<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Maintenence Tonight</title>
	<atom:link href="http://www.bittbox.com/news/maintenence-tonight/feed" rel="self" type="application/rss+xml" />
	<link>http://www.bittbox.com/news/maintenence-tonight</link>
	<description>Free Design Resources including free vectors, buttons, icons, fading corners, quick tips, tutorials and more.</description>
	<lastBuildDate>Sun, 08 Nov 2009 06:06:24 -0800</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: kablo kanali</title>
		<link>http://www.bittbox.com/news/maintenence-tonight/comment-page-1#comment-10624</link>
		<dc:creator>kablo kanali</dc:creator>
		<pubDate>Mon, 03 Dec 2007 15:44:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.bittbox.com/news/maintenence-tonight/#comment-10624</guid>
		<description>thanks</description>
		<content:encoded><![CDATA[<p>thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark</title>
		<link>http://www.bittbox.com/news/maintenence-tonight/comment-page-1#comment-10103</link>
		<dc:creator>Mark</dc:creator>
		<pubDate>Fri, 16 Nov 2007 17:09:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.bittbox.com/news/maintenence-tonight/#comment-10103</guid>
		<description>Hi Bittbox,

It&#039;s just accepted best practice to not publish/advertise/glorify the work of script kiddies. 

They&#039;re in the cracking business for glory/backlinks(money), take away both and they lose their motive.

Maybe I&#039;m being naive, but nevertheless, that is my view and just a suggestion. 

Cheers</description>
		<content:encoded><![CDATA[<p>Hi Bittbox,</p>
<p>It&#8217;s just accepted best practice to not publish/advertise/glorify the work of script kiddies. </p>
<p>They&#8217;re in the cracking business for glory/backlinks(money), take away both and they lose their motive.</p>
<p>Maybe I&#8217;m being naive, but nevertheless, that is my view and just a suggestion. </p>
<p>Cheers</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom</title>
		<link>http://www.bittbox.com/news/maintenence-tonight/comment-page-1#comment-10001</link>
		<dc:creator>Tom</dc:creator>
		<pubDate>Wed, 14 Nov 2007 05:36:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.bittbox.com/news/maintenence-tonight/#comment-10001</guid>
		<description>Jason:

&gt; (Tom) Not sure why PHP is the issue…properly coded PHP works just fine.

Properly coded Java works just fine. That doesn&#039;t mean it is good.

The problem is that PHP, out of the box, is terribly insecure. (check out that there is a &quot;safe mode&quot; for it and look at how many options there are for that).

It is only made worse by the culture of PHP development. I have seen a lot of PHP. Most of it completely fails to incorporate even the most basic concepts of modularity, abstraction and code reuse.  It is often the victim of the worst thing computers ever gave us: copy and paste.

Besides .... As far as I am concerned, PHP is a &quot;dumbed down&quot; Perl. Why not just do everything in Perl? That way, you can keep your code OUT of the document directory like it SHOULD be. 

ALL of WordPress&#039;s executable code is in one directory tree, starting at the DocumentRoot. This is ... not wise.</description>
		<content:encoded><![CDATA[<p>Jason:</p>
<p>&gt; (Tom) Not sure why PHP is the issue…properly coded PHP works just fine.</p>
<p>Properly coded Java works just fine. That doesn&#8217;t mean it is good.</p>
<p>The problem is that PHP, out of the box, is terribly insecure. (check out that there is a &#8220;safe mode&#8221; for it and look at how many options there are for that).</p>
<p>It is only made worse by the culture of PHP development. I have seen a lot of PHP. Most of it completely fails to incorporate even the most basic concepts of modularity, abstraction and code reuse.  It is often the victim of the worst thing computers ever gave us: copy and paste.</p>
<p>Besides &#8230;. As far as I am concerned, PHP is a &#8220;dumbed down&#8221; Perl. Why not just do everything in Perl? That way, you can keep your code OUT of the document directory like it SHOULD be. </p>
<p>ALL of WordPress&#8217;s executable code is in one directory tree, starting at the DocumentRoot. This is &#8230; not wise.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Oliver</title>
		<link>http://www.bittbox.com/news/maintenence-tonight/comment-page-1#comment-9994</link>
		<dc:creator>Oliver</dc:creator>
		<pubDate>Wed, 14 Nov 2007 02:30:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.bittbox.com/news/maintenence-tonight/#comment-9994</guid>
		<description>If it&#039;s any consolation even sites run by programmers get bitten: I found the same message on ajaxian.com a while back (they seem to have fixed the issue)</description>
		<content:encoded><![CDATA[<p>If it&#8217;s any consolation even sites run by programmers get bitten: I found the same message on ajaxian.com a while back (they seem to have fixed the issue)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gilfil</title>
		<link>http://www.bittbox.com/news/maintenence-tonight/comment-page-1#comment-9986</link>
		<dc:creator>Gilfil</dc:creator>
		<pubDate>Wed, 14 Nov 2007 00:11:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.bittbox.com/news/maintenence-tonight/#comment-9986</guid>
		<description>One of my blogs was affected by this &quot;hack&quot;.

