<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Being web-cracked: experience and advice</title>
	<atom:link href="http://www.konstantin.shemyak.com/blog/2009/06/16/being-web-cracked-experience-and-advice/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.konstantin.shemyak.com/blog/2009/06/16/being-web-cracked-experience-and-advice/</link>
	<description></description>
	<lastBuildDate>Thu, 26 Jan 2012 07:01:10 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: konstantin</title>
		<link>http://www.konstantin.shemyak.com/blog/2009/06/16/being-web-cracked-experience-and-advice/comment-page-1/#comment-13165</link>
		<dc:creator>konstantin</dc:creator>
		<pubDate>Tue, 08 Sep 2009 06:36:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.konstantin.shemyak.com/blog/?p=205#comment-13165</guid>
		<description>Hi Lunesse,
Nope, I have not done anything to actually close the entry point. That&#039;s because I was not able to find it. I removed the infected code from the web pages and also found a file in my home directory on the provider&#039;s server which was likely used for the exploit. Got no idea on how it appeared there. Removed that one too, and the exploit does not seem to come back. I realize that the hole is most likely still open :(</description>
		<content:encoded><![CDATA[<p>Hi Lunesse,<br />
Nope, I have not done anything to actually close the entry point. That&#8217;s because I was not able to find it. I removed the infected code from the web pages and also found a file in my home directory on the provider&#8217;s server which was likely used for the exploit. Got no idea on how it appeared there. Removed that one too, and the exploit does not seem to come back. I realize that the hole is most likely still open <img src='http://www.konstantin.shemyak.com/blog/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lunesse</title>
		<link>http://www.konstantin.shemyak.com/blog/2009/06/16/being-web-cracked-experience-and-advice/comment-page-1/#comment-13164</link>
		<dc:creator>Lunesse</dc:creator>
		<pubDate>Tue, 04 Aug 2009 18:49:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.konstantin.shemyak.com/blog/?p=205#comment-13164</guid>
		<description>Mine comes back every day even after I remove the code. I&#039;m starting to suspect the database, as the files do not have modify dates. has it come back for you? did you do anything other than what is listed above in this article you wrote? I&#039;m on DH too.</description>
		<content:encoded><![CDATA[<p>Mine comes back every day even after I remove the code. I&#8217;m starting to suspect the database, as the files do not have modify dates. has it come back for you? did you do anything other than what is listed above in this article you wrote? I&#8217;m on DH too.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: konstantin</title>
		<link>http://www.konstantin.shemyak.com/blog/2009/06/16/being-web-cracked-experience-and-advice/comment-page-1/#comment-13158</link>
		<dc:creator>konstantin</dc:creator>
		<pubDate>Thu, 18 Jun 2009 12:29:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.konstantin.shemyak.com/blog/?p=205#comment-13158</guid>
		<description>Talking back to self... this seems to be a problem not specific to WordPress; at least &lt;a href=&quot;http://www.digitalpimponline.com/board/viewtopic.php?t=6583&amp;postdays=0&amp;postorder=asc&amp;start=15&quot; rel=&quot;nofollow&quot;&gt;phpBB&lt;/a&gt; and &lt;a href=&quot;http://community.mybboard.net/thread-51091.html&quot; rel=&quot;nofollow&quot;&gt;MyBBoard&lt;/a&gt; users are reporting the same problem.</description>
		<content:encoded><![CDATA[<p>Talking back to self&#8230; this seems to be a problem not specific to WordPress; at least <a href="http://www.digitalpimponline.com/board/viewtopic.php?t=6583&amp;postdays=0&amp;postorder=asc&amp;start=15" rel="nofollow">phpBB</a> and <a href="http://community.mybboard.net/thread-51091.html" rel="nofollow">MyBBoard</a> users are reporting the same problem.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: konstantin</title>
		<link>http://www.konstantin.shemyak.com/blog/2009/06/16/being-web-cracked-experience-and-advice/comment-page-1/#comment-13157</link>
		<dc:creator>konstantin</dc:creator>
		<pubDate>Thu, 18 Jun 2009 08:00:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.konstantin.shemyak.com/blog/?p=205#comment-13157</guid>
		<description>Exactly. The responsibility division between me and the provider is not absolutely clear, as this is their &quot;automatic install&quot;, but I did a number of customizations to it. Well, backups are made, stay tuned :)</description>
		<content:encoded><![CDATA[<p>Exactly. The responsibility division between me and the provider is not absolutely clear, as this is their &#8220;automatic install&#8221;, but I did a number of customizations to it. Well, backups are made, stay tuned <img src='http://www.konstantin.shemyak.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: konstantin</title>
		<link>http://www.konstantin.shemyak.com/blog/2009/06/16/being-web-cracked-experience-and-advice/comment-page-1/#comment-13156</link>
		<dc:creator>konstantin</dc:creator>
		<pubDate>Thu, 18 Jun 2009 07:42:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.konstantin.shemyak.com/blog/?p=205#comment-13156</guid>
		<description>&lt;strong&gt;@Thomas&lt;/strong&gt;, thank you. I think I&#039;ve cleaned up the malicious code now, and it&#039;s true that during some time period &lt;strong&gt;this site&lt;/strong&gt; was spreading the scam! Digging the logs now...</description>
		<content:encoded><![CDATA[<p><strong>@Thomas</strong>, thank you. I think I&#8217;ve cleaned up the malicious code now, and it&#8217;s true that during some time period <strong>this site</strong> was spreading the scam! Digging the logs now&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: konstantin</title>
		<link>http://www.konstantin.shemyak.com/blog/2009/06/16/being-web-cracked-experience-and-advice/comment-page-1/#comment-13155</link>
		<dc:creator>konstantin</dc:creator>
		<pubDate>Wed, 17 Jun 2009 20:26:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.konstantin.shemyak.com/blog/?p=205#comment-13155</guid>
		<description>&lt;em&gt;illness goes first, the cure – later&lt;/em&gt;
Or even better: prevention is easier than cure :)</description>
		<content:encoded><![CDATA[<p><em>illness goes first, the cure – later</em><br />
Or even better: prevention is easier than cure <img src='http://www.konstantin.shemyak.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kirill Evstigneev</title>
		<link>http://www.konstantin.shemyak.com/blog/2009/06/16/being-web-cracked-experience-and-advice/comment-page-1/#comment-13153</link>
		<dc:creator>Kirill Evstigneev</dc:creator>
		<pubDate>Wed, 17 Jun 2009 11:48:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.konstantin.shemyak.com/blog/?p=205#comment-13153</guid>
		<description>Strictly speaking NoScript is absolutely The Must for the Web surfing. Some time ago my browser (both IE and Firefox) cache contained at least several pieces of a dangerous junk - trojans, rootkits, etc. Everything is clear after NoScript was installed. Yes, it imposes some inconvenience. But just a little and almost incomparable with a possible harm.
One could say - antivirus is the solution. Well, but remember - illness goes first, the cure - later. And there is a time leap when &lt;em&gt;your&lt;/em&gt; infection won&#039;t be known and detected.</description>
		<content:encoded><![CDATA[<p>Strictly speaking NoScript is absolutely The Must for the Web surfing. Some time ago my browser (both IE and Firefox) cache contained at least several pieces of a dangerous junk &#8211; trojans, rootkits, etc. Everything is clear after NoScript was installed. Yes, it imposes some inconvenience. But just a little and almost incomparable with a possible harm.<br />
One could say &#8211; antivirus is the solution. Well, but remember &#8211; illness goes first, the cure &#8211; later. And there is a time leap when <em>your</em> infection won&#8217;t be known and detected.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Thomas J. Raef</title>
		<link>http://www.konstantin.shemyak.com/blog/2009/06/16/being-web-cracked-experience-and-advice/comment-page-1/#comment-13151</link>
		<dc:creator>Thomas J. Raef</dc:creator>
		<pubDate>Tue, 16 Jun 2009 20:07:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.konstantin.shemyak.com/blog/?p=205#comment-13151</guid>
		<description>I got new for you!

