<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Damn &#8230; my VPS is being cracked</title>
	<atom:link href="http://tiffanybbrown.com/2007/11/07/damn-my-vps-is-being-cracked/feed/" rel="self" type="application/rss+xml" />
	<link>http://tiffanybbrown.com/2007/11/07/damn-my-vps-is-being-cracked/</link>
	<description>A web log about web development and internet culture with frequent detours into other stuff.</description>
	<lastBuildDate>Fri, 03 Feb 2012 12:47:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Eric Caldwell</title>
		<link>http://tiffanybbrown.com/2007/11/07/damn-my-vps-is-being-cracked/comment-page-1/#comment-90486</link>
		<dc:creator>Eric Caldwell</dc:creator>
		<pubDate>Fri, 28 Dec 2007 21:16:31 +0000</pubDate>
		<guid isPermaLink="false">http://tiffanybbrown.com/2007/11/07/damn-my-vps-is-being-cracked/#comment-90486</guid>
		<description>I had the same issue lately and eggdrop and mocks were dropped in because of a vulnerable PHP script.  Once I found the corrupted scripts, I installed patched scripts, turned on safe mode for that account and then disabled the exec() function.  Since the hacker was from Taiwan, I also took the liberty of banning the IP address range for the IPS they were using.

It really is the wild-west out there.. Glad to hear I&#039;m not the only one whacking these weeds.</description>
		<content:encoded><![CDATA[<p>I had the same issue lately and eggdrop and mocks were dropped in because of a vulnerable PHP script.  Once I found the corrupted scripts, I installed patched scripts, turned on safe mode for that account and then disabled the exec() function.  Since the hacker was from Taiwan, I also took the liberty of banning the IP address range for the IPS they were using.</p>
<p>It really is the wild-west out there.. Glad to hear I&#8217;m not the only one whacking these weeds.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eric Caldwell</title>
		<link>http://tiffanybbrown.com/2007/11/07/damn-my-vps-is-being-cracked/comment-page-1/#comment-93050</link>
		<dc:creator>Eric Caldwell</dc:creator>
		<pubDate>Fri, 28 Dec 2007 21:16:00 +0000</pubDate>
		<guid isPermaLink="false">http://tiffanybbrown.com/2007/11/07/damn-my-vps-is-being-cracked/#comment-93050</guid>
		<description>I had the same issue lately and eggdrop and mocks were dropped in because of a vulnerable PHP script.  Once I found the corrupted scripts, I installed patched scripts, turned on safe mode for that account and then disabled the exec() function.  Since the hacker was from Taiwan, I also took the liberty of banning the IP address range for the IPS they were using.

It really is the wild-west out there.. Glad to hear I&#039;m not the only one whacking these weeds.</description>
		<content:encoded><![CDATA[<p>I had the same issue lately and eggdrop and mocks were dropped in because of a vulnerable PHP script.  Once I found the corrupted scripts, I installed patched scripts, turned on safe mode for that account and then disabled the exec() function.  Since the hacker was from Taiwan, I also took the liberty of banning the IP address range for the IPS they were using.</p>
<p>It really is the wild-west out there.. Glad to hear I&#8217;m not the only one whacking these weeds.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Vulnerability in WP Super Cache v0.1 &#124; FactoryCity</title>
		<link>http://tiffanybbrown.com/2007/11/07/damn-my-vps-is-being-cracked/comment-page-1/#comment-88368</link>
		<dc:creator>Vulnerability in WP Super Cache v0.1 &#124; FactoryCity</dc:creator>
		<pubDate>Fri, 09 Nov 2007 04:55:11 +0000</pubDate>
		<guid isPermaLink="false">http://tiffanybbrown.com/2007/11/07/damn-my-vps-is-being-cracked/#comment-88368</guid>
		<description>[...] had replied to me letting me know that Tiffany Brown was having a similar experience (though with greater consequence) and a report in the WordPress forums. Both Kristie Wells from Joyent and Donncha got back to me, [...]</description>
		<content:encoded><![CDATA[<p>[...] had replied to me letting me know that Tiffany Brown was having a similar experience (though with greater consequence) and a report in the WordPress forums. Both Kristie Wells from Joyent and Donncha got back to me, [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tiffany</title>
		<link>http://tiffanybbrown.com/2007/11/07/damn-my-vps-is-being-cracked/comment-page-1/#comment-88336</link>
		<dc:creator>tiffany</dc:creator>
		<pubDate>Wed, 07 Nov 2007 22:24:25 +0000</pubDate>
		<guid isPermaLink="false">http://tiffanybbrown.com/2007/11/07/damn-my-vps-is-being-cracked/#comment-88336</guid>
		<description>Thanks Chris... I think I upgraded WP a couple of days too late. I figured it was WP related though because the only URLs they were trying were WP URLs on this blog.

