<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Protect WordPress from Hackers &#8211; Secure that Beeotch!</title>
	<atom:link href="http://onemansblog.com/2009/12/03/protect-wordpress-from-hackers-secure-that-beeotch/feed/" rel="self" type="application/rss+xml" />
	<link>http://onemansblog.com/2009/12/03/protect-wordpress-from-hackers-secure-that-beeotch/</link>
	<description>Specialization is for Insects.</description>
	<lastBuildDate>Tue, 14 Feb 2012 05:44:21 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Peter</title>
		<link>http://onemansblog.com/2009/12/03/protect-wordpress-from-hackers-secure-that-beeotch/comment-page-1/#comment-63309</link>
		<dc:creator>Peter</dc:creator>
		<pubDate>Tue, 03 Aug 2010 18:25:03 +0000</pubDate>
		<guid isPermaLink="false">http://onemansblog.com/?p=7684#comment-63309</guid>
		<description>I just came across this now, I installed a plugin called BulletProof security for wordpress. It seems to have halted some attacks as  have been a victim from these freaks lately...
Really sucks</description>
		<content:encoded><![CDATA[<p>I just came across this now, I installed a plugin called BulletProof security for wordpress. It seems to have halted some attacks as  have been a victim from these freaks lately&#8230;<br />
Really sucks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: b-projects</title>
		<link>http://onemansblog.com/2009/12/03/protect-wordpress-from-hackers-secure-that-beeotch/comment-page-1/#comment-55334</link>
		<dc:creator>b-projects</dc:creator>
		<pubDate>Mon, 28 Dec 2009 01:54:02 +0000</pubDate>
		<guid isPermaLink="false">http://onemansblog.com/?p=7684#comment-55334</guid>
		<description>i secured my site via captchas. i had problems with the spam bots but i won that race :-)</description>
		<content:encoded><![CDATA[<p>i secured my site via captchas. i had problems with the spam bots but i won that race :-)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ruben Abramov</title>
		<link>http://onemansblog.com/2009/12/03/protect-wordpress-from-hackers-secure-that-beeotch/comment-page-1/#comment-55098</link>
		<dc:creator>Ruben Abramov</dc:creator>
		<pubDate>Thu, 17 Dec 2009 20:07:51 +0000</pubDate>
		<guid isPermaLink="false">http://onemansblog.com/?p=7684#comment-55098</guid>
		<description>switching to wordpress , i thought i was secure , now i haveto secure all my wordpress sites =/</description>
		<content:encoded><![CDATA[<p>switching to wordpress , i thought i was secure , now i haveto secure all my wordpress sites =/</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tradakk</title>
		<link>http://onemansblog.com/2009/12/03/protect-wordpress-from-hackers-secure-that-beeotch/comment-page-1/#comment-54872</link>
		<dc:creator>Tradakk</dc:creator>
		<pubDate>Sun, 06 Dec 2009 20:11:41 +0000</pubDate>
		<guid isPermaLink="false">http://onemansblog.com/?p=7684#comment-54872</guid>
		<description>I&#039;m seconding that first advice piece about your password. Seriously, your phone number as a password? Your last name? Pathetic. I got hammered by a ton of emails from eBay the other day because someone hacked my pathetic password that I&#039;d never bothered to change (for the record, it was &#039;gooood.&#039; Yeah, I know. It&#039;s lame.)
Now, though? My password&#039;s 32 characters long, with four letters and one symbol. Take that, hackers!</description>
		<content:encoded><![CDATA[<p>I&#8217;m seconding that first advice piece about your password. Seriously, your phone number as a password? Your last name? Pathetic. I got hammered by a ton of emails from eBay the other day because someone hacked my pathetic password that I&#8217;d never bothered to change (for the record, it was &#8216;gooood.&#8217; Yeah, I know. It&#8217;s lame.)<br />
Now, though? My password&#8217;s 32 characters long, with four letters and one symbol. Take that, hackers!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John P.</title>
		<link>http://onemansblog.com/2009/12/03/protect-wordpress-from-hackers-secure-that-beeotch/comment-page-1/#comment-54870</link>
		<dc:creator>John P.</dc:creator>
		<pubDate>Sun, 06 Dec 2009 18:47:46 +0000</pubDate>
		<guid isPermaLink="false">http://onemansblog.com/?p=7684#comment-54870</guid>
		<description>Thanks Herbert, I installed that plugin.  I&#039;ll add it to this page later after I&#039;ve tested it out a little bit!

