<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Did your WordPress site get hacked?</title>
	<atom:link href="http://ocaoimh.ie/did-your-wordpress-site-get-hacked/feed/" rel="self" type="application/rss+xml" />
	<link>http://ocaoimh.ie/did-your-wordpress-site-get-hacked/</link>
	<description>Look what I found today!</description>
	<lastBuildDate>Sat, 20 Mar 2010 20:04:49 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: vince</title>
		<link>http://ocaoimh.ie/did-your-wordpress-site-get-hacked/comment-page-3/#comment-673735</link>
		<dc:creator>vince</dc:creator>
		<pubDate>Wed, 17 Mar 2010 06:16:12 +0000</pubDate>
		<guid isPermaLink="false">http://ocaoimh.ie/?p=89493734#comment-673735</guid>
		<description>Ok First up.

1. I have 5 wordpress sites all got hacked into during March. The first one www.vincecianci.com is reported as an attack site and supposedly has malware on it. The google message appears upon trying to load the site. The same thing has happened on my other sites too.

2. I cant access ANY of my sites though the standard wordpress login page as If my own passwords have been changed. 

3. I am not tech savy at all. I checked most of my files on each of the 5 wordpress sites and it appears ok to me but what do I know. I have zero php, ftp experience. My hosting provider GoDaddy cant do anything so I feel I am out of options.

Any ideas here guys??

Vince.</description>
		<content:encoded><![CDATA[<p>Ok First up.</p>
<p>1. I have 5 wordpress sites all got hacked into during March. The first one <a href="http://www.vincecianci.com" rel="nofollow">http://www.vincecianci.com</a> is reported as an attack site and supposedly has malware on it. The google message appears upon trying to load the site. The same thing has happened on my other sites too.</p>
<p>2. I cant access ANY of my sites though the standard wordpress login page as If my own passwords have been changed. </p>
<p>3. I am not tech savy at all. I checked most of my files on each of the 5 wordpress sites and it appears ok to me but what do I know. I have zero php, ftp experience. My hosting provider GoDaddy cant do anything so I feel I am out of options.</p>
<p>Any ideas here guys??</p>
<p>Vince.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Faith</title>
		<link>http://ocaoimh.ie/did-your-wordpress-site-get-hacked/comment-page-3/#comment-673430</link>
		<dc:creator>Faith</dc:creator>
		<pubDate>Fri, 12 Mar 2010 10:24:05 +0000</pubDate>
		<guid isPermaLink="false">http://ocaoimh.ie/?p=89493734#comment-673430</guid>
		<description>I use WPMU and Love WordPress !! I Had 13 sites totaling 4000+ &quot;Real&quot;members,and with in a few hours I had 10,000+Fake members all mixed in !And no sites ! most of the Fake blogs and user emails I noticed (later) were short first name sounding and all had numbers ending that short name, like saally272645343 had matching emails like saally272645343@whateverfake.com
I Also found a theme with files all cute and pretty :{  with images labeled as alott of the codes you mention above, theme was named flavour-extended-png in the themes folder, I am almost sure it is infected.Thank you for all the help wordpress world :)

Keep the Faith :)</description>
		<content:encoded><![CDATA[<p>I use WPMU and Love WordPress !! I Had 13 sites totaling 4000+ &#8220;Real&#8221;members,and with in a few hours I had 10,000+Fake members all mixed in !And no sites ! most of the Fake blogs and user emails I noticed (later) were short first name sounding and all had numbers ending that short name, like saally272645343 had matching emails like <a href="mailto:saally272645343@whateverfake.com">saally272645343@whateverfake.com</a><br />
I Also found a theme with files all cute and pretty :{  with images labeled as alott of the codes you mention above, theme was named flavour-extended-png in the themes folder, I am almost sure it is infected.Thank you for all the help wordpress world <img src='http://ocaoimh.ie/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Keep the Faith <img src='http://ocaoimh.ie/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cenay : Blogging Coach</title>
		<link>http://ocaoimh.ie/did-your-wordpress-site-get-hacked/comment-page-3/#comment-673428</link>
		<dc:creator>Cenay : Blogging Coach</dc:creator>
		<pubDate>Fri, 12 Mar 2010 09:19:15 +0000</pubDate>
		<guid isPermaLink="false">http://ocaoimh.ie/?p=89493734#comment-673428</guid>
		<description>I wanted to mention a couple of plugins that can really help keep your blog protected, especially to all you non-coding webmasters...