I thought the XMLRPC issue had been fixed a couple of years ago. 

As an extra precaution I disabled exec() -- the only function the attacker tried that I &lt;em&gt;hadn&#039;t&lt;/em&gt; disabled before now (d&#039;oh!). With any luck that will do it.</description>
		<content:encoded><![CDATA[<p>Thanks Chris&#8230; I think I upgraded WP a couple of days too late. I figured it was WP related though because the only URLs they were trying were WP URLs on this blog.</p>
<p>I thought the XMLRPC issue had been fixed a couple of years ago. </p>
<p>As an extra precaution I disabled exec() &#8212; the only function the attacker tried that I <em>hadn&#8217;t</em> disabled before now (d&#8217;oh!). With any luck that will do it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tiffany</title>
		<link>http://tiffanybbrown.com/2007/11/07/damn-my-vps-is-being-cracked/comment-page-1/#comment-93049</link>
		<dc:creator>tiffany</dc:creator>
		<pubDate>Wed, 07 Nov 2007 22:24:00 +0000</pubDate>
		<guid isPermaLink="false">http://tiffanybbrown.com/2007/11/07/damn-my-vps-is-being-cracked/#comment-93049</guid>
		<description>Thanks Chris... I think I upgraded WP a couple of days too late. I figured it was WP related though because the only URLs they were trying were WP URLs on this blog.

I thought the XMLRPC issue had been fixed a couple of years ago. 

