<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: EtL Hack Causes Major Disruption to Service</title>
	<atom:link href="http://enticingthelight.com/2010/04/22/etl-hack-causes-major-disruption-to-service/feed/" rel="self" type="application/rss+xml" />
	<link>http://enticingthelight.com/2010/04/22/etl-hack-causes-major-disruption-to-service/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=etl-hack-causes-major-disruption-to-service</link>
	<description>A Quest for Photographic Enlightenment</description>
	<lastBuildDate>Tue, 07 Feb 2012 16:47:04 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: Sussex photographer</title>
		<link>http://enticingthelight.com/2010/04/22/etl-hack-causes-major-disruption-to-service/comment-page-1/#comment-3384</link>
		<dc:creator>Sussex photographer</dc:creator>
		<pubDate>Tue, 27 Apr 2010 16:27:47 +0000</pubDate>
		<guid isPermaLink="false">http://enticingthelight.com/?p=6266#comment-3384</guid>
		<description>Thanks for the info. I&#039;ve tucked it away in case I need it some time.</description>
		<content:encoded><![CDATA[<p>Thanks for the info. I&#8217;ve tucked it away in case I need it some time.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Miserere</title>
		<link>http://enticingthelight.com/2010/04/22/etl-hack-causes-major-disruption-to-service/comment-page-1/#comment-3330</link>
		<dc:creator>Miserere</dc:creator>
		<pubDate>Fri, 23 Apr 2010 16:38:48 +0000</pubDate>
		<guid isPermaLink="false">http://enticingthelight.com/?p=6266#comment-3330</guid>
		<description>That&#039;s a good question about the code in a comment. I don&#039;t think so, but I am no WordPress expert either.

What I did was back up the database, change the passwords for the database, FTP and WordPress account (for both me and Peter), then do a search and delete for instances of eval(base64_decode(blahblahblah)), which had infected almost 400 files; then finally I &quot;updated&quot; WordPress (I was already running the latest version). At this point the site was still redirecting somewhere dodgy and I couldn&#039;t find the script that was doing it, so I disabled all the plugins and the redirecting stopped. I tried activating the plugins one by one, but gave up after the 4th one in a row came up infected--I&#039;m pretty sure they were all infected. So I just deleted all of them and am now in the process of reinstalling them again. At this point I have again changed all the passwords.

I&#039;m pretty sure my problem was that I had some files with 777 permissions (allowing anyone to write to them), and the bots found them. I&#039;m now following closely what WP themselves are recommending &lt;a href=&quot;http://codex.wordpress.org/Hardening_WordPress&quot; rel=&quot;nofollow&quot;&gt;here&lt;/a&gt; in regards to permissions.

In order to reduce my chances of being hacked again I am also beefing up back-end security with some plugins recommended &lt;a href=&quot;http://blog.taragana.com/index.php/archive/20-wordpress-security-plug-ins-and-tips-to-keep-hackers-away/&quot; rel=&quot;nofollow&quot;&gt;here&lt;/a&gt;.</description>
		<content:encoded><![CDATA[<p>That&#8217;s a good question about the code in a comment. I don&#8217;t think so, but I am no WordPress expert either.</p>
<p>What I did was back up the database, change the passwords for the database, FTP and WordPress account (for both me and Peter), then do a search and delete for instances of eval(base64_decode(blahblahblah)), which had infected almost 400 files; then finally I &#8220;updated&#8221; WordPress (I was already running the latest version). At this point the site was still redirecting somewhere dodgy and I couldn&#8217;t find the script that was doing it, so I disabled all the plugins and the redirecting stopped. I tried activating the plugins one by one, but gave up after the 4th one in a row came up infected&#8211;I&#8217;m pretty sure they were all infected. So I just deleted all of them and am now in the process of reinstalling them again. At this point I have again changed all the passwords.</p>
<p>I&#8217;m pretty sure my problem was that I had some files with 777 permissions (allowing anyone to write to them), and the bots found them. I&#8217;m now following closely what WP themselves are recommending <a href="http://codex.wordpress.org/Hardening_WordPress" rel="nofollow">here</a> in regards to permissions.</p>
<p>In order to reduce my chances of being hacked again I am also beefing up back-end security with some plugins recommended <a href="http://blog.taragana.com/index.php/archive/20-wordpress-security-plug-ins-and-tips-to-keep-hackers-away/" rel="nofollow">here</a>.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sussex photographer</title>
		<link>http://enticingthelight.com/2010/04/22/etl-hack-causes-major-disruption-to-service/comment-page-1/#comment-3324</link>
		<dc:creator>Sussex photographer</dc:creator>
		<pubDate>Fri, 23 Apr 2010 13:23:15 +0000</pubDate>
		<guid isPermaLink="false">http://enticingthelight.com/?p=6266#comment-3324</guid>
		<description>That is nasty. My own site is based on Wordpress too so I&#039;d be interested in knowing what was done. I&#039;m not a Wordpress expert. What I would probably have done is back up the blog database and then reinstall everything. I wouldn&#039;t know how to do that straight off but would be able to figure it out. But then I&#039;m not sure that would have handled everything. Is it possible for dodgy code to get into the database via a comment?</description>
		<content:encoded><![CDATA[<p>That is nasty. My own site is based on WordPress too so I&#8217;d be interested in knowing what was done. I&#8217;m not a WordPress expert. What I would probably have done is back up the blog database and then reinstall everything. I wouldn&#8217;t know how to do that straight off but would be able to figure it out. But then I&#8217;m not sure that would have handled everything. Is it possible for dodgy code to get into the database via a comment?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Miserere</title>
		<link>http://enticingthelight.com/2010/04/22/etl-hack-causes-major-disruption-to-service/comment-page-1/#comment-3322</link>
		<dc:creator>Miserere</dc:creator>
		<pubDate>Fri, 23 Apr 2010 12:47:14 +0000</pubDate>
		<guid isPermaLink="false">http://enticingthelight.com/?p=6266#comment-3322</guid>
		<description>Thanks, Javier. I&#039;m taking steps to ensure it doesn&#039;t happen again. It&#039;s not even like the hackers were after anything...and it was probably an automated hacking program, not even a person. There is no point to this type of hacking except to annoy good people like you and me.</description>
		<content:encoded><![CDATA[<p>Thanks, Javier. I&#8217;m taking steps to ensure it doesn&#8217;t happen again. It&#8217;s not even like the hackers were after anything&#8230;and it was probably an automated hacking program, not even a person. There is no point to this type of hacking except to annoy good people like you and me.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: javier</title>
		<link>http://enticingthelight.com/2010/04/22/etl-hack-causes-major-disruption-to-service/comment-page-1/#comment-3316</link>
		<dc:creator>javier</dc:creator>
		<pubDate>Fri, 23 Apr 2010 06:12:23 +0000</pubDate>
		<guid isPermaLink="false">http://enticingthelight.com/?p=6266#comment-3316</guid>
		<description>Sorry to hear this mis...</description>
		<content:encoded><![CDATA[<p>Sorry to hear this mis&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>

