<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Wordpress 2.0.5 Site got hacked using c99shell ?</title>
	<atom:link href="http://www.reaper-x.com/2006/11/03/wordpress-205-site-got-hacked-using-c99shell/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.reaper-x.com/2006/11/03/wordpress-205-site-got-hacked-using-c99shell/</link>
	<description>Technology, Games, Blogging ... Whatever</description>
	<lastBuildDate>Sat, 20 Mar 2010 07:22:54 +0700</lastBuildDate>
	
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: emily</title>
		<link>http://www.reaper-x.com/2006/11/03/wordpress-205-site-got-hacked-using-c99shell/comment-page-1/#comment-435712</link>
		<dc:creator>emily</dc:creator>
		<pubDate>Thu, 04 Mar 2010 07:41:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.reaper-x.com/2006/11/03/wordpress-205-site-got-hacked-using-c99shell.htm#comment-435712</guid>
		<description>I enjoy browsing this page, always find out random new stuff.
Emily R. from &lt;a href=&quot;http://www.huskytraining.net&quot; rel=&quot;nofollow&quot;&gt;Husky Tips&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>I enjoy browsing this page, always find out random new stuff.<br />
Emily R. from <a href="http://www.huskytraining.net" rel="nofollow">Husky Tips</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michelle Wong</title>
		<link>http://www.reaper-x.com/2006/11/03/wordpress-205-site-got-hacked-using-c99shell/comment-page-1/#comment-74990</link>
		<dc:creator>Michelle Wong</dc:creator>
		<pubDate>Sun, 10 Feb 2008 05:48:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.reaper-x.com/2006/11/03/wordpress-205-site-got-hacked-using-c99shell.htm#comment-74990</guid>
		<description>Thanks for the great information. I just suscribed to your blog feed.Michelle,&lt;a href=&quot;http://www.hostgator-coupons.org/&quot; rel=&quot;nofollow&quot;&gt; HostGator Coupons&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>Thanks for the great information. I just suscribed to your blog feed.Michelle,<a href="http://www.hostgator-coupons.org/" rel="nofollow"> HostGator Coupons</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mahmoud</title>
		<link>http://www.reaper-x.com/2006/11/03/wordpress-205-site-got-hacked-using-c99shell/comment-page-1/#comment-13275</link>
		<dc:creator>mahmoud</dc:creator>
		<pubDate>Fri, 04 May 2007 16:11:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.reaper-x.com/2006/11/03/wordpress-205-site-got-hacked-using-c99shell.htm#comment-13275</guid>
		<description>eld&#111;&#111;&#107;&#121;2&#48;&#48;&#51;&#64;y&#97;&#104;&#111;o.&#99;o&#109;</description>
		<content:encoded><![CDATA[<p><a href="mailt&#111;:e&#108;doo&#107;y2&#48;&#48;3&#64;&#121;&#97;&#104;&#111;o&#46;&#99;o&#109;">&#101;&#108;d&#111;&#111;&#107;y2003&#64;&#121;&#97;hoo.&#99;o&#109;</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: gamal</title>
		<link>http://www.reaper-x.com/2006/11/03/wordpress-205-site-got-hacked-using-c99shell/comment-page-1/#comment-12860</link>
		<dc:creator>gamal</dc:creator>
		<pubDate>Thu, 05 Apr 2007 19:11:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.reaper-x.com/2006/11/03/wordpress-205-site-got-hacked-using-c99shell.htm#comment-12860</guid>
		<description>ukgjhhkhjj</description>
		<content:encoded><![CDATA[<p>ukgjhhkhjj</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: amin</title>
		<link>http://www.reaper-x.com/2006/11/03/wordpress-205-site-got-hacked-using-c99shell/comment-page-1/#comment-8953</link>
		<dc:creator>amin</dc:creator>
		<pubDate>Fri, 02 Mar 2007 15:55:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.reaper-x.com/2006/11/03/wordpress-205-site-got-hacked-using-c99shell.htm#comment-8953</guid>
		<description>help me</description>
		<content:encoded><![CDATA[<p>help me</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Christos</title>
		<link>http://www.reaper-x.com/2006/11/03/wordpress-205-site-got-hacked-using-c99shell/comment-page-1/#comment-5325</link>
		<dc:creator>Christos</dc:creator>
		<pubDate>Thu, 08 Feb 2007 00:55:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.reaper-x.com/2006/11/03/wordpress-205-site-got-hacked-using-c99shell.htm#comment-5325</guid>
		<description>It has nothing to do with blog software.
I had forgoten in my path the Appserv folder wich was indexed by the search engines and they used the &quot;README-th.php&quot; file to gain access.
What I found disturbing is that the injection was done by Yahoo Slurp. I don&#039;t know how they managed to make Yahoo do the job for them but they did.

