<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Details on the Network Solutions / WordPress mass hack</title>
	<atom:link href="http://blog.sucuri.net/2010/04/details-on-the-network-solutions-wordpress-mass-hack.html/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.sucuri.net/2010/04/details-on-the-network-solutions-wordpress-mass-hack.html</link>
	<description>Protect Your Interwebs</description>
	<lastBuildDate>Tue, 07 Feb 2012 14:40:59 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Wordpress Blogs Getting hacked! &#124; Adult Webmaster Blog</title>
		<link>http://blog.sucuri.net/2010/04/details-on-the-network-solutions-wordpress-mass-hack.html/comment-page-1#comment-1162</link>
		<dc:creator>Wordpress Blogs Getting hacked! &#124; Adult Webmaster Blog</dc:creator>
		<pubDate>Mon, 28 Jun 2010 14:12:38 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=37#comment-1162</guid>
		<description>[...] http://blog.sucuri.net/2010/04/details-on-the-network-solutions-wordpress-mass-hack.html GD Star Ratingloading...Bookmark to:     No Comments Posted by Rob in Hosting [...]</description>
		<content:encoded><![CDATA[<p>[...] <a href="http://blog.sucuri.net/2010/04/details-on-the-network-solutions-wordpress-mass-hack.html" rel="nofollow">http://blog.sucuri.net/2010/04/details-on-the-network-solutions-wordpress-mass-hack.html</a> GD Star Ratingloading&#8230;Bookmark to:     No Comments Posted by Rob in Hosting [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ricoh Teknoforce</title>
		<link>http://blog.sucuri.net/2010/04/details-on-the-network-solutions-wordpress-mass-hack.html/comment-page-1#comment-1157</link>
		<dc:creator>Ricoh Teknoforce</dc:creator>
		<pubDate>Mon, 28 Jun 2010 04:39:30 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=37#comment-1157</guid>
		<description>As a word press user, I would recommend that the php file which stores all user name and passwords should not be made available to every wordpress user unless required by user itself.  </description>
		<content:encoded><![CDATA[<p>As a word press user, I would recommend that the php file which stores all user name and passwords should not be made available to every wordpress user unless required by user itself.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: WordPress Hack and Security Settings &#8211; flyingpenguin</title>
		<link>http://blog.sucuri.net/2010/04/details-on-the-network-solutions-wordpress-mass-hack.html/comment-page-1#comment-916</link>
		<dc:creator>WordPress Hack and Security Settings &#8211; flyingpenguin</dc:creator>
		<pubDate>Fri, 11 Jun 2010 06:07:09 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=37#comment-916</guid>
		<description>[...] to change the wp-config.php permission to 0640 (instead of 0750). Some have suggested attacks come from shared/co-tenant systems where malicious users search for readable wp-config.php files to steal database [...]</description>
		<content:encoded><![CDATA[<p>[...] to change the wp-config.php permission to 0640 (instead of 0750). Some have suggested attacks come from shared/co-tenant systems where malicious users search for readable wp-config.php files to steal database [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://blog.sucuri.net/2010/04/details-on-the-network-solutions-wordpress-mass-hack.html/comment-page-1#comment-544</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Fri, 23 Apr 2010 15:29:28 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=37#comment-544</guid>
		<description>I have just gone through all the files of a site that was hacked on NS.(I am a WP developer) &lt;br /&gt;&lt;br /&gt;I changed the URL in the database back to the proper name as said here.&lt;br /&gt;&lt;br /&gt;Also, I will mention that I found most all index.php files were corrupt. There is a line of xss attack(a script code injection) just after the php code.&lt;br /&gt;&lt;br /&gt;So these files might also need to be changed for all of you to access admin properly.&lt;br /&gt;index.php on:&lt;br /&gt;&lt;br /&gt;root level/index.php&lt;br /&gt;wp-admin/index.php&lt;br /&gt;wp-content/index.php&lt;br /&gt;wp-content/plugins/index.php&lt;br /&gt;&lt;br /&gt;I would check any index.php file you have.&lt;br /&gt;All of these contained the malicious code.&lt;br /&gt;&lt;br /&gt;I hope this helps someone.</description>
		<content:encoded><![CDATA[<p>I have just gone through all the files of a site that was hacked on NS.(I am a WP developer) </p>
