<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: WordPress Exploited &#8211; 2.8.4 Release</title>
	<atom:link href="http://www.centernetworks.com/wordpress-exploited-284-release/feed" rel="self" type="application/rss+xml" />
	<link>http://www.centernetworks.com/wordpress-exploited-284-release</link>
	<description>Web 2 and Social Media News and Reviews</description>
	<lastBuildDate>Sun, 12 Feb 2012 21:27:36 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<item>
		<title>By: lauren</title>
		<link>http://www.centernetworks.com/wordpress-exploited-284-release#comment-165680</link>
		<dc:creator>lauren</dc:creator>
		<pubDate>Wed, 24 Feb 2010 17:57:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.centernetworks.com/?p=16544#comment-165680</guid>
		<description>i was also hacked on a number of WP sites while using Rackspace. 
Most recently, my master acct was hacked and an entire domain name and its hosted contents removed. after they told me it was my fault, and maybe the client changed it to be hosted elsewhere, they said, essentially, tough sh*t someone must have hacked it on your end. Right. at 3am on a weekday someone broke into my house logged into my account and deleted one website and all its files.

i better get a better door lock.</description>
		<content:encoded><![CDATA[<p>i was also hacked on a number of WP sites while using Rackspace.<br />
Most recently, my master acct was hacked and an entire domain name and its hosted contents removed. after they told me it was my fault, and maybe the client changed it to be hosted elsewhere, they said, essentially, tough sh*t someone must have hacked it on your end. Right. at 3am on a weekday someone broke into my house logged into my account and deleted one website and all its files.</p>
<p>i better get a better door lock.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Angela</title>
		<link>http://www.centernetworks.com/wordpress-exploited-284-release#comment-147405</link>
		<dc:creator>Angela</dc:creator>
		<pubDate>Mon, 18 Jan 2010 06:58:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.centernetworks.com/?p=16544#comment-147405</guid>
		<description>Just had a 2.8.4 site hacked. Yes, I know I should have at least been up to 2.8.6, but I just missed that update when 2.9 came out and some of our plugins wouldn&#039;t work. The site is hosted on Network Solutions and apparently several sites were hacked this weekend on their servers. I still don&#039;t know how they got in. They placed index.php.BAD files in various directories. 

I was surprised because we had taken every security measure prior to this attack (with the exception of removing the generator tag -- oops! -- meant to do that but forgot on one of the templates). We had renamed the table prefix, had limit login attempts and the SEO WP Firewall plugins installed, were using limited plugins, did not use admin for username and had very strong passwords. 

I&#039;m reading these comments to see what I can do to scan to find out what caused the hack. Of course, Network Solutions was completely unresponsive and unavailable by phone, so it&#039;s quite frustrating to watch hour by hour a hacker logged into your site and changing files (even after we changed all the passwords AGAIN and updated to 2.9.1). At one point, I changed the permissions on the themes folder, and the hacker promptly responded by deleting all my theme&#039;s files. He was definitely watching my every move and responding in kind to my various attempts to block -- in a personal not robotic way. Very creepy and annoying since I couldn&#039;t get through to Network Solutions after being on hold for more than 30 minutes with no sense of a queue and just repetitive playing of Pachelbel&#039;s Canon. I think they do that to encourage you to hang up.</description>
		<content:encoded><![CDATA[<p>Just had a 2.8.4 site hacked. Yes, I know I should have at least been up to 2.8.6, but I just missed that update when 2.9 came out and some of our plugins wouldn&#8217;t work. The site is hosted on Network Solutions and apparently several sites were hacked this weekend on their servers. I still don&#8217;t know how they got in. They placed index.php.BAD files in various directories. </p>
<p>I was surprised because we had taken every security measure prior to this attack (with the exception of removing the generator tag &#8212; oops! &#8212; meant to do that but forgot on one of the templates). We had renamed the table prefix, had limit login attempts and the SEO WP Firewall plugins installed, were using limited plugins, did not use admin for username and had very strong passwords. </p>
<p>I&#8217;m reading these comments to see what I can do to scan to find out what caused the hack. Of course, Network Solutions was completely unresponsive and unavailable by phone, so it&#8217;s quite frustrating to watch hour by hour a hacker logged into your site and changing files (even after we changed all the passwords AGAIN and updated to 2.9.1). At one point, I changed the permissions on the themes folder, and the hacker promptly responded by deleting all my theme&#8217;s files. He was definitely watching my every move and responding in kind to my various attempts to block &#8212; in a personal not robotic way. Very creepy and annoying since I couldn&#8217;t get through to Network Solutions after being on hold for more than 30 minutes with no sense of a queue and just repetitive playing of Pachelbel&#8217;s Canon. I think they do that to encourage you to hang up.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nobnoobody</title>
		<link>http://www.centernetworks.com/wordpress-exploited-284-release#comment-104742</link>
		<dc:creator>Nobnoobody</dc:creator>
		<pubDate>Thu, 22 Oct 2009 00:47:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.centernetworks.com/?p=16544#comment-104742</guid>
		<description>Consider this a drive-by post, but I&#039;m LOLing at the thought that this is blamable on wordpress. You said someone editted the template file. That means it wasn&#039;t a security problem in wordpress but rather something else. Way to blame them for the problem.

