<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: WordPress Site Hacked With URL Encoded Javascript document.write</title>
	<atom:link href="http://i.nconspicuo.us/2010/02/04/wordpress-site-hacked-with-url-encoded-javascript-document-write/feed/" rel="self" type="application/rss+xml" />
	<link>http://i.nconspicuo.us/2010/02/04/wordpress-site-hacked-with-url-encoded-javascript-document-write/</link>
	<description>Uncovering the hidden treasures of the internet, tech toys... and life.</description>
	<lastBuildDate>Fri, 10 Sep 2010 07:41:21 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: edelbug</title>
		<link>http://i.nconspicuo.us/2010/02/04/wordpress-site-hacked-with-url-encoded-javascript-document-write/comment-page-1/#comment-233770</link>
		<dc:creator>edelbug</dc:creator>
		<pubDate>Wed, 17 Feb 2010 04:54:52 +0000</pubDate>
		<guid isPermaLink="false">http://i.nconspicuo.us/?p=435#comment-233770</guid>
		<description>Yeah guys I am hosted with godaddy and I had the same issue.  My guess is that its either a wordpress hole or your passwords like mine were not as strong as they should have been.  I had a whole slew of &quot;users&quot; that were clearly fakes and one of them was magically an administrator.  I deleted all those accounts including the administrator one.  Then I edited the header.php file and removed that encoded javascript junk.  I am going to monitor it closely for a few days.

spicuo.us what kind of site are you running getting $30+ a day in ad revenue.  Man I would love to see that kind of income. I am lucky to see around $30 in a two week span!</description>
		<content:encoded><![CDATA[<p>Yeah guys I am hosted with godaddy and I had the same issue.  My guess is that its either a wordpress hole or your passwords like mine were not as strong as they should have been.  I had a whole slew of &#8220;users&#8221; that were clearly fakes and one of them was magically an administrator.  I deleted all those accounts including the administrator one.  Then I edited the header.php file and removed that encoded javascript junk.  I am going to monitor it closely for a few days.</p>
<p>spicuo.us what kind of site are you running getting $30+ a day in ad revenue.  Man I would love to see that kind of income. I am lucky to see around $30 in a two week span!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: i.nconspicuo.us</title>
		<link>http://i.nconspicuo.us/2010/02/04/wordpress-site-hacked-with-url-encoded-javascript-document-write/comment-page-1/#comment-233710</link>
		<dc:creator>i.nconspicuo.us</dc:creator>
		<pubDate>Tue, 16 Feb 2010 17:03:53 +0000</pubDate>
		<guid isPermaLink="false">http://i.nconspicuo.us/?p=435#comment-233710</guid>
		<description>I&#039;m wondering how they got access too. According to Sam&#039;s comment above, it may have been from a 3rd party ad network. I&#039;m wondering if the Kontera links that I was using were somehow compromised?

Either way,  I lost about $75 in revenue over the 2 days that this was happening. Not cool.</description>
		<content:encoded><![CDATA[<p>I&#8217;m wondering how they got access too. According to Sam&#8217;s comment above, it may have been from a 3rd party ad network. I&#8217;m wondering if the Kontera links that I was using were somehow compromised?</p>
<p>Either way,  I lost about $75 in revenue over the 2 days that this was happening. Not cool.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brian Lyssy</title>
		<link>http://i.nconspicuo.us/2010/02/04/wordpress-site-hacked-with-url-encoded-javascript-document-write/comment-page-1/#comment-233603</link>
		<dc:creator>Brian Lyssy</dc:creator>
		<pubDate>Mon, 15 Feb 2010 22:12:46 +0000</pubDate>
		<guid isPermaLink="false">http://i.nconspicuo.us/?p=435#comment-233603</guid>
		<description>The same thing happened to me except it didn&#039;t take 15 seconds to redirect.  It was more like right away.  It seemed like each time the script would send to another .net site that was all about ads.  I did capture two ip addresses.  89.207.130.72 and 208.94.233.33 seemed to show up quite consistently.  I am wondering how these jerks got access to my site.  There has to be some kind of security hole because I am the only one that knows my passwords.

One more thing.  My hosting is with hostgator and they reported that they removed the problem file.  They reported that this file /2009/09/28788.php had gotten uploaded to my account.  One thing they did not check was the associate database entries for wordpress.  The hacker added themselves as an administrator to the site.  You might not see it in the wp-admin area but you can look at the users entries in the database.  I would suggest removing asap and keep checking to make sure they don&#039;t have a backdoor script running.</description>
		<content:encoded><![CDATA[<p>The same thing happened to me except it didn&#8217;t take 15 seconds to redirect.  It was more like right away.  It seemed like each time the script would send to another .net site that was all about ads.  I did capture two ip addresses.  89.207.130.72 and 208.94.233.33 seemed to show up quite consistently.  I am wondering how these jerks got access to my site.  There has to be some kind of security hole because I am the only one that knows my passwords.</p>
<p>One more thing.  My hosting is with hostgator and they reported that they removed the problem file.  They reported that this file /2009/09/28788.php had gotten uploaded to my account.  One thing they did not check was the associate database entries for wordpress.  The hacker added themselves as an administrator to the site.  You might not see it in the wp-admin area but you can look at the users entries in the database.  I would suggest removing asap and keep checking to make sure they don&#8217;t have a backdoor script running.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sam</title>
		<link>http://i.nconspicuo.us/2010/02/04/wordpress-site-hacked-with-url-encoded-javascript-document-write/comment-page-1/#comment-232930</link>
		<dc:creator>sam</dc:creator>
		<pubDate>Wed, 10 Feb 2010 17:05:04 +0000</pubDate>
		<guid isPermaLink="false">http://i.nconspicuo.us/?p=435#comment-232930</guid>
		<description>same here man. I think watch out of those banners servered with scripts. They may also have those too.</description>
		<content:encoded><![CDATA[<p>same here man. I think watch out of those banners servered with scripts. They may also have those too.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