<p>I changed the URL in the database back to the proper name as said here.</p>
<p>Also, I will mention that I found most all index.php files were corrupt. There is a line of xss attack(a script code injection) just after the php code.</p>
<p>So these files might also need to be changed for all of you to access admin properly.<br />index.php on:</p>
<p>root level/index.php<br />wp-admin/index.php<br />wp-content/index.php<br />wp-content/plugins/index.php</p>
<p>I would check any index.php file you have.<br />All of these contained the malicious code.</p>
<p>I hope this helps someone.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://blog.sucuri.net/2010/04/details-on-the-network-solutions-wordpress-mass-hack.html/comment-page-1#comment-545</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Wed, 21 Apr 2010 11:34:59 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=37#comment-545</guid>
		<description>^ So it shows you all fail at understanding Linux. So open a Linux textbook/manpage and read the part on Linux shell permissions.</description>
		<content:encoded><![CDATA[<p>^ So it shows you all fail at understanding Linux. So open a Linux textbook/manpage and read the part on Linux shell permissions.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://blog.sucuri.net/2010/04/details-on-the-network-solutions-wordpress-mass-hack.html/comment-page-1#comment-546</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Wed, 21 Apr 2010 11:30:15 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=37#comment-546</guid>
		<description>644 is standard, you only get 755 or 777 if you assign rights to it. That said, 755 shouldn&#039;t matter at all since the config file doesn&#039;t display anything to the browser. &lt;br /&gt;&lt;br /&gt;They probably got root at networksolutions, or some SQL injection and did a grep for wordpress databases and injected their stuff.</description>
		<content:encoded><![CDATA[<p>644 is standard, you only get 755 or 777 if you assign rights to it. That said, 755 shouldn&#39;t matter at all since the config file doesn&#39;t display anything to the browser. </p>
<p>They probably got root at networksolutions, or some SQL injection and did a grep for wordpress databases and injected their stuff.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Richard</title>
		<link>http://blog.sucuri.net/2010/04/details-on-the-network-solutions-wordpress-mass-hack.html/comment-page-1#comment-547</link>
		<dc:creator>Richard</dc:creator>
		<pubDate>Mon, 19 Apr 2010 21:57:49 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=37#comment-547</guid>
		<description>How about posting an update?  NetSol owned up.  Your turn?&lt;br /&gt;&lt;br /&gt;http://blog.networksolutions.com/2010/wordpress-is-not-the-issue/&lt;br /&gt;&lt;br /&gt;&quot;WordPress is not the issue.&lt;br /&gt;&lt;br /&gt;by Shashi Bellamkonda on April 14, 2010&lt;br /&gt;&lt;br /&gt;We wanted to respond to the debate and conversations about the recent incident affecting Network Solutions’ WordPress customers.  Recently, our customers have complained about malicious code on certain of their blogs hosted by Network Solutions. This was not an issue with WordPress.  Sorry to the WordPress community and customers for any misunderstanding. This issue resulted from a complex combination of factors and we own it. We have taken steps to address this issue and we continue to work to protect our customers.   Also we wanted to let you know that no personal or sensitive financial information was taken as a result of this issue.&lt;br /&gt;&lt;br /&gt;We are learning from this experience.  By the way, we like WordPress and continue to use it for a lot of Network Solutions properties such as this blog.  Network Solutions customers that need any assistance feel free to email us at listen @ networksolutions.com&quot;</description>
		<content:encoded><![CDATA[<p>How about posting an update?  NetSol owned up.  Your turn?</p>
<p><a href="http://blog.networksolutions.com/2010/wordpress-is-not-the-issue/" rel="nofollow">http://blog.networksolutions.com/2010/wordpress-is-not-the-issue/</a></p>
<p>&quot;WordPress is not the issue.</p>
<p>by Shashi Bellamkonda on April 14, 2010</p>