The script-kiddies are capable of much more than what they’ve been doing Unfortunately.
The last one who gained access to my self-hosted server, erased the whole disk.
I guess I was lucky in unluckyness and pulled the plug while he was doing it so along with some other files the Apache log was saved
and I was able to track the events down and
found that it was I guy from Turkey.
I have enough evidence from the log file and also from a forum where he posted his evil doing but I don&#039;t know what can I do against him (legally I mean).
I did not only lost my sites I also lost about 70GB of data and software.</description>
		<content:encoded><![CDATA[<p>It has nothing to do with blog software.<br />
I had forgoten in my path the Appserv folder wich was indexed by the search engines and they used the &#8220;README-th.php&#8221; file to gain access.<br />
What I found disturbing is that the injection was done by Yahoo Slurp. I don&#8217;t know how they managed to make Yahoo do the job for them but they did.</p>
<p>The script-kiddies are capable of much more than what they’ve been doing Unfortunately.<br />
The last one who gained access to my self-hosted server, erased the whole disk.<br />
I guess I was lucky in unluckyness and pulled the plug while he was doing it so along with some other files the Apache log was saved<br />
and I was able to track the events down and<br />
found that it was I guy from Turkey.<br />
I have enough evidence from the log file and also from a forum where he posted his evil doing but I don&#8217;t know what can I do against him (legally I mean).<br />
I did not only lost my sites I also lost about 70GB of data and software.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Reaper-X</title>
		<link>http://www.reaper-x.com/2006/11/03/wordpress-205-site-got-hacked-using-c99shell/comment-page-1/#comment-868</link>
		<dc:creator>Reaper-X</dc:creator>
		<pubDate>Fri, 17 Nov 2006 12:02:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.reaper-x.com/2006/11/03/wordpress-205-site-got-hacked-using-c99shell.htm#comment-868</guid>
		<description>I see ... thanks a lot for that information, i really appreciate it .. but if it caused by xmlrpc then the problem is in the blog software itself :?</description>
		<content:encoded><![CDATA[<p>I see &#8230; thanks a lot for that information, i really appreciate it .. but if it caused by xmlrpc then the problem is in the blog software itself :?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: justinf</title>
		<link>http://www.reaper-x.com/2006/11/03/wordpress-205-site-got-hacked-using-c99shell/comment-page-1/#comment-867</link>
		<dc:creator>justinf</dc:creator>
		<pubDate>Fri, 17 Nov 2006 11:34:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.reaper-x.com/2006/11/03/wordpress-205-site-got-hacked-using-c99shell.htm#comment-867</guid>
		<description>my blog use Nucleus and even that was hacked with c99 - so its nothing to do with wordpress itself.  and my box is Fedora 5 with all the latest security patches.

from my logs , it seems to be a hack based on the xmlrpc component of a blog.</description>
		<content:encoded><![CDATA[<p>my blog use Nucleus and even that was hacked with c99 &#8211; so its nothing to do with wordpress itself.  and my box is Fedora 5 with all the latest security patches.</p>
<p>from my logs , it seems to be a hack based on the xmlrpc component of a blog.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: possum.kicks-ass.org &#187; Blog Archive &#187; I&#8217;ve Been Exploited</title>
		<link>http://www.reaper-x.com/2006/11/03/wordpress-205-site-got-hacked-using-c99shell/comment-page-1/#comment-805</link>
		<dc:creator>possum.kicks-ass.org &#187; Blog Archive &#187; I&#8217;ve Been Exploited</dc:creator>
		<pubDate>Mon, 13 Nov 2006 03:46:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.reaper-x.com/2006/11/03/wordpress-205-site-got-hacked-using-c99shell.htm#comment-805</guid>
		<description>[...] A couple days ago I noticed I had an unusual amount of traffic to my site from a number of IP addresses beginning with 222. I checked my logs and found out they had installed a backdoor into my Dreamhost user account, which was the web application called C99Shell. Obviously this is a serious vulnerability (just Google it) and I have worked to eliminate it from my site. Unfortunately, I noticed they had come back &#8212; with bash access. How they got it is beyond me, but I&#8217;ve taken some steps to prevent them from returning (changing my password, etc.) . I put this out here because the script-kiddies are capable of much more than what they&#8217;ve been doing (spamming) whether they know it or not. I&#8217;ve ensured that they have _not_ installed any viruses on any of my site, but take care while browsing not to use Internet Explorer, just in case anything _does_ happen. [...]</description>
		<content:encoded><![CDATA[<p>[...] A couple days ago I noticed I had an unusual amount of traffic to my site from a number of IP addresses beginning with 222. I checked my logs and found out they had installed a backdoor into my Dreamhost user account, which was the web application called C99Shell. Obviously this is a serious vulnerability (just Google it) and I have worked to eliminate it from my site. Unfortunately, I noticed they had come back &#8212; with bash access. How they got it is beyond me, but I&#8217;ve taken some steps to prevent them from returning (changing my password, etc.) . I put this out here because the script-kiddies are capable of much more than what they&#8217;ve been doing (spamming) whether they know it or not. I&#8217;ve ensured that they have _not_ installed any viruses on any of my site, but take care while browsing not to use Internet Explorer, just in case anything _does_ happen. [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