One is called Wordpress Firewall. It basically protects your Wordpress software from attempts to login, hack passwords or use the query strings to inject code or look for weaknesses. Pro&#039;s: Closes another door or two in the face of hackers. Con&#039;s: Have to ensure your current IP address is listed so you can edit your blog. (Check out whatismyip.com to find it)

Another is Wordpress Antivirus. This basically scans your theme files for injected type code. Tho not full proof, it does add another layer of possible protection. 

I also use Wordpress Scanner to scan my installation for security holes. 

Just Google any of these names and the word &quot;wordpress&quot; or &quot;plugin&quot; at the same time. 

And remember, the safety of your blog and your visitors is in your hands... get proactive.</description>
		<content:encoded><![CDATA[<p>I wanted to mention a couple of plugins that can really help keep your blog protected, especially to all you non-coding webmasters&#8230;</p>
<p>One is called Wordpress Firewall. It basically protects your Wordpress software from attempts to login, hack passwords or use the query strings to inject code or look for weaknesses. Pro&#8217;s: Closes another door or two in the face of hackers. Con&#8217;s: Have to ensure your current IP address is listed so you can edit your blog. (Check out whatismyip.com to find it)</p>
<p>Another is Wordpress Antivirus. This basically scans your theme files for injected type code. Tho not full proof, it does add another layer of possible protection. </p>
<p>I also use Wordpress Scanner to scan my installation for security holes. </p>
<p>Just Google any of these names and the word &#8220;wordpress&#8221; or &#8220;plugin&#8221; at the same time. </p>
<p>And remember, the safety of your blog and your visitors is in your hands&#8230; get proactive.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: VC</title>
		<link>http://ocaoimh.ie/did-your-wordpress-site-get-hacked/comment-page-3/#comment-673339</link>
		<dc:creator>VC</dc:creator>
		<pubDate>Tue, 09 Mar 2010 16:37:29 +0000</pubDate>
		<guid isPermaLink="false">http://ocaoimh.ie/?p=89493734#comment-673339</guid>
		<description>very helpful, thanks!  THis beats the mindless and annoying task of reloading everything!</description>
		<content:encoded><![CDATA[<p>very helpful, thanks!  THis beats the mindless and annoying task of reloading everything!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gaylea</title>
		<link>http://ocaoimh.ie/did-your-wordpress-site-get-hacked/comment-page-3/#comment-673305</link>
		<dc:creator>Gaylea</dc:creator>
		<pubDate>Mon, 08 Mar 2010 15:01:38 +0000</pubDate>
		<guid isPermaLink="false">http://ocaoimh.ie/?p=89493734#comment-673305</guid>
		<description>Hi Donnoha,
You&#039;ve given really great information here and I will definitely apply it.  I only have one problem: cant even get into the back end of my blog!! Do you have any suggestions? 

When i try to go in with firefox, my antivirus comes up with the Mal/iframe-f   If i try to go in with IE it doesnt let me even get near the blog front end or backend.

once i log in with firefox - everything goes to a white screen and hangs.  Had googled and tried to find out what to do but your information is more extensive.  do you ever do paid work? 

(coz I am at my wits end and i dont have enough knowledge of php to know what to delete and what not to)

i have upgraded, added exploit, have manually looked through files for obvious iframes (didnt look for the rest of the code you&#039;ve revealed here though). 
have downloaded, scanned for malware with 5 different programs, have deleted users, changed passwords, and stood on my head with this thing !!!