<p>We wanted to respond to the debate and conversations about the recent incident affecting Network Solutions’ WordPress customers.  Recently, our customers have complained about malicious code on certain of their blogs hosted by Network Solutions. This was not an issue with WordPress.  Sorry to the WordPress community and customers for any misunderstanding. This issue resulted from a complex combination of factors and we own it. We have taken steps to address this issue and we continue to work to protect our customers.   Also we wanted to let you know that no personal or sensitive financial information was taken as a result of this issue.</p>
<p>We are learning from this experience.  By the way, we like WordPress and continue to use it for a lot of Network Solutions properties such as this blog.  Network Solutions customers that need any assistance feel free to email us at listen @ networksolutions.com&quot;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bill Huntley</title>
		<link>http://blog.sucuri.net/2010/04/details-on-the-network-solutions-wordpress-mass-hack.html/comment-page-1#comment-548</link>
		<dc:creator>Bill Huntley</dc:creator>
		<pubDate>Mon, 19 Apr 2010 17:49:05 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=37#comment-548</guid>
		<description>I have been hacked with malicious malware four times in the past two years. My host is Network Solutions. Last week my wordpress blog disappeared and this week my web site is gone. In 2009, Net work Solutions blamed my web developer for the lack of security and,the web developer blamed Network Solutions. My site has been under attack this time since December 09 and I have just paid a ton of money to a web tech guy to clean things up, now only three weeks later my site is gone from the web altogether. My ranking with Google is in the tank and my business is suffering. Who do you trust and how are these problems resolved?</description>
		<content:encoded><![CDATA[<p>I have been hacked with malicious malware four times in the past two years. My host is Network Solutions. Last week my wordpress blog disappeared and this week my web site is gone. In 2009, Net work Solutions blamed my web developer for the lack of security and,the web developer blamed Network Solutions. My site has been under attack this time since December 09 and I have just paid a ton of money to a web tech guy to clean things up, now only three weeks later my site is gone from the web altogether. My ranking with Google is in the tank and my business is suffering. Who do you trust and how are these problems resolved?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike</title>
		<link>http://blog.sucuri.net/2010/04/details-on-the-network-solutions-wordpress-mass-hack.html/comment-page-1#comment-549</link>
		<dc:creator>Mike</dc:creator>
		<pubDate>Sun, 18 Apr 2010 14:51:05 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=37#comment-549</guid>
		<description>Of course the above only works if they&#039;re using suexec/suphp or similar. If they&#039;re not doing that, their security is even more of a joke.</description>
		<content:encoded><![CDATA[<p>Of course the above only works if they&#39;re using suexec/suphp or similar. If they&#39;re not doing that, their security is even more of a joke.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike</title>
		<link>http://blog.sucuri.net/2010/04/details-on-the-network-solutions-wordpress-mass-hack.html/comment-page-1#comment-550</link>
		<dc:creator>Mike</dc:creator>
		<pubDate>Sun, 18 Apr 2010 14:30:22 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=37#comment-550</guid>
		<description>It is entirely Network Solutions fault.&lt;br /&gt;&lt;br /&gt;They should secure the home directories of their users such that other users can not access them even if individual files within those home directories have global read access. Example:&lt;br /&gt;&lt;br /&gt;drwxr-x--- 95 mike apache 12288 2010-04-17 17:18 /home/mike&lt;br /&gt;&lt;br /&gt;If user mike now creates a globally readable file in his home directory, user fred can&#039;t read it...&lt;br /&gt;&lt;br /&gt;This is kids stuff...</description>
		<content:encoded><![CDATA[<p>It is entirely Network Solutions fault.</p>
<p>They should secure the home directories of their users such that other users can not access them even if individual files within those home directories have global read access. Example:</p>
<p>drwxr-x&#8212; 95 mike apache 12288 2010-04-17 17:18 /home/mike</p>
<p>If user mike now creates a globally readable file in his home directory, user fred can&#39;t read it&#8230;</p>
<p>This is kids stuff&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>

