<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>blog.species5618.net &#187; I got Hacked</title>
	<atom:link href="http://blog.species5618.net/tag/i-got-hacked/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.species5618.net</link>
	<description>The time has come to VENT my anger on the world</description>
	<lastBuildDate>Mon, 11 Jul 2011 14:56:51 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>I got Hacked</title>
		<link>http://blog.species5618.net/2009/02/10/i-got-hacked/</link>
		<comments>http://blog.species5618.net/2009/02/10/i-got-hacked/#comments</comments>
		<pubDate>Tue, 10 Feb 2009 16:43:29 +0000</pubDate>
		<dc:creator>Species5618</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[I got Hacked]]></category>

		<guid isPermaLink="false">http://blog.species5618.net/?p=375</guid>
		<description><![CDATA[Well this is one very embarrassing day. Given my day job The brand new WordPress 2.7 instance I setup for my wife, got hacked Still not sure how, the access logs are not very conclusive, but someone managed to edit every header.php file under the themes folder and inject a trojan &#8220;exploit-iframe.gen.c&#8221; I found a [...]]]></description>
			<content:encoded><![CDATA[<p>Well this is one very embarrassing day. Given my day job <img src='http://blog.species5618.net/wp-includes/images/smilies/icon_sad.gif' alt=':-(' class='wp-smiley' /> </p>
<p>The brand new WordPress 2.7 instance I setup for my wife, got hacked<br />
Still not sure how, the access logs are not very conclusive, but someone managed to edit every header.php file under the themes folder and inject a trojan &#8220;exploit-iframe.gen.c&#8221;</p>
<p>I found a similar story hear. http://photocritic.org/wordpress-exploit-iframe-gen-c/</p>
<p>Yes, I admit I allowed apache write access to the themes folder. which i have now fixed</p>
<p>The Code also included a refernce to &#8220;search_bot111&#8243;</p>
<p>The searchbot code seems to be a bit of PHP?? to hide the site/trojan from search engines</p>
<p>needless to say i am VERY annoyed</p>
<script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script><fb:like href="http%3A%2F%2Fblog.species5618.net%2F2009%2F02%2F10%2Fi-got-hacked%2F" send="true" width="450" show_faces="true" font=""></fb:like>]]></content:encoded>
			<wfw:commentRss>http://blog.species5618.net/2009/02/10/i-got-hacked/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