(And this is coming from someone who loves Drupal far more than WordpresS)</description>
		<content:encoded><![CDATA[<p>Consider this a drive-by post, but I&#8217;m LOLing at the thought that this is blamable on wordpress. You said someone editted the template file. That means it wasn&#8217;t a security problem in wordpress but rather something else. Way to blame them for the problem.</p>
<p>(And this is coming from someone who loves Drupal far more than WordpresS)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lon</title>
		<link>http://www.centernetworks.com/wordpress-exploited-284-release#comment-75240</link>
		<dc:creator>Lon</dc:creator>
		<pubDate>Wed, 30 Sep 2009 03:03:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.centernetworks.com/?p=16544#comment-75240</guid>
		<description>Before switching to 2.8.4, our site was compromised.  The @*%$! spammers deployed two files to our system /wp-admin/fotter.php and /wp-admin/inclode.php (note the purposeful misspellings).  These were encrypted files that were web-based backdoors.  These were causing our theme footer to be overwritten nightly.</description>
		<content:encoded><![CDATA[<p>Before switching to 2.8.4, our site was compromised.  The @*%$! spammers deployed two files to our system /wp-admin/fotter.php and /wp-admin/inclode.php (note the purposeful misspellings).  These were encrypted files that were web-based backdoors.  These were causing our theme footer to be overwritten nightly.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Follow-Up To The Wordpress Exploit and Tips to Protect Your Blog &#124; CenterNetworks</title>
		<link>http://www.centernetworks.com/wordpress-exploited-284-release#comment-69320</link>
		<dc:creator>Follow-Up To The Wordpress Exploit and Tips to Protect Your Blog &#124; CenterNetworks</dc:creator>
		<pubDate>Tue, 22 Sep 2009 00:24:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.centernetworks.com/?p=16544#comment-69320</guid>
		<description>[...] With Newly-Acquired Omniture Potential Quantcast RivalTodays Startup and Entrepreneurial UpdatesWordpress Exploited 2.8.4 ReleaseEnsequence Grabs a Bundle of Cash and a New [...]</description>
		<content:encoded><![CDATA[<p>[...] With Newly-Acquired Omniture Potential Quantcast RivalTodays Startup and Entrepreneurial UpdatesWordpress Exploited 2.8.4 ReleaseEnsequence Grabs a Bundle of Cash and a New [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Otto</title>
		<link>http://www.centernetworks.com/wordpress-exploited-284-release#comment-69264</link>
		<dc:creator>Otto</dc:creator>
		<pubDate>Mon, 21 Sep 2009 21:43:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.centernetworks.com/?p=16544#comment-69264</guid>
		<description>Make sure you search *real* good. A mere search for &quot;base64&quot; isn&#039;t enough.