I could identify that everytime that the word &quot;Select&quot; or &quot;select&quot; is placed in a form or query (both GET and POST) on the URL, the hack attacks.

I have more than one blog running wordpress on the box, and only one was affected.

I am now replacing the full script....</description>
		<content:encoded><![CDATA[<p>One of my blogs was affected by this &#8220;hack&#8221;.</p>
<p>I could identify that everytime that the word &#8220;Select&#8221; or &#8220;select&#8221; is placed in a form or query (both GET and POST) on the URL, the hack attacks.</p>
<p>I have more than one blog running wordpress on the box, and only one was affected.</p>
<p>I am now replacing the full script&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BittBox</title>
		<link>http://www.bittbox.com/news/maintenence-tonight/comment-page-1#comment-9982</link>
		<dc:creator>BittBox</dc:creator>
		<pubDate>Tue, 13 Nov 2007 22:24:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.bittbox.com/news/maintenence-tonight/#comment-9982</guid>
		<description>Dino,

I wasn&#039;t even using it, My sidebar uses the widget that comes with wordpress

~Bitt</description>
		<content:encoded><![CDATA[<p>Dino,</p>
<p>I wasn&#8217;t even using it, My sidebar uses the widget that comes with wordpress</p>
<p>~Bitt</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dino</title>
		<link>http://www.bittbox.com/news/maintenence-tonight/comment-page-1#comment-9981</link>
		<dc:creator>Dino</dc:creator>
		<pubDate>Tue, 13 Nov 2007 22:22:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.bittbox.com/news/maintenence-tonight/#comment-9981</guid>
		<description>Now why would somebody use a plugin for bringing out the Recent Posts? You can actually just use the WordPress loop. :)</description>
		<content:encoded><![CDATA[<p>Now why would somebody use a plugin for bringing out the Recent Posts? You can actually just use the WordPress loop. :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Amy Gahran</title>
		<link>http://www.bittbox.com/news/maintenence-tonight/comment-page-1#comment-9980</link>
		<dc:creator>Amy Gahran</dc:creator>
		<pubDate>Tue, 13 Nov 2007 21:57:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.bittbox.com/news/maintenence-tonight/#comment-9980</guid>
		<description>Jay

On my blog, the problem was a hacked Akismet plugin, which has now been reinstalled.

Doesn&#039;t look like they&#039;re targeting one particular plugin, could be any plugin. But you and I were both hacked via plugins.

- Amy Gahran</description>
		<content:encoded><![CDATA[<p>Jay</p>
<p>On my blog, the problem was a hacked Akismet plugin, which has now been reinstalled.</p>
<p>Doesn&#8217;t look like they&#8217;re targeting one particular plugin, could be any plugin. But you and I were both hacked via plugins.</p>
<p>- Amy Gahran</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jason</title>
		<link>http://www.bittbox.com/news/maintenence-tonight/comment-page-1#comment-9979</link>
		<dc:creator>jason</dc:creator>
		<pubDate>Tue, 13 Nov 2007 21:55:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.bittbox.com/news/maintenence-tonight/#comment-9979</guid>
		<description>(Tom) Not sure why PHP is the issue...properly coded PHP works just fine.  Unfortunately significant portions of the open source community fail to code the necessary variable checking routines necessary to safely process data.

