<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	
	xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: How to find a backdoor in a hacked WordPress</title>
	<atom:link href="http://ottodestruct.com/blog/2009/hacked-wordpress-backdoors/feed/" rel="self" type="application/rss+xml" />
	<link>http://ottodestruct.com/blog/2009/hacked-wordpress-backdoors/</link>
	<description>Random meanderings you&#039;re probably not interested in</description>
	<lastBuildDate>Fri, 10 Feb 2012 11:42:14 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: JoeyD714</title>
		<link>http://ottodestruct.com/blog/2009/hacked-wordpress-backdoors/comment-page-1/#comment-1133</link>
		<dc:creator>JoeyD714</dc:creator>
		<pubDate>Thu, 11 Mar 2010 06:10:23 +0000</pubDate>
		<guid isPermaLink="false">http://ottodestruct.com/blog/?p=555#comment-1133</guid>
		<description>We believe the site has a backdoor installed by the company we hired to create it.

any ideas on how to find a backdoor created by the site builders?</description>
		<content:encoded><![CDATA[<p>We believe the site has a backdoor installed by the company we hired to create it.</p>
<p>any ideas on how to find a backdoor created by the site builders?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Otto on WordPress &#187; Blog Archive &#187; How to find a backdoor in a hacked WordPress</title>
		<link>http://ottodestruct.com/blog/2009/hacked-wordpress-backdoors/comment-page-1/#comment-1132</link>
		<dc:creator>Otto on WordPress &#187; Blog Archive &#187; How to find a backdoor in a hacked WordPress</dc:creator>
		<pubDate>Thu, 04 Mar 2010 22:28:29 +0000</pubDate>
		<guid isPermaLink="false">http://ottodestruct.com/blog/?p=555#comment-1132</guid>
		<description>[...] How to find a backdoor in a hacked WordPress March 4, 2010, 4:27 pm   Originally posted here: http://ottodestruct.com/blog/2009/hacked-wordpress-backdoors/ [...]</description>
		<content:encoded><![CDATA[<p>[...] How to find a backdoor in a hacked WordPress March 4, 2010, 4:27 pm   Originally posted here: <a href="http://ottodestruct.com/blog/2009/hacked-wordpress-backdoors/" rel="nofollow">http://ottodestruct.com/blog/2009/hacked-wordpress-backdoors/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Spring Cleaning &#8211; Of Hacked Files : Money News</title>
		<link>http://ottodestruct.com/blog/2009/hacked-wordpress-backdoors/comment-page-1/#comment-1131</link>
		<dc:creator>Spring Cleaning &#8211; Of Hacked Files : Money News</dc:creator>
		<pubDate>Wed, 03 Mar 2010 10:44:25 +0000</pubDate>
		<guid isPermaLink="false">http://ottodestruct.com/blog/?p=555#comment-1131</guid>
		<description>[...] How to find a backdoor in a hacked WordPress [...]</description>
		<content:encoded><![CDATA[<p>[...] How to find a backdoor in a hacked WordPress [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Obnoxious Clients - CLEARLY I&#039;M NOT A PEOPLE PERSON</title>
		<link>http://ottodestruct.com/blog/2009/hacked-wordpress-backdoors/comment-page-1/#comment-1836</link>
		<dc:creator>Obnoxious Clients - CLEARLY I&#039;M NOT A PEOPLE PERSON</dc:creator>
		<pubDate>Sun, 07 Feb 2010 08:09:05 +0000</pubDate>
		<guid isPermaLink="false">http://ottodestruct.com/blog/?p=555#comment-1836</guid>
		<description>[...] How to find a backdoor in a hacked WordPress [...]</description>
		<content:encoded><![CDATA[<p>[...] How to find a backdoor in a hacked WordPress [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Obnoxious Clients - CLEARLY I&#039;M NOT A PEOPLE PERSON</title>
		<link>http://ottodestruct.com/blog/2009/hacked-wordpress-backdoors/comment-page-1/#comment-1130</link>
		<dc:creator>Obnoxious Clients - CLEARLY I&#039;M NOT A PEOPLE PERSON</dc:creator>
		<pubDate>Sun, 07 Feb 2010 08:09:05 +0000</pubDate>
		<guid isPermaLink="false">http://ottodestruct.com/blog/?p=555#comment-1130</guid>
		<description>[...] How to find a backdoor in a hacked WordPress [...]</description>
		<content:encoded><![CDATA[<p>[...] How to find a backdoor in a hacked WordPress [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sanaa</title>
		<link>http://ottodestruct.com/blog/2009/hacked-wordpress-backdoors/comment-page-1/#comment-1129</link>
		<dc:creator>Sanaa</dc:creator>
		<pubDate>Tue, 26 Jan 2010 22:43:38 +0000</pubDate>
		<guid isPermaLink="false">http://ottodestruct.com/blog/?p=555#comment-1129</guid>
		<description>one of my sites got hacked, I had it restored to a Jan 6th version...(I am adding the lost info and will do a backup). I did have the latest version of wordpress but like you said, the hack could have already been installed.

I had it restored to a previous date but...