any advice is appreciated 

Please let me know about the paid thing

Thanks 
Gaylea</description>
		<content:encoded><![CDATA[<p>Hi Donnoha,<br />
You&#8217;ve given really great information here and I will definitely apply it.  I only have one problem: cant even get into the back end of my blog!! Do you have any suggestions? </p>
<p>When i try to go in with firefox, my antivirus comes up with the Mal/iframe-f   If i try to go in with IE it doesnt let me even get near the blog front end or backend.</p>
<p>once i log in with firefox &#8211; everything goes to a white screen and hangs.  Had googled and tried to find out what to do but your information is more extensive.  do you ever do paid work? </p>
<p>(coz I am at my wits end and i dont have enough knowledge of php to know what to delete and what not to)</p>
<p>i have upgraded, added exploit, have manually looked through files for obvious iframes (didnt look for the rest of the code you&#8217;ve revealed here though).<br />
have downloaded, scanned for malware with 5 different programs, have deleted users, changed passwords, and stood on my head with this thing !!!</p>
<p>any advice is appreciated </p>
<p>Please let me know about the paid thing</p>
<p>Thanks<br />
Gaylea</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Good to be back! &#124; John Arroyo</title>
		<link>http://ocaoimh.ie/did-your-wordpress-site-get-hacked/comment-page-3/#comment-673002</link>
		<dc:creator>Good to be back! &#124; John Arroyo</dc:creator>
		<pubDate>Sun, 28 Feb 2010 23:25:50 +0000</pubDate>
		<guid isPermaLink="false">http://ocaoimh.ie/?p=89493734#comment-673002</guid>
		<description>[...] http://ocaoimh.ie/did-your-wordpress-site-get-hacked/ [...]</description>
		<content:encoded><![CDATA[<p>[...] <a href="http://ocaoimh.ie/did-your-wordpress-site-get-hacked/" rel="nofollow">http://ocaoimh.ie/did-your-wordpress-site-get-hacked/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Unhacking your Wordpress installation &#124; Tongfamily Website</title>
		<link>http://ocaoimh.ie/did-your-wordpress-site-get-hacked/comment-page-3/#comment-672871</link>
		<dc:creator>Unhacking your Wordpress installation &#124; Tongfamily Website</dc:creator>
		<pubDate>Tue, 23 Feb 2010 21:31:26 +0000</pubDate>
		<guid isPermaLink="false">http://ocaoimh.ie/?p=89493734#comment-672871</guid>
		<description>[...] Did your Wordpress Site get hacked is a good pointer to fixing things. It is pretty insidious what can happened: [...]</description>
		<content:encoded><![CDATA[<p>[...] Did your Wordpress Site get hacked is a good pointer to fixing things. It is pretty insidious what can happened: [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: How I Remove Trojan.Script.Iframer in My Wordpress Blog That Sends Away My Visitors</title>
		<link>http://ocaoimh.ie/did-your-wordpress-site-get-hacked/comment-page-3/#comment-672560</link>
		<dc:creator>How I Remove Trojan.Script.Iframer in My Wordpress Blog That Sends Away My Visitors</dc:creator>
		<pubDate>Sun, 14 Feb 2010 01:04:20 +0000</pubDate>
		<guid isPermaLink="false">http://ocaoimh.ie/?p=89493734#comment-672560</guid>
		<description>[...] http://ocaoimh.ie/did-your-wordpress-site-get-hacked/ http://forum.kaspersky.com/lofiversion/index.php/t104035.html [...]</description>
		<content:encoded><![CDATA[<p>[...] <a href="http://ocaoimh.ie/did-your-wordpress-site-get-hacked/" rel="nofollow">http://ocaoimh.ie/did-your-wordpress-site-get-hacked/</a> <a href="http://forum.kaspersky.com/lofiversion/index.php/t104035.html" rel="nofollow">http://forum.kaspersky.com/lofiversion/index.php/t104035.html</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: My WordPress Installation Hacked on Netfirms</title>
		<link>http://ocaoimh.ie/did-your-wordpress-site-get-hacked/comment-page-3/#comment-672388</link>
		<dc:creator>My WordPress Installation Hacked on Netfirms</dc:creator>
		<pubDate>Mon, 08 Feb 2010 09:13:17 +0000</pubDate>
		<guid isPermaLink="false">http://ocaoimh.ie/?p=89493734#comment-672388</guid>
		<description>[...] as well go all the way and have longer (and more complicated) passwords created. Good References http://ocaoimh.ie/did-your-wordpress-site-get-hacked/ http://enthusiasm.cozy.org/archives/2010/01/argh-blog-hacked [...]</description>
		<content:encoded><![CDATA[<p>[...] as well go all the way and have longer (and more complicated) passwords created. Good References <a href="http://ocaoimh.ie/did-your-wordpress-site-get-hacked/" rel="nofollow">http://ocaoimh.ie/did-your-wordpress-site-get-hacked/</a> <a href="http://enthusiasm.cozy.org/archives/2010/01/argh-blog-hacked" rel="nofollow">http://enthusiasm.cozy.org/archives/2010/01/argh-blog-hacked</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: phpdude</title>
		<link>http://ocaoimh.ie/did-your-wordpress-site-get-hacked/comment-page-3/#comment-672377</link>
		<dc:creator>phpdude</dc:creator>
		<pubDate>Sun, 07 Feb 2010 23:29:39 +0000</pubDate>
		<guid isPermaLink="false">http://ocaoimh.ie/?p=89493734#comment-672377</guid>
		<description>i have been hacked too :(

at this year july ... bull shit! fucking hackers!</description>
		<content:encoded><![CDATA[<p>i have been hacked too <img src='http://ocaoimh.ie/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
<p>at this year july &#8230; bull shit! fucking hackers!</p>
]]></content:encoded>
	</item>
</channel>
</rss>
