<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Help needed &#8211; War to hackers</title>
	<atom:link href="http://www.emanueleferonato.com/2009/12/09/help-needed-war-to-hackers/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.emanueleferonato.com/2009/12/09/help-needed-war-to-hackers/</link>
	<description>italian geek and PROgrammer</description>
	<lastBuildDate>Fri, 10 Feb 2012 12:12:29 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: Emanuele Feronato - italian geek and PROgrammer</title>
		<link>http://www.emanueleferonato.com/2009/12/09/help-needed-war-to-hackers/#comment-576167</link>
		<dc:creator>Emanuele Feronato - italian geek and PROgrammer</dc:creator>
		<pubDate>Wed, 05 May 2010 16:59:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.emanueleferonato.com/?p=2050#comment-576167</guid>
		<description>[...] you should know if you are an old time reader, this blog has been hacked several times with malicious script [...]</description>
		<content:encoded><![CDATA[<p>[...] you should know if you are an old time reader, this blog has been hacked several times with malicious script [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jafar</title>
		<link>http://www.emanueleferonato.com/2009/12/09/help-needed-war-to-hackers/#comment-536489</link>
		<dc:creator>Jafar</dc:creator>
		<pubDate>Mon, 11 Jan 2010 06:34:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.emanueleferonato.com/?p=2050#comment-536489</guid>
		<description>Try using N-Stalker to search for threats. It&#039; s really a good program :)</description>
		<content:encoded><![CDATA[<p>Try using N-Stalker to search for threats. It&#8217; s really a good program :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Badim</title>
		<link>http://www.emanueleferonato.com/2009/12/09/help-needed-war-to-hackers/#comment-531332</link>
		<dc:creator>Badim</dc:creator>
		<pubDate>Wed, 16 Dec 2009 21:01:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.emanueleferonato.com/?p=2050#comment-531332</guid>
		<description>oh man, i get same attack few weeks ago.
what you HAVE to ad - as Vadersapien said:
purge your http directory, upload latest installation of WP and connect them to your MySQL tables. Or restore backup BEFORE(you have to be 100% sure) your http was modified.

how this attacks works:
you lost your password to TrojanX, TrojanX sent all ftp info to special serverY, and leaved php file for case if you will change pass. Server Y each day each time trying to Do same Script for each access that it has, if access is not working, it will try PhP file, if not - attacks will probably stops.

this all process is auto-matic. so it have to be not personal stuff, just some hazkers doing what they can to get extra $ =(</description>
		<content:encoded><![CDATA[<p>oh man, i get same attack few weeks ago.<br />
what you HAVE to ad &#8211; as Vadersapien said:<br />
purge your http directory, upload latest installation of WP and connect them to your MySQL tables. Or restore backup BEFORE(you have to be 100% sure) your http was modified.</p>
<p>how this attacks works:<br />
you lost your password to TrojanX, TrojanX sent all ftp info to special serverY, and leaved php file for case if you will change pass. Server Y each day each time trying to Do same Script for each access that it has, if access is not working, it will try PhP file, if not &#8211; attacks will probably stops.</p>
<p>this all process is auto-matic. so it have to be not personal stuff, just some hazkers doing what they can to get extra $ =(</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike Duguid</title>
		<link>http://www.emanueleferonato.com/2009/12/09/help-needed-war-to-hackers/#comment-530997</link>
		<dc:creator>Mike Duguid</dc:creator>
		<pubDate>Tue, 15 Dec 2009 13:36:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.emanueleferonato.com/?p=2050#comment-530997</guid>
		<description>If you&#039;re sure it&#039;s not via ftp scan your http access logs and correlation of those with file modification times is the next step.</description>
		<content:encoded><![CDATA[<p>If you&#8217;re sure it&#8217;s not via ftp scan your http access logs and correlation of those with file modification times is the next step.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Vadersapien</title>
		<link>http://www.emanueleferonato.com/2009/12/09/help-needed-war-to-hackers/#comment-530879</link>
		<dc:creator>Vadersapien</dc:creator>
		<pubDate>Mon, 14 Dec 2009 21:32:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.emanueleferonato.com/?p=2050#comment-530879</guid>
		<description>If you never get to find it, I think the best thing to do would be delete everything on the server(maybe keep MySQL tables), and restore from a backup...although that PHP file might have existed when you hosted the site on the other server, explaining why the attacks carried over between servers...</description>
		<content:encoded><![CDATA[<p>If you never get to find it, I think the best thing to do would be delete everything on the server(maybe keep MySQL tables), and restore from a backup&#8230;although that PHP file might have existed when you hosted the site on the other server, explaining why the attacks carried over between servers&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Emanuele Feronato</title>
		<link>http://www.emanueleferonato.com/2009/12/09/help-needed-war-to-hackers/#comment-530849</link>
		<dc:creator>Emanuele Feronato</dc:creator>
		<pubDate>Mon, 14 Dec 2009 14:41:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.emanueleferonato.com/?p=2050#comment-530849</guid>
		<description>I changed the FTP password and never used the FTP since then, but attacks continue.

