<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Expunging the wordpress.net.in spam injection hijack</title>
	<atom:link href="http://gordon.dewis.ca/2008/01/06/expunging-the-wordpressnetin-spam-injection-hijack/feed/" rel="self" type="application/rss+xml" />
	<link>http://gordon.dewis.ca/2008/01/06/expunging-the-wordpressnetin-spam-injection-hijack/</link>
	<description>Random musings from Gordon</description>
	<lastBuildDate>Mon, 15 Mar 2010 01:00:38 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Error on Page Message Wordpress - Website Babble Webmaster Forums</title>
		<link>http://gordon.dewis.ca/2008/01/06/expunging-the-wordpressnetin-spam-injection-hijack/comment-page-1/#comment-39448</link>
		<dc:creator>Error on Page Message Wordpress - Website Babble Webmaster Forums</dc:creator>
		<pubDate>Wed, 01 Jul 2009 12:59:29 +0000</pubDate>
		<guid isPermaLink="false">http://gordon.dewis.ca/2008/01/06/expunging-the-wordpressnetin-spam-injection-hijack/#comment-39448</guid>
		<description>[...] Spam Injection: &#8216;Goro&#8217; hacked my blog[/url] Expunging the wordpress.net.in spam injection hijack The Aftermath of a Wordpress Spam Injection (and a Tool to Prevent it) Wordpress exploit: we been [...]</description>
		<content:encoded><![CDATA[<p>[...] Spam Injection: &#8216;Goro&#8217; hacked my blog[/url] Expunging the wordpress.net.in spam injection hijack The Aftermath of a Wordpress Spam Injection (and a Tool to Prevent it) Wordpress exploit: we been [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike Gifford</title>
		<link>http://gordon.dewis.ca/2008/01/06/expunging-the-wordpressnetin-spam-injection-hijack/comment-page-1/#comment-39371</link>
		<dc:creator>Mike Gifford</dc:creator>
		<pubDate>Tue, 21 Apr 2009 18:20:57 +0000</pubDate>
		<guid isPermaLink="false">http://gordon.dewis.ca/2008/01/06/expunging-the-wordpressnetin-spam-injection-hijack/#comment-39371</guid>
		<description>Thanks, I was wondering what to grep for, and found this quickly using:
 $ grep -ir &#039;http://wordpress.net.in/license.txt&#039; *</description>
		<content:encoded><![CDATA[<p>Thanks, I was wondering what to grep for, and found this quickly using:<br />
 $ grep -ir &#8216;http://wordpress.net.in/license.txt&#8217; *</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: security monitoring</title>
		<link>http://gordon.dewis.ca/2008/01/06/expunging-the-wordpressnetin-spam-injection-hijack/comment-page-1/#comment-33537</link>
		<dc:creator>security monitoring</dc:creator>
		<pubDate>Mon, 15 Dec 2008 02:10:49 +0000</pubDate>
		<guid isPermaLink="false">http://gordon.dewis.ca/2008/01/06/expunging-the-wordpressnetin-spam-injection-hijack/#comment-33537</guid>
		<description>I’ve find some useful information on how to clean that mess. They were caused by a spam injection hijack. Great article.</description>
		<content:encoded><![CDATA[<p>I’ve find some useful information on how to clean that mess. They were caused by a spam injection hijack. Great article.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pinnacle Security</title>
		<link>http://gordon.dewis.ca/2008/01/06/expunging-the-wordpressnetin-spam-injection-hijack/comment-page-1/#comment-32123</link>
		<dc:creator>Pinnacle Security</dc:creator>
		<pubDate>Wed, 19 Nov 2008 21:23:27 +0000</pubDate>
		<guid isPermaLink="false">http://gordon.dewis.ca/2008/01/06/expunging-the-wordpressnetin-spam-injection-hijack/#comment-32123</guid>
		<description>I&#039;ve seen this before,and im lucky to get rid of it.Is there a way to terminate this?</description>
		<content:encoded><![CDATA[<p>I&#8217;ve seen this before,and im lucky to get rid of it.Is there a way to terminate this?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: gordon</title>
		<link>http://gordon.dewis.ca/2008/01/06/expunging-the-wordpressnetin-spam-injection-hijack/comment-page-1/#comment-30831</link>
		<dc:creator>gordon</dc:creator>
		<pubDate>Tue, 21 Oct 2008 16:39:57 +0000</pubDate>
		<guid isPermaLink="false">http://gordon.dewis.ca/2008/01/06/expunging-the-wordpressnetin-spam-injection-hijack/#comment-30831</guid>
		<description>WordPress is very good and many of the problems aren&#039;t with WordPress itself, but rather with components it uses.</description>
		<content:encoded><![CDATA[<p>WordPress is very good and many of the problems aren&#8217;t with WordPress itself, but rather with components it uses.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aaron</title>
		<link>http://gordon.dewis.ca/2008/01/06/expunging-the-wordpressnetin-spam-injection-hijack/comment-page-1/#comment-30803</link>
		<dc:creator>Aaron</dc:creator>
		<pubDate>Tue, 21 Oct 2008 07:02:35 +0000</pubDate>
