<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Spam Links Injected Into Wordpress&#160;2.7</title>
	<atom:link href="http://boxofjack.com/articles/2009/02/09/spam-links-injected-into-wordpress-27/feed/" rel="self" type="application/rss+xml" />
	<link>http://boxofjack.com/articles/2009/02/09/spam-links-injected-into-wordpress-27/</link>
	<description>I hail from Melbourne, Australia but I am living in Seattle, Washington. This blog is powered by passive aggression.</description>
	<lastBuildDate>Thu, 11 Mar 2010 23:14:45 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Ray Hernandez</title>
		<link>http://boxofjack.com/articles/2009/02/09/spam-links-injected-into-wordpress-27/#comment-4685</link>
		<dc:creator>Ray Hernandez</dc:creator>
		<pubDate>Tue, 10 Mar 2009 02:10:18 +0000</pubDate>
		<guid isPermaLink="false">http://boxofjack.com/?p=1186#comment-4685</guid>
		<description>&lt;p&gt;Same exact thing happen to me...and I&#039;m on Dreamhost.  Actually I&#039;m trying to get the fuck off of dreamhost cause I can&#039;t stand them.  If the servers don&#039;t go down...they get hacked.  It&#039;s crap.  Thanks for the explanation...it really helped...and good luck to everyone else infected.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Same exact thing happen to me&#8230;and I&#8217;m on Dreamhost.  Actually I&#8217;m trying to get the fuck off of dreamhost cause I can&#8217;t stand them.  If the servers don&#8217;t go down&#8230;they get hacked.  It&#8217;s crap.  Thanks for the explanation&#8230;it really helped&#8230;and good luck to everyone else infected.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Dennis</title>
		<link>http://boxofjack.com/articles/2009/02/09/spam-links-injected-into-wordpress-27/#comment-4612</link>
		<dc:creator>Dennis</dc:creator>
		<pubDate>Mon, 16 Feb 2009 05:26:11 +0000</pubDate>
		<guid isPermaLink="false">http://boxofjack.com/?p=1186#comment-4612</guid>
		<description>&lt;p&gt;Totally unrelated... but I really like your vim theme. :-)&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Totally unrelated&#8230; but I really like your vim theme. <span class="emoticon">:-)</span></p>]]></content:encoded>
	</item>
	<item>
		<title>By: neal s</title>
		<link>http://boxofjack.com/articles/2009/02/09/spam-links-injected-into-wordpress-27/#comment-4604</link>
		<dc:creator>neal s</dc:creator>
		<pubDate>Sat, 14 Feb 2009 04:25:26 +0000</pubDate>
		<guid isPermaLink="false">http://boxofjack.com/?p=1186#comment-4604</guid>
		<description>&lt;p&gt;Thanks for the heads up on my site, Jack. I took care of it thanks to you, and I might not have noticed for a long time otherwise. I owe you a beer for sure.&lt;/p&gt;

&lt;p&gt;Have we determined if this is a Dreamhost issue? I might very well need to switch after this. They seem way too vulnerable.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Thanks for the heads up on my site, Jack. I took care of it thanks to you, and I might not have noticed for a long time otherwise. I owe you a beer for sure.</p>

<p>Have we determined if this is a Dreamhost issue? I might very well need to switch after this. They seem way too vulnerable.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Bill Vick</title>
		<link>http://boxofjack.com/articles/2009/02/09/spam-links-injected-into-wordpress-27/#comment-4602</link>
		<dc:creator>Bill Vick</dc:creator>
		<pubDate>Fri, 13 Feb 2009 03:01:55 +0000</pubDate>
		<guid isPermaLink="false">http://boxofjack.com/?p=1186#comment-4602</guid>
		<description>&lt;p&gt;Thanks - they hacked my site (on Dreamhost) as well but your heads  up saved me from both grief and embarrassment.&lt;/p&gt;

&lt;p&gt;Why do idiots like that do things like this?&lt;/p&gt;

&lt;p&gt;Thanks again Jack.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Thanks &#8211; they hacked my site (on Dreamhost) as well but your heads  up saved me from both grief and embarrassment.</p>