John P.</description>
		<content:encoded><![CDATA[<p>Thanks Herbert, I installed that plugin.  I&#8217;ll add it to this page later after I&#8217;ve tested it out a little bit!</p>
<p>John P.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Herbert-Jan van Dinther</title>
		<link>http://onemansblog.com/2009/12/03/protect-wordpress-from-hackers-secure-that-beeotch/comment-page-1/#comment-54843</link>
		<dc:creator>Herbert-Jan van Dinther</dc:creator>
		<pubDate>Sat, 05 Dec 2009 10:43:32 +0000</pubDate>
		<guid isPermaLink="false">http://onemansblog.com/?p=7684#comment-54843</guid>
		<description>Hi John, I suggest you install this WordPress file monitor plugin http://wordpress.org/extend/plugins/wordpress-file-monitor/ and check and/or change your WordPress Table prefix to something else then the default wp_ if you havent done that already.</description>
		<content:encoded><![CDATA[<p>Hi John, I suggest you install this WordPress file monitor plugin <a href="http://wordpress.org/extend/plugins/wordpress-file-monitor/" rel="nofollow">http://wordpress.org/extend/plugins/wordpress-file-monitor/</a> and check and/or change your WordPress Table prefix to something else then the default wp_ if you havent done that already.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael VanDeMar</title>
		<link>http://onemansblog.com/2009/12/03/protect-wordpress-from-hackers-secure-that-beeotch/comment-page-1/#comment-54772</link>
		<dc:creator>Michael VanDeMar</dc:creator>
		<pubDate>Fri, 04 Dec 2009 14:51:15 +0000</pubDate>
		<guid isPermaLink="false">http://onemansblog.com/?p=7684#comment-54772</guid>
		<description>John, do you know how to run queries against the database? If so, I would try these two:

SELECT * FROM wp_usermeta where meta_value like &#039;%administrator%&#039;;
SELECT * FROM wp_usermeta where meta_value like &#039;%script%&#039;;

If you changed the default table prefix when you installed Wordpress (usually done if you want to install more than one Wordpress into the same database), then you will need to change wp_usermeta to whatever that is. The first query will show you how many accounts there are with administrator privileges... you can see what the usernames are for each account by matching up the user_id fields with the ID field in the wp-users table. The second query will show you if any of the display names for your users contain suspicious code, from having a  tag embedded in them.

Also, look inside WP&#039;s index.php. See if any extra code has been added to it (download a fresh copy and compare the two).

If you don&#039;t find anything with either of those, then the next place I would look would be for files that were dropped on the server as backdoors. Unfortunately, those can be very hard to track down.</description>
		<content:encoded><![CDATA[<p>John, do you know how to run queries against the database? If so, I would try these two:</p>
<p>SELECT * FROM wp_usermeta where meta_value like &#8216;%administrator%&#8217;;<br />
SELECT * FROM wp_usermeta where meta_value like &#8216;%script%&#8217;;</p>
<p>If you changed the default table prefix when you installed WordPress (usually done if you want to install more than one WordPress into the same database), then you will need to change wp_usermeta to whatever that is. The first query will show you how many accounts there are with administrator privileges&#8230; you can see what the usernames are for each account by matching up the user_id fields with the ID field in the wp-users table. The second query will show you if any of the display names for your users contain suspicious code, from having a  tag embedded in them.</p>
<p>Also, look inside WP&#8217;s index.php. See if any extra code has been added to it (download a fresh copy and compare the two).</p>
<p>If you don&#8217;t find anything with either of those, then the next place I would look would be for files that were dropped on the server as backdoors. Unfortunately, those can be very hard to track down.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John P.</title>
		<link>http://onemansblog.com/2009/12/03/protect-wordpress-from-hackers-secure-that-beeotch/comment-page-1/#comment-54753</link>
		<dc:creator>John P.</dc:creator>
		<pubDate>Fri, 04 Dec 2009 07:54:54 +0000</pubDate>
		<guid isPermaLink="false">http://onemansblog.com/?p=7684#comment-54753</guid>
		<description>Thanks Michael! I just did the auto-upgrade function and yes, I&#039;ve been dealing with this for weeks.  I keep finding the code and deleting it, and I can&#039;t figure out how they are getting into the site considering everything else I&#039;ve done.

