<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: WordPress hacked by inii.info</title>
	<atom:link href="http://vinhboy.com/blog/2010/03/01/wordpress-hacked-by-inii-info/feed/" rel="self" type="application/rss+xml" />
	<link>http://vinhboy.com/blog/2010/03/01/wordpress-hacked-by-inii-info/</link>
	<description>I think you are lost...</description>
	<lastBuildDate>Fri, 10 Feb 2012 14:08:34 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Anonymous</title>
		<link>http://vinhboy.com/blog/2010/03/01/wordpress-hacked-by-inii-info/#comment-19757</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Sat, 12 Feb 2011 14:47:00 +0000</pubDate>
		<guid isPermaLink="false">http://vinhboy.com/?p=757#comment-19757</guid>
		<description>Considering Wordpress has released several security updates since... it&#039;s probably just a sweeping under the rug...</description>
		<content:encoded><![CDATA[<p>Considering WordPress has released several security updates since&#8230; it&#8217;s probably just a sweeping under the rug&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: James</title>
		<link>http://vinhboy.com/blog/2010/03/01/wordpress-hacked-by-inii-info/#comment-13838</link>
		<dc:creator>James</dc:creator>
		<pubDate>Mon, 12 Apr 2010 15:12:44 +0000</pubDate>
		<guid isPermaLink="false">http://vinhboy.com/?p=757#comment-13838</guid>
		<description>So... What happened? Anyone?</description>
		<content:encoded><![CDATA[<p>So&#8230; What happened? Anyone?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andy</title>
		<link>http://vinhboy.com/blog/2010/03/01/wordpress-hacked-by-inii-info/#comment-12112</link>
		<dc:creator>Andy</dc:creator>
		<pubDate>Thu, 04 Mar 2010 01:05:42 +0000</pubDate>
		<guid isPermaLink="false">http://vinhboy.com/?p=757#comment-12112</guid>
		<description>I know it&#039;s common practice to set the permissions of all the Wordpress files so the web server can write to them (for when you do automatic upgrades), but that&#039;s very dangerous, particularly if you&#039;re installing free, third-party plugins from wordpress.org. I mean, yeah, those are great, but you have no idea what kind of backdoors certain bad-apple plugin authors may try to give themselves. But you really should not let your web server be able to write to application files anyway, unless you&#039;re going to review every line of source code of every plugin you install. All the Wordpress installations that I set up have file permissions locked down tight, and I never do the web-based auto-upgrade, only the manual one.</description>
		<content:encoded><![CDATA[<p>I know it&#8217;s common practice to set the permissions of all the WordPress files so the web server can write to them (for when you do automatic upgrades), but that&#8217;s very dangerous, particularly if you&#8217;re installing free, third-party plugins from wordpress.org. I mean, yeah, those are great, but you have no idea what kind of backdoors certain bad-apple plugin authors may try to give themselves. But you really should not let your web server be able to write to application files anyway, unless you&#8217;re going to review every line of source code of every plugin you install. All the WordPress installations that I set up have file permissions locked down tight, and I never do the web-based auto-upgrade, only the manual one.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Scott DeSmet</title>
		<link>http://vinhboy.com/blog/2010/03/01/wordpress-hacked-by-inii-info/#comment-12045</link>
		<dc:creator>Scott DeSmet</dc:creator>
		<pubDate>Wed, 03 Mar 2010 00:25:31 +0000</pubDate>
		<guid isPermaLink="false">http://vinhboy.com/?p=757#comment-12045</guid>
		<description>Hi Vinh, We are investigating the issue and unfortunately I do not have anything definitive to share right now. We take security related incidents very seriously and you can be assured we&#039;ll be transparent about what we discover.</description>
		<content:encoded><![CDATA[<p>Hi Vinh, We are investigating the issue and unfortunately I do not have anything definitive to share right now. We take security related incidents very seriously and you can be assured we&#8217;ll be transparent about what we discover.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: 0-day wordpress vulnerability results in many Media Temple malware infections - WordPress Tavern Forum</title>
		<link>http://vinhboy.com/blog/2010/03/01/wordpress-hacked-by-inii-info/#comment-12037</link>
		<dc:creator>0-day wordpress vulnerability results in many Media Temple malware infections - WordPress Tavern Forum</dc:creator>
		<pubDate>Tue, 02 Mar 2010 22:19:59 +0000</pubDate>
		<guid isPermaLink="false">http://vinhboy.com/?p=757#comment-12037</guid>
