<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: My Blog Hacked, Yet Again &#8211; Wordpress 2.6.5 Vulnerability / Exploit?</title>
	<atom:link href="http://smackdown.blogsblogsblogs.com/2009/01/16/my-blog-hacked-yet-again-wordpress-265-vulnerability-exploit/feed/" rel="self" type="application/rss+xml" />
	<link>http://smackdown.blogsblogsblogs.com/2009/01/16/my-blog-hacked-yet-again-wordpress-265-vulnerability-exploit/</link>
	<description>Smackdown!</description>
	<lastBuildDate>Sun, 14 Mar 2010 13:52:01 -0500</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Tony</title>
		<link>http://smackdown.blogsblogsblogs.com/2009/01/16/my-blog-hacked-yet-again-wordpress-265-vulnerability-exploit/comment-page-1/#comment-33725</link>
		<dc:creator>Tony</dc:creator>
		<pubDate>Sat, 06 Feb 2010 02:05:15 +0000</pubDate>
		<guid isPermaLink="false">http://smackdown.blogsblogsblogs.com/?p=218#comment-33725</guid>
		<description>Why is this world so unjust? Can&#039;t hackers just leave WordPress bloggers and other sites alone and find something else to do?</description>
		<content:encoded><![CDATA[<p>Why is this world so unjust? Can&#8217;t hackers just leave WordPress bloggers and other sites alone and find something else to do?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John</title>
		<link>http://smackdown.blogsblogsblogs.com/2009/01/16/my-blog-hacked-yet-again-wordpress-265-vulnerability-exploit/comment-page-1/#comment-20266</link>
		<dc:creator>John</dc:creator>
		<pubDate>Fri, 19 Jun 2009 16:35:54 +0000</pubDate>
		<guid isPermaLink="false">http://smackdown.blogsblogsblogs.com/?p=218#comment-20266</guid>
		<description>I&#039;ve experienced the same thing. First learned of it when Google e-mailed to tell me they were going to delist me because of spam on my site. I was running. 2.7.1 at the time. I upgraded to 2.8 using the WP based upgrade (not a clean wipe). The span was gone. Then yesterday it reappeared. Different ads but clearly the same exploit. I have tried disabling all plugins to no avail. Since it went away after an upgrade, it&#039;s pretty clear this is a WP problem, but I can&#039;t find the script that&#039;s doing it.

Any help would be greatly appreciated.</description>
		<content:encoded><![CDATA[<p>I&#8217;ve experienced the same thing. First learned of it when Google e-mailed to tell me they were going to delist me because of spam on my site. I was running. 2.7.1 at the time. I upgraded to 2.8 using the WP based upgrade (not a clean wipe). The span was gone. Then yesterday it reappeared. Different ads but clearly the same exploit. I have tried disabling all plugins to no avail. Since it went away after an upgrade, it&#8217;s pretty clear this is a WP problem, but I can&#8217;t find the script that&#8217;s doing it.</p>
<p>Any help would be greatly appreciated.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Will</title>
		<link>http://smackdown.blogsblogsblogs.com/2009/01/16/my-blog-hacked-yet-again-wordpress-265-vulnerability-exploit/comment-page-1/#comment-11088</link>
		<dc:creator>Will</dc:creator>
		<pubDate>Tue, 03 Feb 2009 17:04:39 +0000</pubDate>
		<guid isPermaLink="false">http://smackdown.blogsblogsblogs.com/?p=218#comment-11088</guid>
		<description>No prob.  I would definitely like to know what the vulnerability is.</description>
		<content:encoded><![CDATA[<p>No prob.  I would definitely like to know what the vulnerability is.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael VanDeMar</title>
		<link>http://smackdown.blogsblogsblogs.com/2009/01/16/my-blog-hacked-yet-again-wordpress-265-vulnerability-exploit/comment-page-1/#comment-11056</link>
		<dc:creator>Michael VanDeMar</dc:creator>
		<pubDate>Tue, 03 Feb 2009 06:01:58 +0000</pubDate>
		<guid isPermaLink="false">http://smackdown.blogsblogsblogs.com/?p=218#comment-11056</guid>
		<description>Well, Will, that would appear to be because I was hacked again, this time with WP 2.7.

Thanks for the heads up.</description>
		<content:encoded><![CDATA[<p>Well, Will, that would appear to be because I was hacked again, this time with WP 2.7.</p>
<p>Thanks for the heads up.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Will</title>
		<link>http://smackdown.blogsblogsblogs.com/2009/01/16/my-blog-hacked-yet-again-wordpress-265-vulnerability-exploit/comment-page-1/#comment-11055</link>
		<dc:creator>Will</dc:creator>
		<pubDate>Tue, 03 Feb 2009 05:57:57 +0000</pubDate>
		<guid isPermaLink="false">http://smackdown.blogsblogsblogs.com/?p=218#comment-11055</guid>
		<description>I&#039;m still seeing the spammy links when I look at the cached text version of the page, and it was last cached on February 2nd. Why would that be?</description>
		<content:encoded><![CDATA[<p>I&#8217;m still seeing the spammy links when I look at the cached text version of the page, and it was last cached on February 2nd. Why would that be?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jaimie Sirovich</title>
		<link>http://smackdown.blogsblogsblogs.com/2009/01/16/my-blog-hacked-yet-again-wordpress-265-vulnerability-exploit/comment-page-1/#comment-10567</link>
		<dc:creator>Jaimie Sirovich</dc:creator>
		<pubDate>Tue, 20 Jan 2009 02:36:08 +0000</pubDate>
		<guid isPermaLink="false">http://smackdown.blogsblogsblogs.com/?p=218#comment-10567</guid>
		<description>Check out WordPress Firewall: http://www.seoegghead.com/blog/seo/stop-hackers-with-our-wordpress-firewall-plugin-v12-p544.html

Let me know if you want me to look into it.  Many plugins _do_ totally suck from a security standpoint, but you say it wasn&#039;t a plugin.  Hrm.  Do you have logs?