As an extra precaution I disabled exec() -- the only function the attacker tried that I &lt;em&gt;hadn&#039;t&lt;/em&gt; disabled before now (d&#039;oh!). With any luck that will do it.</description>
		<content:encoded><![CDATA[<p>Thanks Chris&#8230; I think I upgraded WP a couple of days too late. I figured it was WP related though because the only URLs they were trying were WP URLs on this blog.</p>
<p>I thought the XMLRPC issue had been fixed a couple of years ago. </p>
<p>As an extra precaution I disabled exec() &#8212; the only function the attacker tried that I <em>hadn&#8217;t</em> disabled before now (d&#8217;oh!). With any luck that will do it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Heilmann</title>
		<link>http://tiffanybbrown.com/2007/11/07/damn-my-vps-is-being-cracked/comment-page-1/#comment-88335</link>
		<dc:creator>Chris Heilmann</dc:creator>
		<pubDate>Wed, 07 Nov 2007 22:20:49 +0000</pubDate>
		<guid isPermaLink="false">http://tiffanybbrown.com/2007/11/07/damn-my-vps-is-being-cracked/#comment-88335</guid>
		<description>I had a similar problem before I upgraded to 2.3.1. In my case it was the trackback and the old version of XMLRPC that was vulnerable to exec() commands and file generation.</description>
		<content:encoded><![CDATA[<p>I had a similar problem before I upgraded to 2.3.1. In my case it was the trackback and the old version of XMLRPC that was vulnerable to exec() commands and file generation.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Heilmann</title>
		<link>http://tiffanybbrown.com/2007/11/07/damn-my-vps-is-being-cracked/comment-page-1/#comment-93048</link>
		<dc:creator>Chris Heilmann</dc:creator>
		<pubDate>Wed, 07 Nov 2007 22:20:00 +0000</pubDate>
		<guid isPermaLink="false">http://tiffanybbrown.com/2007/11/07/damn-my-vps-is-being-cracked/#comment-93048</guid>
		<description>I had a similar problem before I upgraded to 2.3.1. In my case it was the trackback and the old version of XMLRPC that was vulnerable to exec() commands and file generation.</description>
		<content:encoded><![CDATA[<p>I had a similar problem before I upgraded to 2.3.1. In my case it was the trackback and the old version of XMLRPC that was vulnerable to exec() commands and file generation.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tiffany</title>
		<link>http://tiffanybbrown.com/2007/11/07/damn-my-vps-is-being-cracked/comment-page-1/#comment-88331</link>
		<dc:creator>tiffany</dc:creator>
		<pubDate>Wed, 07 Nov 2007 20:21:12 +0000</pubDate>
		<guid isPermaLink="false">http://tiffanybbrown.com/2007/11/07/damn-my-vps-is-being-cracked/#comment-88331</guid>
		<description>Man, so would I :-). I know what they&#039;re doing once they&#039;re in. But I don&#039;t know how they&#039;re getting in.</description>
		<content:encoded><![CDATA[<p>Man, so would I <img src='http://tiffanybbrown.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> . I know what they&#8217;re doing once they&#8217;re in. But I don&#8217;t know how they&#8217;re getting in.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tiffany</title>
		<link>http://tiffanybbrown.com/2007/11/07/damn-my-vps-is-being-cracked/comment-page-1/#comment-93047</link>
		<dc:creator>tiffany</dc:creator>
		<pubDate>Wed, 07 Nov 2007 20:21:00 +0000</pubDate>
		<guid isPermaLink="false">http://tiffanybbrown.com/2007/11/07/damn-my-vps-is-being-cracked/#comment-93047</guid>
		<description>Man, so would I :-). I know what they&#039;re doing once they&#039;re in. But I don&#039;t know how they&#039;re getting in.</description>
		<content:encoded><![CDATA[<p>Man, so would I <img src='http://tiffanybbrown.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> . I know what they&#8217;re doing once they&#8217;re in. But I don&#8217;t know how they&#8217;re getting in.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Markus</title>
		<link>http://tiffanybbrown.com/2007/11/07/damn-my-vps-is-being-cracked/comment-page-1/#comment-88329</link>
		<dc:creator>Markus</dc:creator>
		<pubDate>Wed, 07 Nov 2007 20:05:39 +0000</pubDate>
		<guid isPermaLink="false">http://tiffanybbrown.com/2007/11/07/damn-my-vps-is-being-cracked/#comment-88329</guid>
		<description>I have been there before! Let me know if you need another set of eyes to look @ those server logs. I would love to know how they got in.</description>
		<content:encoded><![CDATA[<p>I have been there before! Let me know if you need another set of eyes to look @ those server logs. I would love to know how they got in.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Markus</title>
		<link>http://tiffanybbrown.com/2007/11/07/damn-my-vps-is-being-cracked/comment-page-1/#comment-93046</link>
		<dc:creator>Markus</dc:creator>
		<pubDate>Wed, 07 Nov 2007 20:05:00 +0000</pubDate>
		<guid isPermaLink="false">http://tiffanybbrown.com/2007/11/07/damn-my-vps-is-being-cracked/#comment-93046</guid>
		<description>I have been there before! Let me know if you need another set of eyes to look @ those server logs. I would love to know how they got in.</description>
		<content:encoded><![CDATA[<p>I have been there before! Let me know if you need another set of eyes to look @ those server logs. I would love to know how they got in.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