<p>Why do idiots like that do things like this?</p>

<p>Thanks again Jack.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Jared</title>
		<link>http://boxofjack.com/articles/2009/02/09/spam-links-injected-into-wordpress-27/#comment-4601</link>
		<dc:creator>Jared</dc:creator>
		<pubDate>Thu, 12 Feb 2009 19:55:08 +0000</pubDate>
		<guid isPermaLink="false">http://boxofjack.com/?p=1186#comment-4601</guid>
		<description>&lt;p&gt;I was hit twice in a week, also on DH.  I&#039;ve since switched to Media Temple last weekend.&lt;/p&gt;

&lt;p&gt;Check your user list -- I found another administrator created in my blog as well, obfuscated with some clever code so I couldn&#039;t delete it from the admin panel (had to go in through phpMyAdmin and remove it manually from the DB).  I also found uploaded to wp-content/uploads an R57shell named &quot;cache.php&quot; as well as a &quot;wp-manager.php.&quot;&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>I was hit twice in a week, also on DH.  I&#8217;ve since switched to Media Temple last weekend.</p>

<p>Check your user list &#8212; I found another administrator created in my blog as well, obfuscated with some clever code so I couldn&#8217;t delete it from the admin panel (had to go in through phpMyAdmin and remove it manually from the DB).  I also found uploaded to wp-content/uploads an R57shell named &#8220;cache.php&#8221; as well as a &#8220;wp-manager.php.&#8221;</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Karan</title>
		<link>http://boxofjack.com/articles/2009/02/09/spam-links-injected-into-wordpress-27/#comment-4597</link>
		<dc:creator>Karan</dc:creator>
		<pubDate>Wed, 11 Feb 2009 00:56:12 +0000</pubDate>
		<guid isPermaLink="false">http://boxofjack.com/?p=1186#comment-4597</guid>
		<description>&lt;p&gt;Also, could be a plugin - I&#039;ve got a very minimal list of plugins, but some particular plugin could be badly behaved...&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Also, could be a plugin &#8211; I&#8217;ve got a very minimal list of plugins, but some particular plugin could be badly behaved&#8230;</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Karan</title>
		<link>http://boxofjack.com/articles/2009/02/09/spam-links-injected-into-wordpress-27/#comment-4596</link>
		<dc:creator>Karan</dc:creator>
		<pubDate>Wed, 11 Feb 2009 00:54:58 +0000</pubDate>
		<guid isPermaLink="false">http://boxofjack.com/?p=1186#comment-4596</guid>
		<description>&lt;p&gt;Dunno if it&#039;s co-incidence, but 2.7.1 is out now - seems to have one or two XMLRPC related fixes.&lt;/p&gt;

&lt;p&gt;Will, for what it&#039;s worth, i&#039;ve got a couple of installs on Dreamhost too but they haven&#039;t been hit - I&#039;d suspect it&#039;s not Dreamhost but Wordpress that&#039;s vulnerable. Report it to Dreamhost support and see if they can follow up - they&#039;re usually pretty responsive.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Dunno if it&#8217;s co-incidence, but 2.7.1 is out now &#8211; seems to have one or two XMLRPC related fixes.</p>

<p>Will, for what it&#8217;s worth, i&#8217;ve got a couple of installs on Dreamhost too but they haven&#8217;t been hit &#8211; I&#8217;d suspect it&#8217;s not Dreamhost but Wordpress that&#8217;s vulnerable. Report it to Dreamhost support and see if they can follow up &#8211; they&#8217;re usually pretty responsive.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: will</title>
		<link>http://boxofjack.com/articles/2009/02/09/spam-links-injected-into-wordpress-27/#comment-4593</link>
		<dc:creator>will</dc:creator>
		<pubDate>Mon, 09 Feb 2009 21:15:52 +0000</pubDate>
		<guid isPermaLink="false">http://boxofjack.com/?p=1186#comment-4593</guid>
		<description>&lt;p&gt;thanks very much for heads up&lt;/p&gt;

&lt;p&gt;I also use Dreamhost and this is the second time I have had a hack in 2 months .... previously they were disguised links at the footer.&lt;/p&gt;

&lt;p&gt;Time to switch hosts.&lt;/p&gt;

&lt;p&gt;Regards&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>thanks very much for heads up</p>

<p>I also use Dreamhost and this is the second time I have had a hack in 2 months &#8230;. previously they were disguised links at the footer.</p>

<p>Time to switch hosts.</p>

<p>Regards</p>]]></content:encoded>
	</item>
</channel>
</rss>