Look at Matt&#039;s comment on this below blog post ... and the other comments.  I think Anil is totally unfair, but he has a point.

http://www.movabletype.com/blog/2008/06/movable-type-a-history-of-secu.html</description>
		<content:encoded><![CDATA[<p>Check out WordPress Firewall: <a href="http://www.seoegghead.com/blog/seo/stop-hackers-with-our-wordpress-firewall-plugin-v12-p544.html" rel="nofollow">http://www.seoegghead.com/blog.....-p544.html</a></p>
<p>Let me know if you want me to look into it.  Many plugins _do_ totally suck from a security standpoint, but you say it wasn&#8217;t a plugin.  Hrm.  Do you have logs?</p>
<p>Look at Matt&#8217;s comment on this below blog post &#8230; and the other comments.  I think Anil is totally unfair, but he has a point.</p>
<p><a href="http://www.movabletype.com/blog/2008/06/movable-type-a-history-of-secu.html" rel="nofollow">http://www.movabletype.com/blo.....-secu.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: john a</title>
		<link>http://smackdown.blogsblogsblogs.com/2009/01/16/my-blog-hacked-yet-again-wordpress-265-vulnerability-exploit/comment-page-1/#comment-10566</link>
		<dc:creator>john a</dc:creator>
		<pubDate>Tue, 20 Jan 2009 01:18:39 +0000</pubDate>
		<guid isPermaLink="false">http://smackdown.blogsblogsblogs.com/?p=218#comment-10566</guid>
		<description>same thing happend to me. was on 2.6.5 i think too.

wordpress forums are pretty useless for help ans it is never wp&#039;s fault (yet they find some reason to release an update every other week).

lost my serp&#039;s too. damn ...</description>
		<content:encoded><![CDATA[<p>same thing happend to me. was on 2.6.5 i think too.</p>
<p>wordpress forums are pretty useless for help ans it is never wp&#8217;s fault (yet they find some reason to release an update every other week).</p>
<p>lost my serp&#8217;s too. damn &#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael VanDeMar</title>
		<link>http://smackdown.blogsblogsblogs.com/2009/01/16/my-blog-hacked-yet-again-wordpress-265-vulnerability-exploit/comment-page-1/#comment-10564</link>
		<dc:creator>Michael VanDeMar</dc:creator>
		<pubDate>Sat, 17 Jan 2009 17:08:30 +0000</pubDate>
		<guid isPermaLink="false">http://smackdown.blogsblogsblogs.com/?p=218#comment-10564</guid>
		<description>I did check the plugins. I found sites that were exposed to the same hack I was that had none of the plugins I was using. Every time I have been hacked before it was the Wordpress software itself that was the problem, so that is my strongest suspicion. To date, to the best of my knowledge, there has not been a release that an exploit was not found for, at least up until 2.6.5 supposedly. Check out here:
http://blogsecurity.net/wordpress/blogwatch/blogwatch/
and here:
http://blogsecurity.net/wordpress/wordpress-262-snoopy-vulnerability/
and here:
http://blogsecurity.net/wordpress/wordpress/

As I mentioned in the post, mine was the only blog I found running 2.6.5 that was infected, but I was checking manually, and checked less than 100 blogs. I might do some more in-depth research later and see if I can dig up more info on it.</description>
		<content:encoded><![CDATA[<p>I did check the plugins. I found sites that were exposed to the same hack I was that had none of the plugins I was using. Every time I have been hacked before it was the Wordpress software itself that was the problem, so that is my strongest suspicion. To date, to the best of my knowledge, there has not been a release that an exploit was not found for, at least up until 2.6.5 supposedly. Check out here:<br />
<a href="http://blogsecurity.net/wordpress/blogwatch/blogwatch/" rel="nofollow">http://blogsecurity.net/wordpr.....blogwatch/</a><br />
and here:<br />
<a href="http://blogsecurity.net/wordpress/wordpress-262-snoopy-vulnerability/" rel="nofollow">http://blogsecurity.net/wordpr.....erability/</a><br />
and here:<br />
<a href="http://blogsecurity.net/wordpress/wordpress/" rel="nofollow">http://blogsecurity.net/wordpress/wordpress/</a></p>
<p>As I mentioned in the post, mine was the only blog I found running 2.6.5 that was infected, but I was checking manually, and checked less than 100 blogs. I might do some more in-depth research later and see if I can dig up more info on it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Proxy Blog</title>
		<link>http://smackdown.blogsblogsblogs.com/2009/01/16/my-blog-hacked-yet-again-wordpress-265-vulnerability-exploit/comment-page-1/#comment-10563</link>
		<dc:creator>Proxy Blog</dc:creator>
		<pubDate>Sat, 17 Jan 2009 16:41:30 +0000</pubDate>
		<guid isPermaLink="false">http://smackdown.blogsblogsblogs.com/?p=218#comment-10563</guid>
		<description>Hi,

There are lots of ways that you could have been hacked even if the hack wasn&#039;t via the WP &quot;software&quot; itself. Maybe somone got your blog admin or even your ftp login via a previous hack - you should change those. Another possibility is that you had/have a plugin with some sort of vulnerability eg there&#039;s a vulnerability in a popular Adsense plugin.</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>There are lots of ways that you could have been hacked even if the hack wasn&#8217;t via the WP &#8220;software&#8221; itself. Maybe somone got your blog admin or even your ftp login via a previous hack &#8211; you should change those. Another possibility is that you had/have a plugin with some sort of vulnerability eg there&#8217;s a vulnerability in a popular Adsense plugin.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
