<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Hacked !</title>
	<atom:link href="http://www.phocean.net/2008/06/03/hacked.html/feed" rel="self" type="application/rss+xml" />
	<link>http://www.phocean.net/2008/06/03/hacked.html?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=hacked</link>
	<description>&#34;A defense that hedgehogs possess is the ability to roll into a tight ball, causing all of the spines to point outwards.&#34; -- Wikipedia</description>
	<lastBuildDate>Wed, 09 Nov 2011 11:04:26 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Owen</title>
		<link>http://www.phocean.net/2008/06/03/hacked.html/comment-page-1#comment-1252</link>
		<dc:creator>Owen</dc:creator>
		<pubDate>Mon, 14 Jul 2008 02:48:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.phocean.net/?p=109#comment-1252</guid>
		<description>Well, thats fortunate that you haven&#039;t had any more problems. I know there have been OpenID authentication plug-in exploits for Drupal but am not aware of any for Wordpress, very possible though.</description>
		<content:encoded><![CDATA[<p>Well, thats fortunate that you haven&#8217;t had any more problems. I know there have been OpenID authentication plug-in exploits for Drupal but am not aware of any for WordPress, very possible though.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JC</title>
		<link>http://www.phocean.net/2008/06/03/hacked.html/comment-page-1#comment-581</link>
		<dc:creator>JC</dc:creator>
		<pubDate>Wed, 18 Jun 2008 21:31:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.phocean.net/?p=109#comment-581</guid>
		<description>My blog is on my own server. I can&#039;t say I have perfectly secured it well yet, but it is not that bad and I am sure of the permission.

I really think there is an exploit, and as you say most probably on a plug-in.
Especially, I suspect the OpenID authentication plug-in, because it is quite new, not tested and susceptible to grant access to everything.

So far, running without any other plugin than Akismet, I haven&#039;t been attacked anymore...
Time will tell...</description>
		<content:encoded><![CDATA[<p>My blog is on my own server. I can&#8217;t say I have perfectly secured it well yet, but it is not that bad and I am sure of the permission.</p>
<p>I really think there is an exploit, and as you say most probably on a plug-in.<br />
Especially, I suspect the OpenID authentication plug-in, because it is quite new, not tested and susceptible to grant access to everything.</p>
<p>So far, running without any other plugin than Akismet, I haven&#8217;t been attacked anymore&#8230;<br />
Time will tell&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Owen</title>
		<link>http://www.phocean.net/2008/06/03/hacked.html/comment-page-1#comment-577</link>
		<dc:creator>Owen</dc:creator>
		<pubDate>Wed, 18 Jun 2008 18:28:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.phocean.net/?p=109#comment-577</guid>
		<description>There are many ways that it could have got put there. One possibility is the directory is not chmod&#039;ed correctly and the file was uploaded from a form. Otherwise it could be a new Wordpress exploit that has not been released yet. If you are on a shared server, who knows. It could have been any one on the server with 1/2 a brain. I think that it was a plugin that had a bug.


I&#039;m going to check for that file on my blogs now.</description>
		<content:encoded><![CDATA[<p>There are many ways that it could have got put there. One possibility is the directory is not chmod&#8217;ed correctly and the file was uploaded from a form. Otherwise it could be a new WordPress exploit that has not been released yet. If you are on a shared server, who knows. It could have been any one on the server with 1/2 a brain. I think that it was a plugin that had a bug.</p>
<p>I&#8217;m going to check for that file on my blogs now.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JC</title>
		<link>http://www.phocean.net/2008/06/03/hacked.html/comment-page-1#comment-496</link>
		<dc:creator>JC</dc:creator>
		<pubDate>Fri, 13 Jun 2008 06:36:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.phocean.net/?p=109#comment-496</guid>
		<description>Thanks :)

So it seems that the code responsible for infecting all the files was injected through a wp-stats.php...

Now, as I have started from scratch with a fresh archive of Wordpress, I don&#039;t have such a file anymore.

How the hell could this file have been injected ?</description>
		<content:encoded><![CDATA[<p>Thanks <img src='http://www.phocean.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>So it seems that the code responsible for infecting all the files was injected through a wp-stats.php&#8230;</p>
<p>Now, as I have started from scratch with a fresh archive of WordPress, I don&#8217;t have such a file anymore.</p>
<p>How the hell could this file have been injected ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: C.S.Lee</title>
		<link>http://www.phocean.net/2008/06/03/hacked.html/comment-page-1#comment-493</link>
		<dc:creator>C.S.Lee</dc:creator>
		<pubDate>Wed, 11 Jun 2008 03:08:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.phocean.net/?p=109#comment-493</guid>
		<description>hi,

Nice blog here, anyway that lead to 



And if you check out wp-stats.php, another obfuscated content.

Cheers ;]</description>
		<content:encoded><![CDATA[<p>hi,</p>
<p>Nice blog here, anyway that lead to </p>
<p>And if you check out wp-stats.php, another obfuscated content.</p>
<p>Cheers ;]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