I did go into the Google Webmaster Tools and already request that they not de-index me, though if it reoccurs and I don&#039;t catch it quickly enough when they check again they&#039;ll likely do it.  So I&#039;m pretty nervous about it.

This kind of thing really sucks for someone in my position.  I&#039;m just good enough to hack some PHP and operate the blog on a day to day basis, but not good enough to deal with emergency situations like database backups and restores, etc.

GRRR!!!

John</description>
		<content:encoded><![CDATA[<p>Thanks Michael! I just did the auto-upgrade function and yes, I&#8217;ve been dealing with this for weeks.  I keep finding the code and deleting it, and I can&#8217;t figure out how they are getting into the site considering everything else I&#8217;ve done.</p>
<p>I did go into the Google Webmaster Tools and already request that they not de-index me, though if it reoccurs and I don&#8217;t catch it quickly enough when they check again they&#8217;ll likely do it.  So I&#8217;m pretty nervous about it.</p>
<p>This kind of thing really sucks for someone in my position.  I&#8217;m just good enough to hack some PHP and operate the blog on a day to day basis, but not good enough to deal with emergency situations like database backups and restores, etc.</p>
<p>GRRR!!!</p>
<p>John</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael VanDeMar</title>
		<link>http://onemansblog.com/2009/12/03/protect-wordpress-from-hackers-secure-that-beeotch/comment-page-1/#comment-54748</link>
		<dc:creator>Michael VanDeMar</dc:creator>
		<pubDate>Fri, 04 Dec 2009 03:57:41 +0000</pubDate>
		<guid isPermaLink="false">http://onemansblog.com/?p=7684#comment-54748</guid>
		<description>John, when you upgraded, did you do complete wipe and resintalls? Or did you just upgrade the files? It&#039;s possible that the hackers got in while you had an earlier version installed (afaik everything up to and including WP 2.8.4 was vulnerable), and it just went undetected (might not even have been exploited) until recently. If this is the case then just upgrading won&#039;t help. I wrote up a piece a while ago on how to completely clean your WP install:

&lt;a href=&quot;http://smackdown.blogsblogsblogs.com/2008/06/24/how-to-completely-clean-your-hacked-wordpress-installation/&quot; rel=&quot;nofollow&quot;&gt;http://smackdown.blogsblogsblogs.com/2008/06/24/how-to-completely-clean-your-hacked-wordpress-installation/&lt;/a&gt;

but even if you do that, with some exploits you need to be careful because they might have left a back door in the database itself. 

Sorry you got hacked, I know it sucks. Been through it a few times. One thing I would suggest for after it&#039;s cleaned... you can probably cut the ban time from Google (or possibly head it off altogether, since you are still fully indexed as of right now) by doing a reinclusion request through the Google Webmaster Tools utility. You would have to sign up and register your site if you haven&#039;t already, but it&#039;s relatively painless to do.

