<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Attack of WordPress blogs on Rackspace</title>
	<atom:link href="http://blog.sucuri.net/2010/06/mass-attack-of-wordpress-blogs-on-rackspace.html/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.sucuri.net/2010/06/mass-attack-of-wordpress-blogs-on-rackspace.html</link>
	<description>Protect Your Interwebs</description>
	<lastBuildDate>Tue, 07 Feb 2012 14:40:59 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Is BlogOnCloud9 WordPress Heaven? &#124; The Blog Herald</title>
		<link>http://blog.sucuri.net/2010/06/mass-attack-of-wordpress-blogs-on-rackspace.html/comment-page-1#comment-2070</link>
		<dc:creator>Is BlogOnCloud9 WordPress Heaven? &#124; The Blog Herald</dc:creator>
		<pubDate>Wed, 15 Sep 2010 21:29:10 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=296#comment-2070</guid>
		<description>[...] Rackspace does have a positive reputation in the geek world, the site was hacked into in June (which caused a mass panic amongst the WordPress faithful) and is increasingly becoming a [...]</description>
		<content:encoded><![CDATA[<p>[...] Rackspace does have a positive reputation in the geek world, the site was hacked into in June (which caused a mass panic amongst the WordPress faithful) and is increasingly becoming a [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Fanatical Support? What fanatical support&#8230;Rackspace sucks! &#124; Julian Sula's Blog</title>
		<link>http://blog.sucuri.net/2010/06/mass-attack-of-wordpress-blogs-on-rackspace.html/comment-page-1#comment-1286</link>
		<dc:creator>Fanatical Support? What fanatical support&#8230;Rackspace sucks! &#124; Julian Sula's Blog</dc:creator>
		<pubDate>Sat, 03 Jul 2010 06:51:31 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=296#comment-1286</guid>
		<description>[...] so how is it our fault in the first place that our customer sites get hacked? As noted here or here or [...]</description>
		<content:encoded><![CDATA[<p>[...] so how is it our fault in the first place that our customer sites get hacked? As noted here or here or [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Managing Hacked Client WordPress Sites: Prevention, Reaction and Investigation &#8211; Chris LeCompte</title>
		<link>http://blog.sucuri.net/2010/06/mass-attack-of-wordpress-blogs-on-rackspace.html/comment-page-1#comment-1022</link>
		<dc:creator>Managing Hacked Client WordPress Sites: Prevention, Reaction and Investigation &#8211; Chris LeCompte</dc:creator>
		<pubDate>Thu, 17 Jun 2010 13:23:27 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=296#comment-1022</guid>
		<description>[...] Sucuri Blog: Attack of WordPress blogs on Rackspace [...]</description>
		<content:encoded><![CDATA[<p>[...] Sucuri Blog: Attack of WordPress blogs on Rackspace [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: 0-day wordpress vulnerability results in many Media Temple malware infections</title>
		<link>http://blog.sucuri.net/2010/06/mass-attack-of-wordpress-blogs-on-rackspace.html/comment-page-1#comment-1016</link>
		<dc:creator>0-day wordpress vulnerability results in many Media Temple malware infections</dc:creator>
		<pubDate>Wed, 16 Jun 2010 20:08:41 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=296#comment-1016</guid>
		<description>[...] like this http://blog.sucuri.net/2010/06/mass-...rackspace.html you mean?     Twitter&#124; Personal Blog &#124; That Other Site         Reply With Quote &#160;              [...]</description>
		<content:encoded><![CDATA[<p>[...] like this <a href="http://blog.sucuri.net/2010/06/mass-...rackspace.html" rel="nofollow">http://blog.sucuri.net/2010/06/mass-&#8230;rackspace.html</a> you mean?     Twitter| Personal Blog | That Other Site         Reply With Quote &nbsp;              [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Scott</title>
		<link>http://blog.sucuri.net/2010/06/mass-attack-of-wordpress-blogs-on-rackspace.html/comment-page-1#comment-1015</link>
		<dc:creator>Scott</dc:creator>
		<pubDate>Wed, 16 Jun 2010 18:05:49 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=296#comment-1015</guid>
		<description>I got hit as well. 5 of my WP sites (which are all using Sucuri) got hit with this &#039;amin&#039; attack. I must have caught the attack before anything malicious was done as none of my files were modified (thus not tripping the Securi alarm). I found multiple rows in the DB with base64 garbage in them and lots of unknown users in the users table. I also found some malicious PHP files within the plugins folder. 
