosted wordpress 2.7 on an easyspace Virtual private server, where i control the security, and left the themes folder writable to apache after tweaking her latest theme of choice</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Duncan</title>
		<link>http://photocritic.org/wordpress-exploit-iframe-gen-c/#comment-296632</link>
		<dc:creator>Duncan</dc:creator>
		<pubDate>Tue, 10 Feb 2009 18:09:53 +0000</pubDate>
		<guid isPermaLink="false">http://photocritic.org/?p=1482#comment-296632</guid>
		<description>I was looking into a WP hack for a friend and this whitepaper was very helpful:

http://blogsecurity.net/wordpress/wordpress-security-whitepaper/

I&#039;ve seen two classes of WP hacks:
•Something getting inserted into the page template. I think that WP stores each theme separately, so you might be able to restore back to a known-good copy of your theme if you&#039;ve got extra stuff inserted.

•Alternatively, I&#039;ve seen a tiny iframe added to one or more posts, generally linking to a malicious site. This is easier to fix; just search for an iframe tag on each post and if you see one that shouldn&#039;t be there, nuke it.</description>
		<content:encoded><![CDATA[<p>I was looking into a WP hack for a friend and this whitepaper was very helpful:</p>
<p><a href="http://blogsecurity.net/wordpress/wordpress-security-whitepaper/" rel="nofollow">http://blogsecurity.net/wordpress/wordpress-security-whitepaper/</a></p>
<p>I&#8217;ve seen two classes of WP hacks:<br />
•Something getting inserted into the page template. I think that WP stores each theme separately, so you might be able to restore back to a known-good copy of your theme if you&#8217;ve got extra stuff inserted.</p>
<p>•Alternatively, I&#8217;ve seen a tiny iframe added to one or more posts, generally linking to a malicious site. This is easier to fix; just search for an iframe tag on each post and if you see one that shouldn&#8217;t be there, nuke it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Black</title>
		<link>http://photocritic.org/wordpress-exploit-iframe-gen-c/#comment-296630</link>
		<dc:creator>Chris Black</dc:creator>
		<pubDate>Tue, 10 Feb 2009 17:01:55 +0000</pubDate>
		<guid isPermaLink="false">http://photocritic.org/?p=1482#comment-296630</guid>
		<description>Lee: is your wife&#039;s website hosted by 1&amp;1 (mine is)

Haje: only plugin which we have in common is akismet</description>
		<content:encoded><![CDATA[<p>Lee: is your wife&#8217;s website hosted by 1&amp;1 (mine is)</p>
<p>Haje: only plugin which we have in common is akismet</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lee Hampton-Whitehead</title>
		<link>http://photocritic.org/wordpress-exploit-iframe-gen-c/#comment-296625</link>
		<dc:creator>Lee Hampton-Whitehead</dc:creator>
		<pubDate>Tue, 10 Feb 2009 16:23:51 +0000</pubDate>
		<guid isPermaLink="false">http://photocritic.org/?p=1482#comment-296625</guid>
		<description>in case it is of any use

the httpd log from the time of the hack

87.118.120.36 - - [10/Feb/2009:02:05:43 +0000] &quot;POST /wp-atom.php HTTP/1.1&quot; 200 32 &quot;-&quot; 
87.118.120.36 - - [10/Feb/2009:02:05:43 +0000] &quot;POST /wp-atom.php HTTP/1.1&quot; 200 - &quot;-&quot; 

ip is in germany</description>
		<content:encoded><![CDATA[<p>in case it is of any use</p>
<p>the httpd log from the time of the hack</p>
<p>87.118.120.36 &#8211; - [10/Feb/2009:02:05:43 +0000] &#8220;POST /wp-atom.php HTTP/1.1&#8243; 200 32 &#8220;-&#8221;<br />
87.118.120.36 &#8211; - [10/Feb/2009:02:05:43 +0000] &#8220;POST /wp-atom.php HTTP/1.1&#8243; 200 &#8211; &#8220;-&#8221; </p>
<p>ip is in germany</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Black</title>
		<link>http://photocritic.org/wordpress-exploit-iframe-gen-c/#comment-296624</link>
		<dc:creator>Chris Black</dc:creator>
		<pubDate>Tue, 10 Feb 2009 16:23:18 +0000</pubDate>
		<guid isPermaLink="false">http://photocritic.org/?p=1482#comment-296624</guid>
		<description>Hi same thing has just happened with my site - I googled Exploit-IFrame.gen.c and found you.