Bitt - I&#039;m glad to hear that you found the vulnerable plugin...

jason...</description>
		<content:encoded><![CDATA[<p>(Tom) Not sure why PHP is the issue&#8230;properly coded PHP works just fine.  Unfortunately significant portions of the open source community fail to code the necessary variable checking routines necessary to safely process data.</p>
<p>Bitt &#8211; I&#8217;m glad to hear that you found the vulnerable plugin&#8230;</p>
<p>jason&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BittBox</title>
		<link>http://www.bittbox.com/news/maintenence-tonight/comment-page-1#comment-9976</link>
		<dc:creator>BittBox</dc:creator>
		<pubDate>Tue, 13 Nov 2007 19:36:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.bittbox.com/news/maintenence-tonight/#comment-9976</guid>
		<description>Mark, 
May I ask why?
~BItt</description>
		<content:encoded><![CDATA[<p>Mark,<br />
May I ask why?<br />
~BItt</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Israel Jernigan</title>
		<link>http://www.bittbox.com/news/maintenence-tonight/comment-page-1#comment-9974</link>
		<dc:creator>Israel Jernigan</dc:creator>
		<pubDate>Tue, 13 Nov 2007 19:20:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.bittbox.com/news/maintenence-tonight/#comment-9974</guid>
		<description>Awesome!!!! Glad you might have found the problem.</description>
		<content:encoded><![CDATA[<p>Awesome!!!! Glad you might have found the problem.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark</title>
		<link>http://www.bittbox.com/news/maintenence-tonight/comment-page-1#comment-9973</link>
		<dc:creator>Mark</dc:creator>
		<pubDate>Tue, 13 Nov 2007 19:20:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.bittbox.com/news/maintenence-tonight/#comment-9973</guid>
		<description>Bitt,

Please remove &quot;Hacked by .....&quot; from your post. &quot;Hacked by kiddies&quot; will do.

Thanks</description>
		<content:encoded><![CDATA[<p>Bitt,</p>
<p>Please remove &#8220;Hacked by &#8230;..&#8221; from your post. &#8220;Hacked by kiddies&#8221; will do.</p>
<p>Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BittBox</title>
		<link>http://www.bittbox.com/news/maintenence-tonight/comment-page-1#comment-9972</link>
		<dc:creator>BittBox</dc:creator>
		<pubDate>Tue, 13 Nov 2007 19:07:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.bittbox.com/news/maintenence-tonight/#comment-9972</guid>
		<description>Jonic You Rock! 

A friend of mine in the UK found the problem. It was a hacked version of the &quot;Recent Posts&quot; plug-in. I deleted it and it seems to have fixed the problem! Still making sure. Thanks to everyone for helping.

~Bitt</description>
		<content:encoded><![CDATA[<p>Jonic You Rock! </p>
<p>A friend of mine in the UK found the problem. It was a hacked version of the &#8220;Recent Posts&#8221; plug-in. I deleted it and it seems to have fixed the problem! Still making sure. Thanks to everyone for helping.</p>
<p>~Bitt</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MAD_MAN</title>
		<link>http://www.bittbox.com/news/maintenence-tonight/comment-page-1#comment-9970</link>
		<dc:creator>MAD_MAN</dc:creator>
		<pubDate>Tue, 13 Nov 2007 18:51:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.bittbox.com/news/maintenence-tonight/#comment-9970</guid>
		<description>hay, good luck ... sorry i cant help you :( didn&#039;t have to deal which security issues till now ...

lg mad_man</description>
		<content:encoded><![CDATA[<p>hay, good luck &#8230; sorry i cant help you :( didn&#8217;t have to deal which security issues till now &#8230;</p>
<p>lg mad_man</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gerardo</title>
		<link>http://www.bittbox.com/news/maintenence-tonight/comment-page-1#comment-9968</link>
		<dc:creator>Gerardo</dc:creator>
		<pubDate>Tue, 13 Nov 2007 16:54:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.bittbox.com/news/maintenence-tonight/#comment-9968</guid>
		<description>Bitt that sucks im pretty sure that if you ask the support people of wordpress might help you out finding the problem.-