 
And yes....ALL of my affected websites were hosted on Rackspace Cloud. </description>
		<content:encoded><![CDATA[<p>I got hit as well. 5 of my WP sites (which are all using Sucuri) got hit with this &#039;amin&#039; attack. I must have caught the attack before anything malicious was done as none of my files were modified (thus not tripping the Securi alarm). I found multiple rows in the DB with base64 garbage in them and lots of unknown users in the users table. I also found some malicious PHP files within the plugins folder. </p>
<p>And yes&#8230;.ALL of my affected websites were hosted on Rackspace Cloud.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kevin</title>
		<link>http://blog.sucuri.net/2010/06/mass-attack-of-wordpress-blogs-on-rackspace.html/comment-page-1#comment-1005</link>
		<dc:creator>Kevin</dc:creator>
		<pubDate>Tue, 15 Jun 2010 22:49:26 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=296#comment-1005</guid>
		<description> Cloud Sites (which is their shared hosting) got hit too. 
My recent post &lt;a href=&quot;http://feeds.unfocus.com/~r/unfocus/projects/~3/QqjUQZim354/&quot; target=&quot;_blank&quot;&gt;I&#8217;m totally signing up for Final Fantasy XIV beta&lt;/a&gt; </description>
		<content:encoded><![CDATA[<p>Cloud Sites (which is their shared hosting) got hit too.<br />
My recent post <a href="http://feeds.unfocus.com/~r/unfocus/projects/~3/QqjUQZim354/" target="_blank">I&rsquo;m totally signing up for Final Fantasy XIV beta</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael VanDeMar</title>
		<link>http://blog.sucuri.net/2010/06/mass-attack-of-wordpress-blogs-on-rackspace.html/comment-page-1#comment-999</link>
		<dc:creator>Michael VanDeMar</dc:creator>
		<pubDate>Tue, 15 Jun 2010 20:55:01 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=296#comment-999</guid>
		<description>@anapologetos - no, Cloud Hosting. </description>
		<content:encoded><![CDATA[<p>@anapologetos &#8211; no, Cloud Hosting.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: anapologetos</title>
		<link>http://blog.sucuri.net/2010/06/mass-attack-of-wordpress-blogs-on-rackspace.html/comment-page-1#comment-994</link>
		<dc:creator>anapologetos</dc:creator>
		<pubDate>Tue, 15 Jun 2010 17:26:05 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=296#comment-994</guid>
		<description>I&#039;m assuming it was RS&#039;s shared hosting, correct? 
 
-Josh </description>
		<content:encoded><![CDATA[<p>I&#8217;m assuming it was RS&#8217;s shared hosting, correct? </p>
<p>-Josh</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tweets that mention Mass attack of Wordpress blogs on Rackspace &#124; Sucuri Security -- Topsy.com</title>
		<link>http://blog.sucuri.net/2010/06/mass-attack-of-wordpress-blogs-on-rackspace.html/comment-page-1#comment-993</link>
		<dc:creator>Tweets that mention Mass attack of Wordpress blogs on Rackspace &#124; Sucuri Security -- Topsy.com</dc:creator>
		<pubDate>Tue, 15 Jun 2010 17:16:50 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=296#comment-993</guid>
		<description>[...] This post was mentioned on Twitter by Sucuri, Richard, Clément Gagnon, WordPress Vibe, CERT-XMCO and others. CERT-XMCO said: RT @sucuri_security: ALERT: Mass Attack of WordPress sites on Rackspace http://bit.ly/dzW6eL #security #malware #infosec #hosting [...]</description>
		<content:encoded><![CDATA[<p>[...] This post was mentioned on Twitter by Sucuri, Richard, Clément Gagnon, WordPress Vibe, CERT-XMCO and others. CERT-XMCO said: RT @sucuri_security: ALERT: Mass Attack of WordPress sites on Rackspace <a href="http://bit.ly/dzW6eL" rel="nofollow">http://bit.ly/dzW6eL</a> #security #malware #infosec #hosting [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