See here: http://ottodestruct.com/blog/2009/hacked-wordpress-backdoors/</description>
		<content:encoded><![CDATA[<p>Make sure you search *real* good. A mere search for &#8220;base64&#8243; isn&#8217;t enough.</p>
<p>See here: <a href="http://ottodestruct.com/blog/2009/hacked-wordpress-backdoors/" rel="nofollow">http://ottodestruct.com/blog/2009/hacked-wordpress-backdoors/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Otto</title>
		<link>http://www.centernetworks.com/wordpress-exploited-284-release#comment-69261</link>
		<dc:creator>Otto</dc:creator>
		<pubDate>Mon, 21 Sep 2009 21:41:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.centernetworks.com/?p=16544#comment-69261</guid>
		<description>Yeah, and Macs are immune to malware too.

How many WordPress sites are there? How many Drupal sites? 

Thought experiment: You&#039;re a malware author. What do you target?</description>
		<content:encoded><![CDATA[<p>Yeah, and Macs are immune to malware too.</p>
<p>How many WordPress sites are there? How many Drupal sites? </p>
<p>Thought experiment: You&#8217;re a malware author. What do you target?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: wplaat</title>
		<link>http://www.centernetworks.com/wordpress-exploited-284-release#comment-68864</link>
		<dc:creator>wplaat</dc:creator>
		<pubDate>Mon, 21 Sep 2009 05:47:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.centernetworks.com/?p=16544#comment-68864</guid>
		<description>My Wordpress 2.8.4 website was also hacked last three days. Footer.php is edited every night. Download file permissions were changed. Does anybody has a solution for it! Looking forward to all your replies!</description>
		<content:encoded><![CDATA[<p>My WordPress 2.8.4 website was also hacked last three days. Footer.php is edited every night. Download file permissions were changed. Does anybody has a solution for it! Looking forward to all your replies!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nikolay Kolev</title>
		<link>http://www.centernetworks.com/wordpress-exploited-284-release#comment-68429</link>
		<dc:creator>Nikolay Kolev</dc:creator>
		<pubDate>Sat, 19 Sep 2009 20:29:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.centernetworks.com/?p=16544#comment-68429</guid>
		<description>Drupal indicates when a new version is not an &quot;upgrade&quot;, but rather - a required security patch. In WordPress, there&#039;s no such indication and you should not expect people to rush to upgrade.

Anyway, kudos to WordPress for the one-click upgrades of everything - core, plugins, themes. This process is so painful with Drupal!</description>
		<content:encoded><![CDATA[<p>Drupal indicates when a new version is not an &#8220;upgrade&#8221;, but rather &#8211; a required security patch. In WordPress, there&#8217;s no such indication and you should not expect people to rush to upgrade.</p>
<p>Anyway, kudos to WordPress for the one-click upgrades of everything &#8211; core, plugins, themes. This process is so painful with Drupal!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mario Olckers</title>
		<link>http://www.centernetworks.com/wordpress-exploited-284-release#comment-68427</link>
		<dc:creator>Mario Olckers</dc:creator>
		<pubDate>Sat, 19 Sep 2009 20:26:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.centernetworks.com/?p=16544#comment-68427</guid>
		<description>hey allen :) yeah, sure but my point is nevertheless to also look out for that kind of thing in themes found elsewhere on the web

many design and webdevelopment type sites have regular compiled lists of free themes and I have taken a couple apart and some had the encrypted string in the footer file</description>
		<content:encoded><![CDATA[<p>hey allen :) yeah, sure but my point is nevertheless to also look out for that kind of thing in themes found elsewhere on the web</p>
<p>many design and webdevelopment type sites have regular compiled lists of free themes and I have taken a couple apart and some had the encrypted string in the footer file</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chuck</title>
		<link>http://www.centernetworks.com/wordpress-exploited-284-release#comment-68412</link>
		<dc:creator>Chuck</dc:creator>
		<pubDate>Sat, 19 Sep 2009 19:36:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.centernetworks.com/?p=16544#comment-68412</guid>
		<description>Wordpress is leakier than Drupal but my Drupal sites have been hacked a couple of times.