best of luck 

Gg</description>
		<content:encoded><![CDATA[<p>Bitt that sucks im pretty sure that if you ask the support people of wordpress might help you out finding the problem.-</p>
<p>best of luck </p>
<p>Gg</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dersu</title>
		<link>http://www.bittbox.com/news/maintenence-tonight/comment-page-1#comment-9967</link>
		<dc:creator>dersu</dc:creator>
		<pubDate>Tue, 13 Nov 2007 16:45:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.bittbox.com/news/maintenence-tonight/#comment-9967</guid>
		<description>f&#039;in hackers, best of luck. looking forward to your return.</description>
		<content:encoded><![CDATA[<p>f&#8217;in hackers, best of luck. looking forward to your return.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom</title>
		<link>http://www.bittbox.com/news/maintenence-tonight/comment-page-1#comment-9966</link>
		<dc:creator>Tom</dc:creator>
		<pubDate>Tue, 13 Nov 2007 16:38:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.bittbox.com/news/maintenence-tonight/#comment-9966</guid>
		<description>Yet another reason I don&#039;t like PHP.</description>
		<content:encoded><![CDATA[<p>Yet another reason I don&#8217;t like PHP.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BittBox</title>
		<link>http://www.bittbox.com/news/maintenence-tonight/comment-page-1#comment-9965</link>
		<dc:creator>BittBox</dc:creator>
		<pubDate>Tue, 13 Nov 2007 16:33:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.bittbox.com/news/maintenence-tonight/#comment-9965</guid>
		<description>Amy,

I&#039;m running the latest version of WP, so that won&#039;t fix it. :(

~Bitt</description>
		<content:encoded><![CDATA[<p>Amy,</p>
<p>I&#8217;m running the latest version of WP, so that won&#8217;t fix it. :(</p>
<p>~Bitt</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: contentious.com - This blog is still hacked, grrrrrrr&#8230;..</title>
		<link>http://www.bittbox.com/news/maintenence-tonight/comment-page-1#comment-9964</link>
		<dc:creator>contentious.com - This blog is still hacked, grrrrrrr&#8230;..</dc:creator>
		<pubDate>Tue, 13 Nov 2007 16:17:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.bittbox.com/news/maintenence-tonight/#comment-9964</guid>
		<description>[...] The blog BittBox is experiencing an identical problem. The comment thread there offers some [...]</description>
		<content:encoded><![CDATA[<p>[...] The blog BittBox is experiencing an identical problem. The comment thread there offers some [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Amy Gahran</title>
		<link>http://www.bittbox.com/news/maintenence-tonight/comment-page-1#comment-9963</link>
		<dc:creator>Amy Gahran</dc:creator>
		<pubDate>Tue, 13 Nov 2007 16:06:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.bittbox.com/news/maintenence-tonight/#comment-9963</guid>
		<description>Damn! This same exact thing just happened to me, and I have to prepare for a big trip too. Bad timing.

See: http://snipurl.com/1tktf

By any chance were you at Blogworld Expo? I was on the open wifi there and suspect that&#039;s where the hacker sniffed my password.

I&#039;m also currently running an older version of Wordpress. I&#039;ve arranged for an upgrade, but that hasn&#039;t happened yet.

Sounds like from what your commenters say that more might have been compromised on your site, and mine, than just Wordpress. I&#039;m in over my head here, I don&#039;t really understand server-side stuff. I&#039;d appreciate assistance for how to fix this and secure my site more appropriately. I&#039;ll be watching this thread for tips.

- Amy Gahran</description>
		<content:encoded><![CDATA[<p>Damn! This same exact thing just happened to me, and I have to prepare for a big trip too. Bad timing.</p>
<p>See: <a href="http://snipurl.com/1tktf" rel="nofollow">http://snipurl.com/1tktf</a></p>
<p>By any chance were you at Blogworld Expo? I was on the open wifi there and suspect that&#8217;s where the hacker sniffed my password.</p>
<p>I&#8217;m also currently running an older version of Wordpress. I&#8217;ve arranged for an upgrade, but that hasn&#8217;t happened yet.</p>
<p>Sounds like from what your commenters say that more might have been compromised on your site, and mine, than just Wordpress. I&#8217;m in over my head here, I don&#8217;t really understand server-side stuff. I&#8217;d appreciate assistance for how to fix this and secure my site more appropriately. I&#8217;ll be watching this thread for tips.</p>
<p>- Amy Gahran</p>
]]></content:encoded>
	</item>
</channel>
</rss>