		<description>[...] via his github gist post, and he directed me to his blog post, which has some technical details:  http://vinhboy.com/blog/2010/03/01/w...-by-inii-info/  We exchanged a few emails, and discovered that there were easily dozens of sites affected by this [...]</description>
		<content:encoded><![CDATA[<p>[...] via his github gist post, and he directed me to his blog post, which has some technical details:  <a href="http://vinhboy.com/blog/2010/03/01/w...-by-inii-info/" rel="nofollow">http://vinhboy.com/blog/2010/03/01/w&#8230;-by-inii-info/</a>  We exchanged a few emails, and discovered that there were easily dozens of sites affected by this [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: frank farmer</title>
		<link>http://vinhboy.com/blog/2010/03/01/wordpress-hacked-by-inii-info/#comment-12030</link>
		<dc:creator>frank farmer</dc:creator>
		<pubDate>Tue, 02 Mar 2010 20:09:17 +0000</pubDate>
		<guid isPermaLink="false">http://vinhboy.com/?p=757#comment-12030</guid>
		<description>Wordpress.org deleted my post on this subject.  Here are some examples of the infection in the wild:

http://www.google.com/search?sourceid=chrome&amp;ie=UTF-8&amp;q=site:newlife.id.au+zpu.php
http://www.google.com/search?sourceid=chrome&amp;ie=UTF-8&amp;q=site:jedcohen.com+yriji.php
http://www.google.com/search?sourceid=chrome&amp;ie=UTF-8&amp;q=site:bostonmassduilawyer.com+ypi.php
http://www.google.com/search?sourceid=chrome&amp;ie=UTF-8&amp;q=site:bostonmassdui.com+ypy.php
http://www.google.com/search?sourceid=chrome&amp;ie=UTF-8&amp;q=site:torschtl.de+yzidu.php
http://www.google.com/search?sourceid=chrome&amp;ie=UTF-8&amp;q=site:krippen-unikate.de+zmy.php
http://www.google.com/search?sourceid=chrome&amp;ie=UTF-8&amp;q=site:devblogger.de+xza.php
http://www.google.com/search?sourceid=chrome&amp;ie=UTF-8&amp;q=site:capital-competence.com+yguco.php
http://www.google.com/search?sourceid=chrome&amp;ie=UTF-8&amp;q=site:allaboutapple.de+ynu.php
http://www.google.com/search?sourceid=chrome&amp;ie=UTF-8&amp;q=site:benundjana.de+xnosi.php
http://www.google.com/search?sourceid=chrome&amp;ie=UTF-8&amp;q=site:sandbox.belite.de+xdyvi.php</description>
		<content:encoded><![CDATA[<p>WordPress.org deleted my post on this subject.  Here are some examples of the infection in the wild:</p>
<p><a href="http://www.google.com/search?sourceid=chrome&#038;ie=UTF-8&#038;q=site:newlife.id.au+zpu.php" rel="nofollow">http://www.google.com/search?sourceid=chrome&#038;ie=UTF-8&#038;q=site:newlife.id.au+zpu.php</a><br />
<a href="http://www.google.com/search?sourceid=chrome&#038;ie=UTF-8&#038;q=site:jedcohen.com+yriji.php" rel="nofollow">http://www.google.com/search?sourceid=chrome&#038;ie=UTF-8&#038;q=site:jedcohen.com+yriji.php</a><br />
<a href="http://www.google.com/search?sourceid=chrome&#038;ie=UTF-8&#038;q=site:bostonmassduilawyer.com+ypi.php" rel="nofollow">http://www.google.com/search?sourceid=chrome&#038;ie=UTF-8&#038;q=site:bostonmassduilawyer.com+ypi.php</a><br />
<a href="http://www.google.com/search?sourceid=chrome&#038;ie=UTF-8&#038;q=site:bostonmassdui.com+ypy.php" rel="nofollow">http://www.google.com/search?sourceid=chrome&#038;ie=UTF-8&#038;q=site:bostonmassdui.com+ypy.php</a><br />
<a href="http://www.google.com/search?sourceid=chrome&#038;ie=UTF-8&#038;q=site:torschtl.de+yzidu.php" rel="nofollow">http://www.google.com/search?sourceid=chrome&#038;ie=UTF-8&#038;q=site:torschtl.de+yzidu.php</a><br />
<a href="http://www.google.com/search?sourceid=chrome&#038;ie=UTF-8&#038;q=site:krippen-unikate.de+zmy.php" rel="nofollow">http://www.google.com/search?sourceid=chrome&#038;ie=UTF-8&#038;q=site:krippen-unikate.de+zmy.php</a><br />
<a href="http://www.google.com/search?sourceid=chrome&#038;ie=UTF-8&#038;q=site:devblogger.de+xza.php" rel="nofollow">http://www.google.com/search?sourceid=chrome&#038;ie=UTF-8&#038;q=site:devblogger.de+xza.php</a><br />
<a href="http://www.google.com/search?sourceid=chrome&#038;ie=UTF-8&#038;q=site:capital-competence.com+yguco.php" rel="nofollow">http://www.google.com/search?sourceid=chrome&#038;ie=UTF-8&#038;q=site:capital-competence.com+yguco.php</a><br />
<a href="http://www.google.com/search?sourceid=chrome&#038;ie=UTF-8&#038;q=site:allaboutapple.de+ynu.php" rel="nofollow">http://www.google.com/search?sourceid=chrome&#038;ie=UTF-8&#038;q=site:allaboutapple.de+ynu.php</a><br />
<a href="http://www.google.com/search?sourceid=chrome&#038;ie=UTF-8&#038;q=site:benundjana.de+xnosi.php" rel="nofollow">http://www.google.com/search?sourceid=chrome&#038;ie=UTF-8&#038;q=site:benundjana.de+xnosi.php</a><br />
<a href="http://www.google.com/search?sourceid=chrome&#038;ie=UTF-8&#038;q=site:sandbox.belite.de+xdyvi.php" rel="nofollow">http://www.google.com/search?sourceid=chrome&#038;ie=UTF-8&#038;q=site:sandbox.belite.de+xdyvi.php</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>

