<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.3.3" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: New hacking attempt</title>
	<link>http://alexrabe.boelinger.com/2008/02/18/new-hacking-attempt/</link>
	<description>ALEX RABE &#124; learning by doing...</description>
	<pubDate>Fri, 25 Jul 2008 11:06:23 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.3</generator>
		<item>
		<title>By: Jenny</title>
		<link>http://alexrabe.boelinger.com/2008/02/18/new-hacking-attempt/#comment-5975</link>
		<dc:creator>Jenny</dc:creator>
		<pubDate>Sun, 02 Mar 2008 15:40:49 +0000</pubDate>
		<guid>http://alexrabe.boelinger.com/2008/02/18/new-hacking-attempt/#comment-5975</guid>
		<description>when I changed to thickbox it seems to work, but I am afraid something could have happend to my db. How can I check?

Please send me an email and I will give you the address to my site.

Thanks for your help,
Jenny</description>
		<content:encoded><![CDATA[<p>when I changed to thickbox it seems to work, but I am afraid something could have happend to my db. How can I check?</p>
<p>Please send me an email and I will give you the address to my site.</p>
<p>Thanks for your help,<br />
Jenny</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: alex.rabe</title>
		<link>http://alexrabe.boelinger.com/2008/02/18/new-hacking-attempt/#comment-5971</link>
		<dc:creator>alex.rabe</dc:creator>
		<pubDate>Sat, 01 Mar 2008 16:22:20 +0000</pubDate>
		<guid>http://alexrabe.boelinger.com/2008/02/18/new-hacking-attempt/#comment-5971</guid>
		<description>@Jamas
keep in your mind that I'm not free for failure, good luck...

@Jenny 
Give me a link to your page</description>
		<content:encoded><![CDATA[<p>@Jamas<br />
keep in your mind that I&#8217;m not free for failure, good luck&#8230;</p>
<p>@Jenny<br />
Give me a link to your page</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jamas</title>
		<link>http://alexrabe.boelinger.com/2008/02/18/new-hacking-attempt/#comment-5970</link>
		<dc:creator>Jamas</dc:creator>
		<pubDate>Sat, 01 Mar 2008 16:09:13 +0000</pubDate>
		<guid>http://alexrabe.boelinger.com/2008/02/18/new-hacking-attempt/#comment-5970</guid>
		<description>Hey Alex,

Well so far NextGEN Gallery is holding up much better then WPPA to hack attempts. The site slsc.ca which I admin was hacked twice in the last week. 

The first time they managed to replace all the files in my active theme.  Mostly my fault as I had the folder permissions and file permissions wide open on that page.  

However the second time they managed to insert a post into the site and replace the contents of several pages. I noticed that my stats show search hits for: 'allinurl: page_id album "photo"' which is a WPPA format for pages.  They then managed to upload a .zip file into the uploads directory. The some how managed to unzip it which must then have given them access to the site.  Still trying to sort out all the details. 

So I am going to try an experiment.  Patch the site back up (clean copy of all wordpress files (just in case they managed to change anything). Remove WPPA  and install NextGEN Gallery.  The site slsc.ca now shows up on their hacking forum so will see if they managed to get in using NextGEN.  I will let you know the results. 

Jamas</description>
		<content:encoded><![CDATA[<p>Hey Alex,</p>
<p>Well so far NextGEN Gallery is holding up much better then WPPA to hack attempts. The site slsc.ca which I admin was hacked twice in the last week. </p>
<p>The first time they managed to replace all the files in my active theme.  Mostly my fault as I had the folder permissions and file permissions wide open on that page.  </p>
<p>However the second time they managed to insert a post into the site and replace the contents of several pages. I noticed that my stats show search hits for: &#8216;allinurl: page_id album &#8220;photo&#8221;&#8216; which is a WPPA format for pages.  They then managed to upload a .zip file into the uploads directory. The some how managed to unzip it which must then have given them access to the site.  Still trying to sort out all the details. </p>
<p>So I am going to try an experiment.  Patch the site back up (clean copy of all wordpress files (just in case they managed to change anything). Remove WPPA  and install NextGEN Gallery.  The site slsc.ca now shows up on their hacking forum so will see if they managed to get in using NextGEN.  I will let you know the results. </p>
<p>Jamas</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jenny</title>
		<link>http://alexrabe.boelinger.com/2008/02/18/new-hacking-attempt/#comment-5968</link>
		<dc:creator>Jenny</dc:creator>
		<pubDate>Sat, 01 Mar 2008 12:08:12 +0000</pubDate>
		<guid>http://alexrabe.boelinger.com/2008/02/18/new-hacking-attempt/#comment-5968</guid>
		<description>Guess my site has been hacked as well. When you click at one of my pictures the lightbox doesnt appear anymore, the picture appears in the browser instead.
Where do I find log files and what to do?
Thanks for your help
J</description>
		<content:encoded><![CDATA[<p>Guess my site has been hacked as well. When you click at one of my pictures the lightbox doesnt appear anymore, the picture appears in the browser instead.<br />
Where do I find log files and what to do?<br />
Thanks for your help<br />
J</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike</title>
		<link>http://alexrabe.boelinger.com/2008/02/18/new-hacking-attempt/#comment-5859</link>
		<dc:creator>Mike</dc:creator>
		<pubDate>Sun, 24 Feb 2008 22:47:19 +0000</pubDate>
		<guid>http://alexrabe.boelinger.com/2008/02/18/new-hacking-attempt/#comment-5859</guid>
		<description>Oh.. I wanna use it or some Flickr plugin, I dont know yet.
Your gallery looks nice though.