The most important thing about any CMS is to stay up to date.</description>
		<content:encoded><![CDATA[<p>WordPress is leakier than Drupal but my Drupal sites have been hacked a couple of times.</p>
<p>The most important thing about any CMS is to stay up to date.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Deltina</title>
		<link>http://www.centernetworks.com/wordpress-exploited-284-release#comment-68377</link>
		<dc:creator>Deltina</dc:creator>
		<pubDate>Sat, 19 Sep 2009 18:28:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.centernetworks.com/?p=16544#comment-68377</guid>
		<description>Matt,

I use the WP Security Scanner plugin on all of my WordPress sites, and I seem to keep relatively hack free. By relatively, I mean that there are hacking attempts, but they never get very far. Is this a plugin you would recommend for everyone, or is there another as well?

I am also a Drupal user, but am willing to take the risk with WordPress because of its user-friendly backend and its SEO and SMO superiority. If we as developers are using FREE software, we should be privy to the responsibility and risk that comes with it.

Thanks for all you do, Matt!!</description>
		<content:encoded><![CDATA[<p>Matt,</p>
<p>I use the WP Security Scanner plugin on all of my WordPress sites, and I seem to keep relatively hack free. By relatively, I mean that there are hacking attempts, but they never get very far. Is this a plugin you would recommend for everyone, or is there another as well?</p>
<p>I am also a Drupal user, but am willing to take the risk with WordPress because of its user-friendly backend and its SEO and SMO superiority. If we as developers are using FREE software, we should be privy to the responsibility and risk that comes with it.</p>
<p>Thanks for all you do, Matt!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Allen Stern</title>
		<link>http://www.centernetworks.com/wordpress-exploited-284-release#comment-68366</link>
		<dc:creator>Allen Stern</dc:creator>
		<pubDate>Sat, 19 Sep 2009 18:16:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.centernetworks.com/?p=16544#comment-68366</guid>
		<description>just to confirm - the CN theme I made :)</description>
		<content:encoded><![CDATA[<p>just to confirm &#8211; the CN theme I made :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mario Olckers</title>
		<link>http://www.centernetworks.com/wordpress-exploited-284-release#comment-68365</link>
		<dc:creator>Mario Olckers</dc:creator>
		<pubDate>Sat, 19 Sep 2009 18:12:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.centernetworks.com/?p=16544#comment-68365</guid>
		<description>@Admiral thanks for the good advice, also as you mentioned searching for the eval(base64) string, a lot of the free wordpress themes out in the wild has that very same string with the gobbledygook string of characters in the footer.php file and i think that is how many installs get pwn&#039;ed

apparently it is to keep unscrupulous people from editing out the credit in the footers of themes, but in most cases it carries nasty backdoor entries into your wp install and ultimately the servers on which your blog is hosted

so stick to either the themes from wordpress.org or pay someone to customize or design your desired theme from scratch

just my 0.002 :)</description>
		<content:encoded><![CDATA[<p>@Admiral thanks for the good advice, also as you mentioned searching for the eval(base64) string, a lot of the free wordpress themes out in the wild has that very same string with the gobbledygook string of characters in the footer.php file and i think that is how many installs get pwn&#8217;ed</p>
<p>apparently it is to keep unscrupulous people from editing out the credit in the footers of themes, but in most cases it carries nasty backdoor entries into your wp install and ultimately the servers on which your blog is hosted</p>
<p>so stick to either the themes from wordpress.org or pay someone to customize or design your desired theme from scratch</p>
<p>just my 0.002 :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Allen Stern</title>
		<link>http://www.centernetworks.com/wordpress-exploited-284-release#comment-68359</link>
		<dc:creator>Allen Stern</dc:creator>
		<pubDate>Sat, 19 Sep 2009 17:58:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.centernetworks.com/?p=16544#comment-68359</guid>
		<description>Yep, this happened before - the backdoor was inserted into one of the core WP files which wasn&#039;t easily noticeable.</description>
		<content:encoded><![CDATA[<p>Yep, this happened before &#8211; the backdoor was inserted into one of the core WP files which wasn&#8217;t easily noticeable.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced
Database Caching 1/5 queries in 0.005 seconds using disk: basic
Object Caching 487/488 objects using disk: basic

Served from: www.centernetworks.com @ 2012-02-12 23:51:11 -->