I think there is a unsanitized PHP executing scripts... but I can&#039;t find it...</description>
		<content:encoded><![CDATA[<p>I changed the FTP password and never used the FTP since then, but attacks continue.</p>
<p>I think there is a unsanitized PHP executing scripts&#8230; but I can&#8217;t find it&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sandro</title>
		<link>http://www.emanueleferonato.com/2009/12/09/help-needed-war-to-hackers/#comment-530720</link>
		<dc:creator>sandro</dc:creator>
		<pubDate>Sun, 13 Dec 2009 22:55:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.emanueleferonato.com/?p=2050#comment-530720</guid>
		<description>try this

http://www.evilsocket.net/764/wp-sentinel-pubblicato.html</description>
		<content:encoded><![CDATA[<p>try this</p>
<p><a href="http://www.evilsocket.net/764/wp-sentinel-pubblicato.html" rel="nofollow">http://www.evilsocket.net/764/wp-sentinel-pubblicato.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike Duguid</title>
		<link>http://www.emanueleferonato.com/2009/12/09/help-needed-war-to-hackers/#comment-530554</link>
		<dc:creator>Mike Duguid</dc:creator>
		<pubDate>Sat, 12 Dec 2009 21:24:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.emanueleferonato.com/?p=2050#comment-530554</guid>
		<description>Andrea, he&#039;s running on a hostgator host - he cannot make changes to the overall server config that would make any difference, and it&#039;d be unlikely that a shared server with 1000&#039;s of people on it has been rooted. I&#039;d take the hostgator advice with a pinch of salt, it&#039;s a standard canned reply, the tier of support staff you will deal with at large companies like this haven&#039;t the knowledge or time to really get to the bottom of the cause.</description>
		<content:encoded><![CDATA[<p>Andrea, he&#8217;s running on a hostgator host &#8211; he cannot make changes to the overall server config that would make any difference, and it&#8217;d be unlikely that a shared server with 1000&#8242;s of people on it has been rooted. I&#8217;d take the hostgator advice with a pinch of salt, it&#8217;s a standard canned reply, the tier of support staff you will deal with at large companies like this haven&#8217;t the knowledge or time to really get to the bottom of the cause.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike Duguid</title>
		<link>http://www.emanueleferonato.com/2009/12/09/help-needed-war-to-hackers/#comment-530553</link>
		<dc:creator>Mike Duguid</dc:creator>
		<pubDate>Sat, 12 Dec 2009 21:19:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.emanueleferonato.com/?p=2050#comment-530553</guid>
		<description>I&#039;ve seen a similar issue where a PC was infected with a gumblar variant (up to date AV didn&#039;t recognise!) which sniffed ftp details. The outgoing data also bypassed a firewall by attaching to an svchost instance. So don&#039;t be too sure a quick scan will give you an &#039;all clear&#039; for this route of vulnerability. The way to -know- and not -guess- how the attack is happening is to check server logs against modification time of infected files and correlate users/ips/access at that time. Once you -know- how the attack happened you can sort it rather than stumbling from one ineffective solution to another. I&#039;ll reiterate again - don&#039;t use shared hosting (shared hosting is a complete waste of time for professional use - can&#039;t modify firewall rules e.g lock ftp to your own, often can&#039;t get access to ftp logs, change apache/ftp users permission, no sftp or ssh etc etc).</description>
		<content:encoded><![CDATA[<p>I&#8217;ve seen a similar issue where a PC was infected with a gumblar variant (up to date AV didn&#8217;t recognise!) which sniffed ftp details. The outgoing data also bypassed a firewall by attaching to an svchost instance. So don&#8217;t be too sure a quick scan will give you an &#8216;all clear&#8217; for this route of vulnerability. The way to -know- and not -guess- how the attack is happening is to check server logs against modification time of infected files and correlate users/ips/access at that time. Once you -know- how the attack happened you can sort it rather than stumbling from one ineffective solution to another. I&#8217;ll reiterate again &#8211; don&#8217;t use shared hosting (shared hosting is a complete waste of time for professional use &#8211; can&#8217;t modify firewall rules e.g lock ftp to your own, often can&#8217;t get access to ftp logs, change apache/ftp users permission, no sftp or ssh etc etc).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andrea</title>
		<link>http://www.emanueleferonato.com/2009/12/09/help-needed-war-to-hackers/#comment-530441</link>
		<dc:creator>Andrea</dc:creator>
		<pubDate>Sat, 12 Dec 2009 10:26:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.emanueleferonato.com/?p=2050#comment-530441</guid>
		<description>I check your server, there are too many open ports, including a port running a service unknown</description>
		<content:encoded><![CDATA[<p>I check your server, there are too many open ports, including a port running a service unknown</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using disk: enhanced
Database Caching 5/11 queries in 0.033 seconds using disk: basic

Served from: www.emanueleferonato.com @ 2012-02-10 22:00:51 -->