Your site is still trying to infect visitors.

It&#039;s trying to deliver a malicious Adobe Acrobat file. Luckily I had javascript turned off in Acrobat.

Many of these infections have been the result of a virus/trojan on the PC used to update the website. We&#039;ve had the best luck in finding and eradicating these PC infections with a combination of AVG and Malwarebytes.

According to our scanners, blog/index.html is also infected.

Do you have the log files for your site? Do you seen any FTP activity that is not yours?

In the log files do you see any POSTs with strange query strings? 

If you get nowhere with your hosting provider, please contact me off-list and we&#039;ll help you. We help out a lot on www.badwarebusters.org

Good luck!</description>
		<content:encoded><![CDATA[<p>I got new for you!</p>
<p>Your site is still trying to infect visitors.</p>
<p>It&#8217;s trying to deliver a malicious Adobe Acrobat file. Luckily I had javascript turned off in Acrobat.</p>
<p>Many of these infections have been the result of a virus/trojan on the PC used to update the website. We&#8217;ve had the best luck in finding and eradicating these PC infections with a combination of AVG and Malwarebytes.</p>
<p>According to our scanners, blog/index.html is also infected.</p>
<p>Do you have the log files for your site? Do you seen any FTP activity that is not yours?</p>
<p>In the log files do you see any POSTs with strange query strings? </p>
<p>If you get nowhere with your hosting provider, please contact me off-list and we&#8217;ll help you. We help out a lot on <a href="http://www.badwarebusters.org" rel="nofollow">http://www.badwarebusters.org</a></p>
<p>Good luck!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: vitaly repin</title>
		<link>http://www.konstantin.shemyak.com/blog/2009/06/16/being-web-cracked-experience-and-advice/comment-page-1/#comment-13149</link>
		<dc:creator>vitaly repin</dc:creator>
		<pubDate>Tue, 16 Jun 2009 17:08:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.konstantin.shemyak.com/blog/?p=205#comment-13149</guid>
		<description>wget -O infected-script &#039;http://www.konstantin.shemyak.com/dnevnik/wp-admin/load-scripts.php?c=0&amp;load=jquery,utils,quicktags&amp;ver=b64ae9a301a545332f1fcd4c6c5351b4&#039;

Hm.  But the key question is how this script was infected?  How the attacker was able to add his stuff into the page which is hosted by your server?</description>
		<content:encoded><![CDATA[<p>wget -O infected-script &#8216;<a href="http://www.konstantin.shemyak.com/dnevnik/wp-admin/load-scripts.php?c=0&#038;load=jquery,utils,quicktags&#038;ver=b64ae9a301a545332f1fcd4c6c5351b4" rel="nofollow">http://www.konstantin.shemyak.com/dnevnik/wp-admin/load-scripts.php?c=0&#038;load=jquery,utils,quicktags&#038;ver=b64ae9a301a545332f1fcd4c6c5351b4</a>&#8216;</p>
<p>Hm.  But the key question is how this script was infected?  How the attacker was able to add his stuff into the page which is hosted by your server?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