HOW do I prevent this from happening again on this site, as well as, on my other sites which haven&#039;t been hacked --in other words, how do I find the backdoor and close it?</description>
		<content:encoded><![CDATA[<p>one of my sites got hacked, I had it restored to a Jan 6th version&#8230;(I am adding the lost info and will do a backup). I did have the latest version of wordpress but like you said, the hack could have already been installed.</p>
<p>I had it restored to a previous date but&#8230;</p>
<p>HOW do I prevent this from happening again on this site, as well as, on my other sites which haven&#8217;t been hacked &#8211;in other words, how do I find the backdoor and close it?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jillian</title>
		<link>http://ottodestruct.com/blog/2009/hacked-wordpress-backdoors/comment-page-1/#comment-1128</link>
		<dc:creator>Jillian</dc:creator>
		<pubDate>Fri, 11 Dec 2009 09:56:35 +0000</pubDate>
		<guid isPermaLink="false">http://ottodestruct.com/blog/?p=555#comment-1128</guid>
		<description>Does anyone know if people who installed WP into a randomly named sub-directory under the DocumentRoot were less likely to get hacked? It probably doesn&#039;t matter too much, but if any of the backdoors assumed where files were located with respect to the docroot -- then installing WP in a subdirectory would be another security measure. Not that injected code couldn&#039;t smarten up and add logic to compensate. I&#039;m just curious. Also, did it affect WPMU installations the same way?

Just curious.</description>
		<content:encoded><![CDATA[<p>Does anyone know if people who installed WP into a randomly named sub-directory under the DocumentRoot were less likely to get hacked? It probably doesn&#8217;t matter too much, but if any of the backdoors assumed where files were located with respect to the docroot &#8212; then installing WP in a subdirectory would be another security measure. Not that injected code couldn&#8217;t smarten up and add logic to compensate. I&#8217;m just curious. Also, did it affect WPMU installations the same way?</p>
<p>Just curious.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Averill</title>
		<link>http://ottodestruct.com/blog/2009/hacked-wordpress-backdoors/comment-page-1/#comment-1127</link>
		<dc:creator>Averill</dc:creator>
		<pubDate>Tue, 24 Nov 2009 15:04:30 +0000</pubDate>
		<guid isPermaLink="false">http://ottodestruct.com/blog/?p=555#comment-1127</guid>
		<description>Thanks, Otto. I&#039;m kinda compulsive, so I had to comb through the site to find whatever I could. There were, as you say, more backdoors, and I don&#039;t trust that I caught all of them. I also deleted multiple users from the database, and did lose the extra (hidden) admin person. I can see that they easily could have gained access through our plugin folder. I&#039;m learning a lot more about this than I ever planned to learn. I guess it&#039;s good. I appreciate your sharing this information.</description>
		<content:encoded><![CDATA[<p>Thanks, Otto. I&#8217;m kinda compulsive, so I had to comb through the site to find whatever I could. There were, as you say, more backdoors, and I don&#8217;t trust that I caught all of them. I also deleted multiple users from the database, and did lose the extra (hidden) admin person. I can see that they easily could have gained access through our plugin folder. I&#8217;m learning a lot more about this than I ever planned to learn. I guess it&#8217;s good. I appreciate your sharing this information.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Otto</title>
		<link>http://ottodestruct.com/blog/2009/hacked-wordpress-backdoors/comment-page-1/#comment-1126</link>
		<dc:creator>Otto</dc:creator>
		<pubDate>Mon, 23 Nov 2009 23:04:33 +0000</pubDate>
		<guid isPermaLink="false">http://ottodestruct.com/blog/?p=555#comment-1126</guid>
		<description>I don&#039;t think there is a wp-manager.php file, that whole thing is probably added by the hacker.

There&#039;s almost certain to be more than one backdoor in the system, I&#039;d go through and replace all the WP files with fresh ones, just to be sure. Anything else should be examined carefully.</description>
		<content:encoded><![CDATA[<p>I don&#8217;t think there is a wp-manager.php file, that whole thing is probably added by the hacker.</p>
<p>There&#8217;s almost certain to be more than one backdoor in the system, I&#8217;d go through and replace all the WP files with fresh ones, just to be sure. Anything else should be examined carefully.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Averill</title>
		<link>http://ottodestruct.com/blog/2009/hacked-wordpress-backdoors/comment-page-1/#comment-1125</link>
		<dc:creator>Averill</dc:creator>
		<pubDate>Mon, 23 Nov 2009 14:47:26 +0000</pubDate>
		<guid isPermaLink="false">http://ottodestruct.com/blog/?p=555#comment-1125</guid>
		<description>P.S. I&#039;ve found several other files that have been altered, including wp-manager.php, wp-blog-header.php... I can&#039;t even begin to figure out what to do with the wp-manager file, since I don&#039;t have the original. On to re-doing the site. Quite insidious, this invasion!</description>
		<content:encoded><![CDATA[<p>P.S. I&#8217;ve found several other files that have been altered, including wp-manager.php, wp-blog-header.php&#8230; I can&#8217;t even begin to figure out what to do with the wp-manager file, since I don&#8217;t have the original. On to re-doing the site. Quite insidious, this invasion!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using xcache
Object Caching 412/420 objects using xcache

Served from: ottodestruct.com @ 2012-02-11 11:59:57 -->
