<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: What to do when your blog has a virus</title>
	<atom:link href="http://www.emanueleferonato.com/2009/05/01/what-to-do-when-your-blog-has-a-virus/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.emanueleferonato.com/2009/05/01/what-to-do-when-your-blog-has-a-virus/</link>
	<description>italian geek and PROgrammer</description>
	<lastBuildDate>Fri, 10 Feb 2012 12:12:29 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: aqui_c</title>
		<link>http://www.emanueleferonato.com/2009/05/01/what-to-do-when-your-blog-has-a-virus/#comment-865453</link>
		<dc:creator>aqui_c</dc:creator>
		<pubDate>Fri, 01 Jul 2011 01:45:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.emanueleferonato.com/?p=1205#comment-865453</guid>
		<description>Well, my site is now marked as &quot;harmful&quot;, but it seems as a problem with .htaccess file. I don&#039;t know HOW it was modified to redirect traffic to different sites, and it happened to ALL the blogs hosted (and even to a site that does not uses Worpress). Still investigating... But if anybody has a problem, you should check the .htaccess file in the first place.</description>
		<content:encoded><![CDATA[<p>Well, my site is now marked as &#8220;harmful&#8221;, but it seems as a problem with .htaccess file. I don&#8217;t know HOW it was modified to redirect traffic to different sites, and it happened to ALL the blogs hosted (and even to a site that does not uses Worpress). Still investigating&#8230; But if anybody has a problem, you should check the .htaccess file in the first place.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cyclone103</title>
		<link>http://www.emanueleferonato.com/2009/05/01/what-to-do-when-your-blog-has-a-virus/#comment-477228</link>
		<dc:creator>Cyclone103</dc:creator>
		<pubDate>Sat, 25 Jul 2009 21:05:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.emanueleferonato.com/?p=1205#comment-477228</guid>
		<description>My website was recently hacked, and a malicious worm file distributed itself to all my folders which had perms of at least 755, and even some which did not (idk how, and idc.)

Emanuele, I found out the creator of the script. I will not post their username here however, just in case....

The script is quite nasty, it does basically everything I am afraid of to my files.

Fortunately, it seems whoever left the files on there forgot about em and never ran it.

I have a safe backup.

Can you help me determine the cause of my getting this and how to prevent it? The file is a php one, so I saw in the comments who made it. Would simply blacklisting the script name on the server itself prevent its execution?

PLEASE email me about this, you are the best person for me to ask.</description>
		<content:encoded><![CDATA[<p>My website was recently hacked, and a malicious worm file distributed itself to all my folders which had perms of at least 755, and even some which did not (idk how, and idc.)</p>
<p>Emanuele, I found out the creator of the script. I will not post their username here however, just in case&#8230;.</p>
<p>The script is quite nasty, it does basically everything I am afraid of to my files.</p>
<p>Fortunately, it seems whoever left the files on there forgot about em and never ran it.</p>
<p>I have a safe backup.</p>
<p>Can you help me determine the cause of my getting this and how to prevent it? The file is a php one, so I saw in the comments who made it. Would simply blacklisting the script name on the server itself prevent its execution?</p>
<p>PLEASE email me about this, you are the best person for me to ask.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Albert</title>
		<link>http://www.emanueleferonato.com/2009/05/01/what-to-do-when-your-blog-has-a-virus/#comment-464182</link>
		<dc:creator>Albert</dc:creator>
		<pubDate>Mon, 22 Jun 2009 12:12:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.emanueleferonato.com/?p=1205#comment-464182</guid>
		<description>@Emanuele Feronato: Thanks for sharing... Useful tips. 

@swineinflu: No. this malicious threads will not only affect WordPress Blogs. Its main entrance in PHP. If you are using PHP in your site, It will affect your PHP codes and it will insert malicious codes. 

If your Host have good security software or Firewall in their server, no need to worry. Or otherwise You need to survive with these threads.</description>
		<content:encoded><![CDATA[<p>@Emanuele Feronato: Thanks for sharing&#8230; Useful tips. </p>
<p>@swineinflu: No. this malicious threads will not only affect WordPress Blogs. Its main entrance in PHP. If you are using PHP in your site, It will affect your PHP codes and it will insert malicious codes. </p>
<p>If your Host have good security software or Firewall in their server, no need to worry. Or otherwise You need to survive with these threads.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mattias Wirf</title>
		<link>http://www.emanueleferonato.com/2009/05/01/what-to-do-when-your-blog-has-a-virus/#comment-446031</link>
		<dc:creator>Mattias Wirf</dc:creator>
		<pubDate>Fri, 08 May 2009 07:42:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.emanueleferonato.com/?p=1205#comment-446031</guid>
		<description>@Brindy: Depends on your need, I can&#039;t stand the blogger.com where you never have full control and if you just wan&#039;t to change a little thing in layout is extremly painful. Wonder what clients would say if you told them &quot;meh, get a blogger-blog instead!&quot; ;) 