Hopefully I can follow what you did and deal with this...</description>
		<content:encoded><![CDATA[<p>Hi same thing has just happened with my site &#8211; I googled Exploit-IFrame.gen.c and found you.</p>
<p>Hopefully I can follow what you did and deal with this&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lee Hampton-Whitehead</title>
		<link>http://photocritic.org/wordpress-exploit-iframe-gen-c/#comment-296623</link>
		<dc:creator>Lee Hampton-Whitehead</dc:creator>
		<pubDate>Tue, 10 Feb 2009 16:17:31 +0000</pubDate>
		<guid isPermaLink="false">http://photocritic.org/?p=1482#comment-296623</guid>
		<description>interesting post
today (10th feb) at 0205 UK time, my wife wordpress site got hacked too.

same snippet of code placed in every header.php file underneath the themes folder

nothing obvious in httpd logs, i am very confused</description>
		<content:encoded><![CDATA[<p>interesting post<br />
today (10th feb) at 0205 UK time, my wife wordpress site got hacked too.</p>
<p>same snippet of code placed in every header.php file underneath the themes folder</p>
<p>nothing obvious in httpd logs, i am very confused</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Haje Jan Kamps</title>
		<link>http://photocritic.org/wordpress-exploit-iframe-gen-c/#comment-296610</link>
		<dc:creator>Haje Jan Kamps</dc:creator>
		<pubDate>Tue, 10 Feb 2009 11:39:06 +0000</pubDate>
		<guid isPermaLink="false">http://photocritic.org/?p=1482#comment-296610</guid>
		<description>Flo: Yeah, that&#039;s what I&#039;m afraid of too, but I do trust most of the plug-ins quite well, and they are all (with two notable exceptions, which I&#039;ll fix tonight) completely up to date. 

I&#039;ve had issues with odd things showing up on my blog before, but all rootkit checking in the world doesn&#039;t indicate that the server itself is compromised - and the passwords are as hardened as I can make them with paranoia levels turned to 11 (passwords are many digits, completely random, with upper and lower, numerals and obscure punctuation symbols), no FTP access, each site on the server lives in its own silo, etc. 

Apart from my octal n00b mistake, I am genuinely surprised how the site still ended up hacked - I&#039;ve genuinely done everything in my power to keep it completely safe... I guess I&#039;ll just have to start doing more.</description>
		<content:encoded><![CDATA[<p>Flo: Yeah, that&#8217;s what I&#8217;m afraid of too, but I do trust most of the plug-ins quite well, and they are all (with two notable exceptions, which I&#8217;ll fix tonight) completely up to date. </p>
<p>I&#8217;ve had issues with odd things showing up on my blog before, but all rootkit checking in the world doesn&#8217;t indicate that the server itself is compromised &#8211; and the passwords are as hardened as I can make them with paranoia levels turned to 11 (passwords are many digits, completely random, with upper and lower, numerals and obscure punctuation symbols), no FTP access, each site on the server lives in its own silo, etc. </p>
<p>Apart from my octal n00b mistake, I am genuinely surprised how the site still ended up hacked &#8211; I&#8217;ve genuinely done everything in my power to keep it completely safe&#8230; I guess I&#8217;ll just have to start doing more.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Flo</title>
		<link>http://photocritic.org/wordpress-exploit-iframe-gen-c/#comment-296609</link>
		<dc:creator>Flo</dc:creator>
		<pubDate>Tue, 10 Feb 2009 11:31:08 +0000</pubDate>
		<guid isPermaLink="false">http://photocritic.org/?p=1482#comment-296609</guid>
		<description>This does not necessarily have to be connected to file permissions or your webmaster. There are tons of ways how wordpress can become vulnerable. For example, there are quite a few plugins which can be a security risk, so you should keep those up to date as well.</description>
		<content:encoded><![CDATA[<p>This does not necessarily have to be connected to file permissions or your webmaster. There are tons of ways how wordpress can become vulnerable. For example, there are quite a few plugins which can be a security risk, so you should keep those up to date as well.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Haje Jan Kamps</title>
		<link>http://photocritic.org/wordpress-exploit-iframe-gen-c/#comment-296608</link>
		<dc:creator>Haje Jan Kamps</dc:creator>
		<pubDate>Tue, 10 Feb 2009 11:16:18 +0000</pubDate>
		<guid isPermaLink="false">http://photocritic.org/?p=1482#comment-296608</guid>
		<description>patpro: Jeez, can you tell I typed this up in a rush? 

I obviously ought to have my have my webmaster pass revoked on a permanent basis...</description>
		<content:encoded><![CDATA[<p>patpro: Jeez, can you tell I typed this up in a rush? </p>
<p>I obviously ought to have my have my webmaster pass revoked on a permanent basis&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: patpro</title>
		<link>http://photocritic.org/wordpress-exploit-iframe-gen-c/#comment-296607</link>
		<dc:creator>patpro</dc:creator>
		<pubDate>Tue, 10 Feb 2009 11:06:27 +0000</pubDate>
		<guid isPermaLink="false">http://photocritic.org/?p=1482#comment-296607</guid>
		<description>You might want to replace &quot;octagonal&quot; by &quot;octal&quot; ;)</description>
		<content:encoded><![CDATA[<p>You might want to replace &#8220;octagonal&#8221; by &#8220;octal&#8221; ;)</p>
]]></content:encoded>
	</item>
</channel>
</rss>