Good luck. :)</description>
		<content:encoded><![CDATA[<p>John, when you upgraded, did you do complete wipe and resintalls? Or did you just upgrade the files? It&#8217;s possible that the hackers got in while you had an earlier version installed (afaik everything up to and including WP 2.8.4 was vulnerable), and it just went undetected (might not even have been exploited) until recently. If this is the case then just upgrading won&#8217;t help. I wrote up a piece a while ago on how to completely clean your WP install:</p>
<p><a href="http://smackdown.blogsblogsblogs.com/2008/06/24/how-to-completely-clean-your-hacked-wordpress-installation/" rel="nofollow">http://smackdown.blogsblogsblogs.com/2008/06/24/how-to-completely-clean-your-hacked-wordpress-installation/</a></p>
<p>but even if you do that, with some exploits you need to be careful because they might have left a back door in the database itself. </p>
<p>Sorry you got hacked, I know it sucks. Been through it a few times. One thing I would suggest for after it&#8217;s cleaned&#8230; you can probably cut the ban time from Google (or possibly head it off altogether, since you are still fully indexed as of right now) by doing a reinclusion request through the Google Webmaster Tools utility. You would have to sign up and register your site if you haven&#8217;t already, but it&#8217;s relatively painless to do.</p>
<p>Good luck. :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eve</title>
		<link>http://onemansblog.com/2009/12/03/protect-wordpress-from-hackers-secure-that-beeotch/comment-page-1/#comment-54746</link>
		<dc:creator>Eve</dc:creator>
		<pubDate>Fri, 04 Dec 2009 02:35:01 +0000</pubDate>
		<guid isPermaLink="false">http://onemansblog.com/?p=7684#comment-54746</guid>
		<description>Great article, I am off to install the plugins and check my files! Thanks.</description>
		<content:encoded><![CDATA[<p>Great article, I am off to install the plugins and check my files! Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John P.</title>
		<link>http://onemansblog.com/2009/12/03/protect-wordpress-from-hackers-secure-that-beeotch/comment-page-1/#comment-54743</link>
		<dc:creator>John P.</dc:creator>
		<pubDate>Thu, 03 Dec 2009 23:19:06 +0000</pubDate>
		<guid isPermaLink="false">http://onemansblog.com/?p=7684#comment-54743</guid>
		<description>I don&#039;t know how they did it.  The DEFCON keeps the server itself hardened, but if you have a weakness in the WordPress stuff they can&#039;t protect against that.  This is why doing all of these things is very important.  

I suspected it was a problem with the permissions I had on a couple of directories at first.  I used WP Security Scan to correct those.  Then it happened again!  So I just changed my passwords for WordPress and even for my FTP.

I&#039;ll be keeping a very close eye on it for a while, and probably also get Jad (our Woopra server magician) to take a look at it too.  If I determine what is going on I&#039;ll update everyone so that you can take preventative measures.

John P.</description>
		<content:encoded><![CDATA[<p>I don&#8217;t know how they did it.  The DEFCON keeps the server itself hardened, but if you have a weakness in the WordPress stuff they can&#8217;t protect against that.  This is why doing all of these things is very important.  </p>
<p>I suspected it was a problem with the permissions I had on a couple of directories at first.  I used WP Security Scan to correct those.  Then it happened again!  So I just changed my passwords for WordPress and even for my FTP.</p>
<p>I&#8217;ll be keeping a very close eye on it for a while, and probably also get Jad (our Woopra server magician) to take a look at it too.  If I determine what is going on I&#8217;ll update everyone so that you can take preventative measures.</p>
<p>John P.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Robert Geczi</title>
		<link>http://onemansblog.com/2009/12/03/protect-wordpress-from-hackers-secure-that-beeotch/comment-page-1/#comment-54742</link>
		<dc:creator>Robert Geczi</dc:creator>
		<pubDate>Thu, 03 Dec 2009 23:18:07 +0000</pubDate>
		<guid isPermaLink="false">http://onemansblog.com/?p=7684#comment-54742</guid>
		<description>If the Pentagon can&#039;t keep hackers and troublemakers off of their servers and setups, how can we?  I remember hearing breaches at various places such as the Pentagon, and so on.  

