<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: Nice Exploit Code I Found in my Wordpress</title>
	<atom:link href="http://www.dellanave.com/blog/2008/03/10/nice-exploit-code-i-found-in-my-wordpress/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.dellanave.com/blog/2008/03/10/nice-exploit-code-i-found-in-my-wordpress/</link>
	<description>The third attempt</description>
	<pubDate>Wed, 19 Nov 2008 22:48:18 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7-almost-beta-9300</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: My Wordpress Blog Got Hacked Right Next To Matt Mullenweg : Purposeinc</title>
		<link>http://www.dellanave.com/blog/2008/03/10/nice-exploit-code-i-found-in-my-wordpress/#comment-71507</link>
		<dc:creator>My Wordpress Blog Got Hacked Right Next To Matt Mullenweg : Purposeinc</dc:creator>
		<pubDate>Tue, 08 Apr 2008 08:14:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.dellanave.com/blog/2008/03/10/nice-exploit-code-i-found-in-my-wordpress/#comment-71507</guid>
		<description>[...] looked over to my right, and there was Dave Dellanave, Shoemoney&#8217;s ace programmer sitting 3 feet across the isle from me banging away on the keys creating fighters.com their new [...]</description>
		<content:encoded><![CDATA[<p>[...] looked over to my right, and there was Dave Dellanave, Shoemoney&#8217;s ace programmer sitting 3 feet across the isle from me banging away on the keys creating fighters.com their new [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike Peters</title>
		<link>http://www.dellanave.com/blog/2008/03/10/nice-exploit-code-i-found-in-my-wordpress/#comment-71414</link>
		<dc:creator>Mike Peters</dc:creator>
		<pubDate>Tue, 11 Mar 2008 15:21:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.dellanave.com/blog/2008/03/10/nice-exploit-code-i-found-in-my-wordpress/#comment-71414</guid>
		<description>So true :-)</description>
		<content:encoded><![CDATA[<p>So true <img src='http://www.dellanave.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: david</title>
		<link>http://www.dellanave.com/blog/2008/03/10/nice-exploit-code-i-found-in-my-wordpress/#comment-71413</link>
		<dc:creator>david</dc:creator>
		<pubDate>Tue, 11 Mar 2008 15:02:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.dellanave.com/blog/2008/03/10/nice-exploit-code-i-found-in-my-wordpress/#comment-71413</guid>
		<description>If you run Windows ;)</description>
		<content:encoded><![CDATA[<p>If you run Windows <img src='http://www.dellanave.com/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike Peters</title>
		<link>http://www.dellanave.com/blog/2008/03/10/nice-exploit-code-i-found-in-my-wordpress/#comment-71412</link>
		<dc:creator>Mike Peters</dc:creator>
		<pubDate>Tue, 11 Mar 2008 14:42:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.dellanave.com/blog/2008/03/10/nice-exploit-code-i-found-in-my-wordpress/#comment-71412</guid>
		<description>This code got sql injected into your wp_posts.  

Make sure you upgrade to the 2.3.2 version of WordPress:
http://wordpress.org/support/topic/151888

What it does is attempt to install a VBS malware on your machine using an xmlrpc exploit in older versions of WordPress. 

Look for something like this in your server logs -

200.216.67.181 - - [28/Jan/2008:13:10:54 -0500] "POST /xmlrpc.php HTTP/1.0" 

Once you view the post, you're infected - the VBS code will be installed and you're going to need to run NOD32 or AVG to clean it up</description>
		<content:encoded><![CDATA[<p>This code got sql injected into your wp_posts.  </p>
<p>Make sure you upgrade to the 2.3.2 version of WordPress:<br />
<a href="http://wordpress.org/support/topic/151888" rel="nofollow">http://wordpress.org/support/topic/151888</a></p>
<p>What it does is attempt to install a VBS malware on your machine using an xmlrpc exploit in older versions of WordPress. </p>
<p>Look for something like this in your server logs -</p>
<p>200.216.67.181 - - [28/Jan/2008:13:10:54 -0500] &#8220;POST /xmlrpc.php HTTP/1.0&#8243; </p>
<p>Once you view the post, you&#8217;re infected - the VBS code will be installed and you&#8217;re going to need to run NOD32 or AVG to clean it up</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: david</title>
		<link>http://www.dellanave.com/blog/2008/03/10/nice-exploit-code-i-found-in-my-wordpress/#comment-71410</link>
		<dc:creator>david</dc:creator>
		<pubDate>Mon, 10 Mar 2008 19:20:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.dellanave.com/blog/2008/03/10/nice-exploit-code-i-found-in-my-wordpress/#comment-71410</guid>
		<description>Yeah thats a start but it will take a bit more work to figure out exactly what it does.</description>
		<content:encoded><![CDATA[<p>Yeah thats a start but it will take a bit more work to figure out exactly what it does.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Josh</title>
		<link>http://www.dellanave.com/blog/2008/03/10/nice-exploit-code-i-found-in-my-wordpress/#comment-71409</link>
		<dc:creator>Josh</dc:creator>
		<pubDate>Mon, 10 Mar 2008 18:33:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.dellanave.com/blog/2008/03/10/nice-exploit-code-i-found-in-my-wordpress/#comment-71409</guid>
		<description>Try this out for a fellow lazy bum.  :-)

Allows you to cut and paste encoded/decoded stuff for javascript.

http://www.the-art-of-web.com/javascript/escape/</description>
		<content:encoded><![CDATA[<p>Try this out for a fellow lazy bum.  <img src='http://www.dellanave.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>Allows you to cut and paste encoded/decoded stuff for javascript.</p>
<p><a href="http://www.the-art-of-web.com/javascript/escape/" rel="nofollow">http://www.the-art-of-web.com/javascript/escape/</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>