Greetings.
/Mike</description>
		<content:encoded><![CDATA[<p>Oh.. I wanna use it or some Flickr plugin, I dont know yet.<br />
Your gallery looks nice though.</p>
<p>Greetings.<br />
/Mike</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: alex.rabe</title>
		<link>http://alexrabe.boelinger.com/2008/02/18/new-hacking-attempt/#comment-5854</link>
		<dc:creator>alex.rabe</dc:creator>
		<pubDate>Sun, 24 Feb 2008 18:35:24 +0000</pubDate>
		<guid>http://alexrabe.boelinger.com/2008/02/18/new-hacking-attempt/#comment-5854</guid>
		<description>I must be quite honestly say : I don't know</description>
		<content:encoded><![CDATA[<p>I must be quite honestly say : I don&#8217;t know</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike</title>
		<link>http://alexrabe.boelinger.com/2008/02/18/new-hacking-attempt/#comment-5853</link>
		<dc:creator>Mike</dc:creator>
		<pubDate>Sun, 24 Feb 2008 18:07:01 +0000</pubDate>
		<guid>http://alexrabe.boelinger.com/2008/02/18/new-hacking-attempt/#comment-5853</guid>
		<description>I got to ask you :)
NextGen Gallery, is it secure?

Greetings.
/Mike</description>
		<content:encoded><![CDATA[<p>I got to ask you <img src='http://alexrabe.boelinger.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
NextGen Gallery, is it secure?</p>
<p>Greetings.<br />
/Mike</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike</title>
		<link>http://alexrabe.boelinger.com/2008/02/18/new-hacking-attempt/#comment-5818</link>
		<dc:creator>Mike</dc:creator>
		<pubDate>Fri, 22 Feb 2008 12:35:29 +0000</pubDate>
		<guid>http://alexrabe.boelinger.com/2008/02/18/new-hacking-attempt/#comment-5818</guid>
		<description>Thanks Alex.

Yeah youre absolutely right. I will do all necessary actions to secure my wordpress.

I have decided to hack the hackers forum + all their sites.
I just can't sit back and pretend it never happened.
Like everyone else whos been hacked by them are doing..

Take care, Alex
Greetings :
/Mike</description>
		<content:encoded><![CDATA[<p>Thanks Alex.</p>
<p>Yeah youre absolutely right. I will do all necessary actions to secure my wordpress.</p>
<p>I have decided to hack the hackers forum + all their sites.<br />
I just can&#8217;t sit back and pretend it never happened.<br />
Like everyone else whos been hacked by them are doing..</p>
<p>Take care, Alex<br />
Greetings :<br />
/Mike</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: alex.rabe</title>
		<link>http://alexrabe.boelinger.com/2008/02/18/new-hacking-attempt/#comment-5816</link>
		<dc:creator>alex.rabe</dc:creator>
		<pubDate>Fri, 22 Feb 2008 08:28:22 +0000</pubDate>
		<guid>http://alexrabe.boelinger.com/2008/02/18/new-hacking-attempt/#comment-5816</guid>
		<description>Mike,

in the Web with OpenSource Application we will never be secure again. Script Kiddies are review every piece of code, and of course plugins and WordPress itself could have a leak.

So review your logifile often, keep up to date , install only plugins which you really need.</description>
		<content:encoded><![CDATA[<p>Mike,</p>
<p>in the Web with OpenSource Application we will never be secure again. Script Kiddies are review every piece of code, and of course plugins and WordPress itself could have a leak.</p>
<p>So review your logifile often, keep up to date , install only plugins which you really need.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike</title>
		<link>http://alexrabe.boelinger.com/2008/02/18/new-hacking-attempt/#comment-5813</link>
		<dc:creator>Mike</dc:creator>
		<pubDate>Fri, 22 Feb 2008 01:14:16 +0000</pubDate>
		<guid>http://alexrabe.boelinger.com/2008/02/18/new-hacking-attempt/#comment-5813</guid>
		<description>Hello.

Yes I've had two hacks, the first was just a post, the second was severe - they erased everything, and my database was mangled too.. After a search for a while thru google I found where the hackers meet and talk about my site, and how to hack it : http://www.azhack.org/forums.php?m=posts&#38;q=2486

I dont know if I can have any plugins after this.. Feels like everything is insecure..

Greetings.
/Mike</description>
		<content:encoded><![CDATA[<p>Hello.</p>
<p>Yes I&#8217;ve had two hacks, the first was just a post, the second was severe - they erased everything, and my database was mangled too.. After a search for a while thru google I found where the hackers meet and talk about my site, and how to hack it : <a href="http://www.azhack.org/forums.php?m=posts&amp;q=2486" rel="nofollow">http://www.azhack.org/forums.php?m=posts&amp;q=2486</a></p>
<p>I dont know if I can have any plugins after this.. Feels like everything is insecure..</p>
<p>Greetings.<br />
/Mike</p>
]]></content:encoded>
	</item>
</channel>
</rss>
