<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: WordPress hacked: googlerank.info</title>
	<atom:link href="http://creativebriefing.com/wordpress-hacked-googlerankinfo/feed/" rel="self" type="application/rss+xml" />
	<link>http://creativebriefing.com/wordpress-hacked-googlerankinfo/</link>
	<description>for the marketer, designer, and entrepreneur</description>
	<lastBuildDate>Thu, 11 Mar 2010 06:50:47 -0600</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Kevin S</title>
		<link>http://creativebriefing.com/wordpress-hacked-googlerankinfo/comment-page-2/#comment-4244</link>
		<dc:creator>Kevin S</dc:creator>
		<pubDate>Mon, 22 Jun 2009 11:31:09 +0000</pubDate>
		<guid isPermaLink="false">http://creativebriefing.com/wordpress-hacked-googlerankinfo/#comment-4244</guid>
		<description>This week one of the sites I work on was hacked and an iframe was placed in all index.php files, plus in the functions.php file in the wp-includes folder.

The specfic hack code is:
``

This code often overwrites the ending php tags in the file and thus brings the site down.

I have seen a couple of other threads on this (links at bottom), but not exactly the same code example, so wanted to bring it to light here to:

* Gauge how often it’s happening
* Share solutions
* Expose the culprits, if possible
* Alert WP team so they can review possible core level security measures

As to remedies and security measures to take, the other threads have given some good advise, and I plan to sweep my machine and those of other team members with FTP access (could be virus attached to our systems), check recent plugins, scan for virus’ on the hosting servers, and change all relevant security codes and settings. I will report again here, and encourage you to do same.

For permanent solution read more @ http://annanta.com/?p=338&lt;a href=&quot;http://annanta.com/?p=338&quot; rel=&quot;nofollow&quot;&gt;</description>
		<content:encoded><![CDATA[<p>This week one of the sites I work on was hacked and an iframe was placed in all index.php files, plus in the functions.php file in the wp-includes folder.</p>
<p>The specfic hack code is:<br />
&#8220;</p>
<p>This code often overwrites the ending php tags in the file and thus brings the site down.</p>
<p>I have seen a couple of other threads on this (links at bottom), but not exactly the same code example, so wanted to bring it to light here to:</p>
<p>* Gauge how often it’s happening<br />
* Share solutions<br />
* Expose the culprits, if possible<br />
* Alert WP team so they can review possible core level security measures</p>
<p>As to remedies and security measures to take, the other threads have given some good advise, and I plan to sweep my machine and those of other team members with FTP access (could be virus attached to our systems), check recent plugins, scan for virus’ on the hosting servers, and change all relevant security codes and settings. I will report again here, and encourage you to do same.</p>
<p>For permanent solution read more @ <a href="http://annanta.com/?p=338" rel="nofollow">http://annanta.com/?p=338</a><a href="http://annanta.com/?p=338" rel="nofollow"></a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John</title>
		<link>http://creativebriefing.com/wordpress-hacked-googlerankinfo/comment-page-2/#comment-4131</link>
		<dc:creator>John</dc:creator>
		<pubDate>Thu, 04 Jun 2009 03:32:51 +0000</pubDate>
		<guid isPermaLink="false">http://creativebriefing.com/wordpress-hacked-googlerankinfo/#comment-4131</guid>
		<description>Sorry, I meant 2.7.1.What bothers me is that I had upgraded to the new version recently and only then made the last post (which was one of two that were infected). The second post was made with an older version. Just like before, it was embedded right into the post. Not much info available on this for the new version. Your post was on top when I googled, only noticed the post was old when I started reading.</description>
		<content:encoded><![CDATA[<p>Sorry, I meant 2.7.1.What bothers me is that I had upgraded to the new version recently and only then made the last post (which was one of two that were infected). The second post was made with an older version. Just like before, it was embedded right into the post. Not much info available on this for the new version. Your post was on top when I googled, only noticed the post was old when I started reading.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rick</title>
		<link>http://creativebriefing.com/wordpress-hacked-googlerankinfo/comment-page-1/#comment-4128</link>
		<dc:creator>Rick</dc:creator>
		<pubDate>Wed, 03 Jun 2009 20:18:39 +0000</pubDate>
		<guid isPermaLink="false">http://creativebriefing.com/wordpress-hacked-googlerankinfo/#comment-4128</guid>
		<description>Are you sure you haven&#039;t got a hacked copy of Wordpress? The latest legitimate version is only 2.7.1.