@Emanuele and others: Great tips, never had a problem so far but I&#039;m going to have an extra look through my blogs now :)</description>
		<content:encoded><![CDATA[<p>@Brindy: Depends on your need, I can&#8217;t stand the blogger.com where you never have full control and if you just wan&#8217;t to change a little thing in layout is extremly painful. Wonder what clients would say if you told them &#8220;meh, get a blogger-blog instead!&#8221; ;) </p>
<p>@Emanuele and others: Great tips, never had a problem so far but I&#8217;m going to have an extra look through my blogs now :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gecko</title>
		<link>http://www.emanueleferonato.com/2009/05/01/what-to-do-when-your-blog-has-a-virus/#comment-444870</link>
		<dc:creator>Gecko</dc:creator>
		<pubDate>Tue, 05 May 2009 15:56:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.emanueleferonato.com/?p=1205#comment-444870</guid>
		<description>My website (http://www.lizardproductions.net/) recently got a threatening message from a supposed &quot;hacker&quot; on the main page... I&#039;m only 13 years old and I don&#039;t know much about Dreamweaver, apart from how to make templates and pages and upload them to the server... Has anybody got some tips on how I might be able to prevent my site from possibly being hacked?</description>
		<content:encoded><![CDATA[<p>My website (<a href="http://www.lizardproductions.net/" rel="nofollow">http://www.lizardproductions.net/</a>) recently got a threatening message from a supposed &#8220;hacker&#8221; on the main page&#8230; I&#8217;m only 13 years old and I don&#8217;t know much about Dreamweaver, apart from how to make templates and pages and upload them to the server&#8230; Has anybody got some tips on how I might be able to prevent my site from possibly being hacked?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: whywouldyoue-mailme@spoof.wow</title>
		<link>http://www.emanueleferonato.com/2009/05/01/what-to-do-when-your-blog-has-a-virus/#comment-443973</link>
		<dc:creator>whywouldyoue-mailme@spoof.wow</dc:creator>
		<pubDate>Sun, 03 May 2009 22:24:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.emanueleferonato.com/?p=1205#comment-443973</guid>
		<description>There is a difference between a &quot;hacker&quot; and &quot;cracker&quot;. A hacker is nice person who find these &quot;bugs&quot; and &quot;loopholes&quot; top stop the evil &quot;crackers&quot; from causing damage. Why do they do it? The n00b crackers (script kiddies) do it so they can be &quot;cool&quot; and look like a &quot;pro&quot;, sadly they find the software on the net and use it XD. Please don&#039;t get the terms mixed up!</description>
		<content:encoded><![CDATA[<p>There is a difference between a &#8220;hacker&#8221; and &#8220;cracker&#8221;. A hacker is nice person who find these &#8220;bugs&#8221; and &#8220;loopholes&#8221; top stop the evil &#8220;crackers&#8221; from causing damage. Why do they do it? The n00b crackers (script kiddies) do it so they can be &#8220;cool&#8221; and look like a &#8220;pro&#8221;, sadly they find the software on the net and use it XD. Please don&#8217;t get the terms mixed up!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: RipeX</title>
		<link>http://www.emanueleferonato.com/2009/05/01/what-to-do-when-your-blog-has-a-virus/#comment-443914</link>
		<dc:creator>RipeX</dc:creator>
		<pubDate>Sun, 03 May 2009 20:24:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.emanueleferonato.com/?p=1205#comment-443914</guid>
		<description>Wow, thanks for the tips, Mike D! :)</description>
		<content:encoded><![CDATA[<p>Wow, thanks for the tips, Mike D! :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike D</title>
		<link>http://www.emanueleferonato.com/2009/05/01/what-to-do-when-your-blog-has-a-virus/#comment-443579</link>
		<dc:creator>Mike D</dc:creator>
		<pubDate>Sun, 03 May 2009 04:33:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.emanueleferonato.com/?p=1205#comment-443579</guid>
		<description>I&#039;ve ran dozens of wordpress sites and never had an issue. But then I pay attention to securing them in the first place. 
- Don&#039;t use shared hosting, and if you must, pay very close attention to write permissions on files and directories.
- Don&#039;t use wp- prefix on directories or database
- htaccess the admin directory with a password or ip restriction
- Install as few plugins as possible and never install obscure ones.
- Keep everything updated
- Remove meta generator worpdress version from header and themes</description>
		<content:encoded><![CDATA[<p>I&#8217;ve ran dozens of wordpress sites and never had an issue. But then I pay attention to securing them in the first place.<br />
- Don&#8217;t use shared hosting, and if you must, pay very close attention to write permissions on files and directories.<br />
- Don&#8217;t use wp- prefix on directories or database<br />
- htaccess the admin directory with a password or ip restriction<br />
- Install as few plugins as possible and never install obscure ones.<br />
- Keep everything updated<br />
- Remove meta generator worpdress version from header and themes</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: swineinflu</title>
		<link>http://www.emanueleferonato.com/2009/05/01/what-to-do-when-your-blog-has-a-virus/#comment-443031</link>
		<dc:creator>swineinflu</dc:creator>
		<pubDate>Sat, 02 May 2009 08:25:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.emanueleferonato.com/?p=1205#comment-443031</guid>
		<description>Wow Let me know the virus only attack wordpress? thanks alot tool for cure the virus
Damn hacker!</description>
		<content:encoded><![CDATA[<p>Wow Let me know the virus only attack wordpress? thanks alot tool for cure the virus<br />
Damn hacker!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Marcos</title>
		<link>http://www.emanueleferonato.com/2009/05/01/what-to-do-when-your-blog-has-a-virus/#comment-442912</link>
		<dc:creator>Marcos</dc:creator>
		<pubDate>Sat, 02 May 2009 02:40:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.emanueleferonato.com/?p=1205#comment-442912</guid>
		<description>But how do they insert the code in the php file? I mean, to edit the php file they must have access to the OS (or ftp), or they don&#039;t?</description>
		<content:encoded><![CDATA[<p>But how do they insert the code in the php file? I mean, to edit the php file they must have access to the OS (or ftp), or they don&#8217;t?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using disk: enhanced
Database Caching 6/11 queries in 0.024 seconds using disk: basic

Served from: www.emanueleferonato.com @ 2012-02-11 05:55:40 -->
