<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>mikesoh.com &#187; wordpress</title>
	<atom:link href="http://www.mikesoh.com/tag/wordpress/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.mikesoh.com</link>
	<description>conservative thoughts on a liberal world</description>
	<lastBuildDate>Wed, 21 Jul 2010 13:30:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=abc</generator>
		<item>
		<title>mikesoh.com was hacked!!</title>
		<link>http://www.mikesoh.com/2009/04/mikesohcom-was-hacked/</link>
		<comments>http://www.mikesoh.com/2009/04/mikesohcom-was-hacked/#comments</comments>
		<pubDate>Wed, 15 Apr 2009 22:39:51 +0000</pubDate>
		<dc:creator>mike</dc:creator>
				<category><![CDATA[Announcements]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[injection]]></category>
		<category><![CDATA[theme]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://www.mikesoh.com/?p=241</guid>
		<description><![CDATA[Due to an unknown security vulnerability, mikesoh.com was down for about 14 hours.  Feeds were unaffected and I haven&#8217;t seen any real damage to the site.  My sister site was not affected at all. I&#8217;m still sorting out the details of the hack but what I&#8217;ve gathered so far is that the hacker was able [...]]]></description>
			<content:encoded><![CDATA[<p>Due to an unknown security vulnerability, mikesoh.com was down for about 14 hours.  Feeds were unaffected and I haven&#8217;t seen any real damage to the site.  My sister site was not affected at all.</p>
<p>I&#8217;m still sorting out the details of the hack but what I&#8217;ve gathered so far is that the hacker was able to overwrite the theme I have selected.  I believe that this is a wordpress vulnerability, but I&#8217;m looking into the posibility that it may not be.</p>
<p>After a quick search, <a href="http://practicethis.com/" target="_blank">another site</a> was hit with the <a href="http://practicethis.com/2009/04/15/protect-your-blog-or-get-hacked-like-practicethiscom-was/" target="_blank">same exact hack</a>.  He is also using WordPress, but he also uses the same hosting service.</p>
<p><span id="more-241"></span>The hack read &#8220;Security Z3ro&#8221; and had a weird picture (guessing middle-eastern) and played a RealMedia clip named <strong>es350.ram</strong>.  The biggest security issue was the image that it displayed.  For those of you who aren&#8217;t webmasters, any time you download anything from the internet, whether it&#8217;s a file, web page, image, movie, picture, etc, your IP address is recorded on the server.  This is done usually for statistical purposes.  But for someone who wants to wreck havoc, an IP address can be used to compromise your personal computer.</p>
<p>I&#8217;m guessing that the hack was taking advantage of a WP vulnerability since the attack only compromised the themes.  Upon inspection of the theme files, I noticed one of them was updated recently:</p>
<p><img class="aligncenter size-full wp-image-243" title="ls-l" src="http://www.mikesoh.com/wp-content/uploads/2009/04/ls-l.png" alt="ls-l" width="585" height="447" />Pay particular attention to index.php.  Note the utime (update time).  Once I had the date and time, I went into my logs to see who was on my website during that time.  Thankfully, I didn&#8217;t have too many visiters at 11:30pm.  I soon found out that the hacker is either located or used a proxy server in Syria.  In either case, I can&#8217;t issue a subpoena to a foreign country to find out who did this.  But in the mean time, I have blocked his entire subnet from ever reaching my site again.</p>
<p>The offending IP address is 91.144.1.41.  Feel free to add this IP address to any of your filters.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mikesoh.com/2009/04/mikesohcom-was-hacked/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