But anyway, there are a lot of other ways into web hosting sites now - exploits of PHP, Apache and other stuff so I would check all of those as well.</description>
		<content:encoded><![CDATA[<p>Are you sure you haven&#8217;t got a hacked copy of Wordpress? The latest legitimate version is only 2.7.1.</p>
<p>But anyway, there are a lot of other ways into web hosting sites now &#8211; exploits of PHP, Apache and other stuff so I would check all of those as well.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John</title>
		<link>http://creativebriefing.com/wordpress-hacked-googlerankinfo/comment-page-1/#comment-4123</link>
		<dc:creator>John</dc:creator>
		<pubDate>Wed, 03 Jun 2009 05:39:33 +0000</pubDate>
		<guid isPermaLink="false">http://creativebriefing.com/wordpress-hacked-googlerankinfo/#comment-4123</guid>
		<description>I&#039;m running 2.7.2 and AVG just flagged my site. I checked the source and found an iframe. But it wasn&#039;t from tinymce. It was embedded right into my post :S I&#039;ve since updated the post and it seems to be clear. Still a bit worried though.</description>
		<content:encoded><![CDATA[<p>I&#8217;m running 2.7.2 and AVG just flagged my site. I checked the source and found an iframe. But it wasn&#8217;t from tinymce. It was embedded right into my post :S I&#8217;ve since updated the post and it seems to be clear. Still a bit worried though.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: E-TARD</title>
		<link>http://creativebriefing.com/wordpress-hacked-googlerankinfo/comment-page-1/#comment-3864</link>
		<dc:creator>E-TARD</dc:creator>
		<pubDate>Sun, 05 Apr 2009 16:42:35 +0000</pubDate>
		<guid isPermaLink="false">http://creativebriefing.com/wordpress-hacked-googlerankinfo/#comment-3864</guid>
		<description>Hmm interesting</description>
		<content:encoded><![CDATA[<p>Hmm interesting</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Katalogs</title>
		<link>http://creativebriefing.com/wordpress-hacked-googlerankinfo/comment-page-1/#comment-3766</link>
		<dc:creator>Katalogs</dc:creator>
		<pubDate>Thu, 05 Mar 2009 08:37:47 +0000</pubDate>
		<guid isPermaLink="false">http://creativebriefing.com/wordpress-hacked-googlerankinfo/#comment-3766</guid>
		<description>This is interesting</description>
		<content:encoded><![CDATA[<p>This is interesting</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: iCarly cds</title>
		<link>http://creativebriefing.com/wordpress-hacked-googlerankinfo/comment-page-1/#comment-3709</link>
		<dc:creator>iCarly cds</dc:creator>
		<pubDate>Mon, 26 Jan 2009 23:35:43 +0000</pubDate>
		<guid isPermaLink="false">http://creativebriefing.com/wordpress-hacked-googlerankinfo/#comment-3709</guid>
		<description>Crazy what wordpress has involved into</description>
		<content:encoded><![CDATA[<p>Crazy what wordpress has involved into</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rich B</title>
		<link>http://creativebriefing.com/wordpress-hacked-googlerankinfo/comment-page-1/#comment-3687</link>
		<dc:creator>Rich B</dc:creator>
		<pubDate>Tue, 20 Jan 2009 21:36:09 +0000</pubDate>
		<guid isPermaLink="false">http://creativebriefing.com/wordpress-hacked-googlerankinfo/#comment-3687</guid>
		<description>The bug may have reared it&#039;s ugly head again. Was at a site this morning, no problems, just returned to it and my AVG cut me off with the message of Virus name JS/Psyme.QM as a trojan so someone may have re-introduced it or else upgraded it to get in to the current version of Wordpress.</description>
		<content:encoded><![CDATA[<p>The bug may have reared it&#8217;s ugly head again. Was at a site this morning, no problems, just returned to it and my AVG cut me off with the message of Virus name JS/Psyme.QM as a trojan so someone may have re-introduced it or else upgraded it to get in to the current version of Wordpress.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: FMS GROUP</title>
		<link>http://creativebriefing.com/wordpress-hacked-googlerankinfo/comment-page-1/#comment-3325</link>
		<dc:creator>FMS GROUP</dc:creator>
		<pubDate>Wed, 30 Jul 2008 22:51:06 +0000</pubDate>
		<guid isPermaLink="false">http://creativebriefing.com/wordpress-hacked-googlerankinfo/#comment-3325</guid>
		<description>Thanks for the heads up :)</description>
		<content:encoded><![CDATA[<p>Thanks for the heads up :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Niyaz</title>
		<link>http://creativebriefing.com/wordpress-hacked-googlerankinfo/comment-page-1/#comment-3315</link>
		<dc:creator>Niyaz</dc:creator>
		<pubDate>Wed, 23 Jul 2008 10:46:14 +0000</pubDate>
		<guid isPermaLink="false">http://creativebriefing.com/wordpress-hacked-googlerankinfo/#comment-3315</guid>
		<description>Well New Versions of WP are out now with more security .. Like People Say until there is the software.. hackers will be too :D</description>
		<content:encoded><![CDATA[<p>Well New Versions of WP are out now with more security .. Like People Say until there is the software.. hackers will be too :D</p>
]]></content:encoded>
	</item>
</channel>
</rss>