Not good at all.</description>
		<content:encoded><![CDATA[<p>If the Pentagon can&#8217;t keep hackers and troublemakers off of their servers and setups, how can we?  I remember hearing breaches at various places such as the Pentagon, and so on.  </p>
<p>Not good at all.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John P.</title>
		<link>http://onemansblog.com/2009/12/03/protect-wordpress-from-hackers-secure-that-beeotch/comment-page-1/#comment-54740</link>
		<dc:creator>John P.</dc:creator>
		<pubDate>Thu, 03 Dec 2009 23:15:50 +0000</pubDate>
		<guid isPermaLink="false">http://onemansblog.com/?p=7684#comment-54740</guid>
		<description>I know!  It&#039;s reee-diculous.  :-)  Oh, and it says &quot;AT LEAST&quot; 30 days!

John P.</description>
		<content:encoded><![CDATA[<p>I know!  It&#8217;s reee-diculous.  :-)  Oh, and it says &#8220;AT LEAST&#8221; 30 days!</p>
<p>John P.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sleenie</title>
		<link>http://onemansblog.com/2009/12/03/protect-wordpress-from-hackers-secure-that-beeotch/comment-page-1/#comment-54739</link>
		<dc:creator>Sleenie</dc:creator>
		<pubDate>Thu, 03 Dec 2009 22:59:43 +0000</pubDate>
		<guid isPermaLink="false">http://onemansblog.com/?p=7684#comment-54739</guid>
		<description>I had major problems during November and lost 10 WordPress sites. Yes, I keep them updated but they managed to get into my databases and eventually infected all my accounts on one server. it was a nightmare. I had backups but it seems that the infection was there for at least a month as all of my backups were infected also. Had to nuke my account and rebuild!  Thanks for the tips. i will definitely add them to my arsenal.</description>
		<content:encoded><![CDATA[<p>I had major problems during November and lost 10 WordPress sites. Yes, I keep them updated but they managed to get into my databases and eventually infected all my accounts on one server. it was a nightmare. I had backups but it seems that the infection was there for at least a month as all of my backups were infected also. Had to nuke my account and rebuild!  Thanks for the tips. i will definitely add them to my arsenal.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lisa Marie Mary</title>
		<link>http://onemansblog.com/2009/12/03/protect-wordpress-from-hackers-secure-that-beeotch/comment-page-1/#comment-54737</link>
		<dc:creator>Lisa Marie Mary</dc:creator>
		<pubDate>Thu, 03 Dec 2009 22:21:28 +0000</pubDate>
		<guid isPermaLink="false">http://onemansblog.com/?p=7684#comment-54737</guid>
		<description>&lt;i&gt;Thirty days???&lt;/i&gt; Because of some bastard spammer?? Damn!!! That royally sucks....

Now I gotta go back and read the rest of the post - that part right there just &lt;I&gt;RILED&lt;/i&gt; me UP!!!</description>
		<content:encoded><![CDATA[<p><i>Thirty days???</i> Because of some bastard spammer?? Damn!!! That royally sucks&#8230;.</p>
<p>Now I gotta go back and read the rest of the post &#8211; that part right there just <i>RILED</i> me UP!!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Zig Baird</title>
		<link>http://onemansblog.com/2009/12/03/protect-wordpress-from-hackers-secure-that-beeotch/comment-page-1/#comment-54736</link>
		<dc:creator>Zig Baird</dc:creator>
		<pubDate>Thu, 03 Dec 2009 21:02:53 +0000</pubDate>
		<guid isPermaLink="false">http://onemansblog.com/?p=7684#comment-54736</guid>
		<description>John - how the heck did they get past your DEFCON 1 security?  Keep me in the loop if you find out. I&#039;d like to know what to fix.</description>
		<content:encoded><![CDATA[<p>John &#8211; how the heck did they get past your DEFCON 1 security?  Keep me in the loop if you find out. I&#8217;d like to know what to fix.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