		<guid isPermaLink="false">http://gordon.dewis.ca/2008/01/06/expunging-the-wordpressnetin-spam-injection-hijack/#comment-30803</guid>
		<description>Wordpress is great, and I realize no software is perfect, but come on, this hijacking is getting out of control. Can&#039;t somebody get in there in fix it?</description>
		<content:encoded><![CDATA[<p>Wordpress is great, and I realize no software is perfect, but come on, this hijacking is getting out of control. Can&#8217;t somebody get in there in fix it?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: gordon</title>
		<link>http://gordon.dewis.ca/2008/01/06/expunging-the-wordpressnetin-spam-injection-hijack/comment-page-1/#comment-28282</link>
		<dc:creator>gordon</dc:creator>
		<pubDate>Sun, 07 Sep 2008 22:23:59 +0000</pubDate>
		<guid isPermaLink="false">http://gordon.dewis.ca/2008/01/06/expunging-the-wordpressnetin-spam-injection-hijack/#comment-28282</guid>
		<description>Ugh... that&#039;s not good.  Did you happen to change your theme recently?  I&#039;ve been wondering if poorly-written or maliciously-written themes are one way this sort of thing happens.</description>
		<content:encoded><![CDATA[<p>Ugh&#8230; that&#8217;s not good.  Did you happen to change your theme recently?  I&#8217;ve been wondering if poorly-written or maliciously-written themes are one way this sort of thing happens.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Uptowngal</title>
		<link>http://gordon.dewis.ca/2008/01/06/expunging-the-wordpressnetin-spam-injection-hijack/comment-page-1/#comment-28262</link>
		<dc:creator>Uptowngal</dc:creator>
		<pubDate>Sun, 07 Sep 2008 15:28:56 +0000</pubDate>
		<guid isPermaLink="false">http://gordon.dewis.ca/2008/01/06/expunging-the-wordpressnetin-spam-injection-hijack/#comment-28262</guid>
		<description>It&#039;s freaking bad lucky but my blog got hacked AGAIN even after I upgraded to Wordpress 2.6!  :(  Tried to harden my blog by adding in the &quot;Secret Key&quot; as suggested by WP... hope it works.  :(  Not sure what else I can do &#039;cos I&#039;m quite lousy at WP stuff.</description>
		<content:encoded><![CDATA[<p>It&#8217;s freaking bad lucky but my blog got hacked AGAIN even after I upgraded to Wordpress 2.6!  <img src='http://gordon.dewis.ca/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' />   Tried to harden my blog by adding in the &#8220;Secret Key&#8221; as suggested by WP&#8230; hope it works.  <img src='http://gordon.dewis.ca/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' />   Not sure what else I can do &#8216;cos I&#8217;m quite lousy at WP stuff.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Forex Converter</title>
		<link>http://gordon.dewis.ca/2008/01/06/expunging-the-wordpressnetin-spam-injection-hijack/comment-page-1/#comment-25624</link>
		<dc:creator>Forex Converter</dc:creator>
		<pubDate>Fri, 18 Jul 2008 12:43:05 +0000</pubDate>
		<guid isPermaLink="false">http://gordon.dewis.ca/2008/01/06/expunging-the-wordpressnetin-spam-injection-hijack/#comment-25624</guid>
		<description>Isn&#039;t there a plugin to fix all these hacking attempts? Someone tried to hack my blogs too :(</description>
		<content:encoded><![CDATA[<p>Isn&#8217;t there a plugin to fix all these hacking attempts? Someone tried to hack my blogs too <img src='http://gordon.dewis.ca/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dan</title>
		<link>http://gordon.dewis.ca/2008/01/06/expunging-the-wordpressnetin-spam-injection-hijack/comment-page-1/#comment-24239</link>
		<dc:creator>Dan</dc:creator>
		<pubDate>Wed, 25 Jun 2008 09:31:24 +0000</pubDate>
		<guid isPermaLink="false">http://gordon.dewis.ca/2008/01/06/expunging-the-wordpressnetin-spam-injection-hijack/#comment-24239</guid>
		<description>My blog was dropped by Google because of this attack.  After cleaning up and fixing as you all did above I still found that the hacker had injected spam links into my blog database.

I just wrote a &#039;fix&#039; in PHP that everyone can use to clean all of the spam links out of their database.  This fix is tested and worked in my case.  Feedback is welcomed!

You can get the fix here -

http://hygen.net/blog/?p=195

~ Dan</description>
		<content:encoded><![CDATA[<p>My blog was dropped by Google because of this attack.  After cleaning up and fixing as you all did above I still found that the hacker had injected spam links into my blog database.</p>
<p>I just wrote a &#8216;fix&#8217; in PHP that everyone can use to clean all of the spam links out of their database.  This fix is tested and worked in my case.  Feedback is welcomed!</p>
<p>You can get the fix here -</p>
<p><a href="http://hygen.net/blog/?p=195" rel="nofollow">http://hygen.net/blog/?p=195</a></p>
<p>~ Dan</p>
]]></content:encoded>
	</item>
</channel>
</rss>
