<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" 
	xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: How to find a backdoor in a hacked WordPress</title>
	<atom:link href="http://ottodestruct.com/blog/2009/hacked-wordpress-backdoors/feed/" rel="self" type="application/rss+xml" />
	<link>http://ottodestruct.com/blog/2009/hacked-wordpress-backdoors/</link>
	<description>Random meanderings you&#039;re probably not interested in</description>
	<lastBuildDate>Thu, 11 Mar 2010 06:10:23 -0600</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: JoeyD714</title>
		<link>http://ottodestruct.com/blog/2009/hacked-wordpress-backdoors/comment-page-1/#comment-7868</link>
		<dc:creator>JoeyD714</dc:creator>
		<pubDate>Thu, 11 Mar 2010 06:10:23 +0000</pubDate>
		<guid isPermaLink="false">http://ottodestruct.com/blog/?p=555#comment-7868</guid>
		<description>We believe the site has a backdoor installed by the company we hired to create it.

any ideas on how to find a backdoor created by the site builders?</description>
		<content:encoded><![CDATA[<p>We believe the site has a backdoor installed by the company we hired to create it.</p>
<p>any ideas on how to find a backdoor created by the site builders?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Otto on WordPress &#187; Blog Archive &#187; How to find a backdoor in a hacked WordPress</title>
		<link>http://ottodestruct.com/blog/2009/hacked-wordpress-backdoors/comment-page-1/#comment-7833</link>
		<dc:creator>Otto on WordPress &#187; Blog Archive &#187; How to find a backdoor in a hacked WordPress</dc:creator>
		<pubDate>Thu, 04 Mar 2010 22:28:29 +0000</pubDate>
		<guid isPermaLink="false">http://ottodestruct.com/blog/?p=555#comment-7833</guid>
		<description>[...] How to find a backdoor in a hacked WordPress March 4, 2010, 4:27 pm   Originally posted here: http://ottodestruct.com/blog/2009/hacked-wordpress-backdoors/ [...]</description>
		<content:encoded><![CDATA[<p>[...] How to find a backdoor in a hacked WordPress March 4, 2010, 4:27 pm   Originally posted here: <a href="http://ottodestruct.com/blog/2009/hacked-wordpress-backdoors/" rel="nofollow">http://ottodestruct.com/blog/2.....backdoors/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Spring Cleaning &#8211; Of Hacked Files : Money News</title>
		<link>http://ottodestruct.com/blog/2009/hacked-wordpress-backdoors/comment-page-1/#comment-7783</link>
		<dc:creator>Spring Cleaning &#8211; Of Hacked Files : Money News</dc:creator>
		<pubDate>Wed, 03 Mar 2010 10:44:25 +0000</pubDate>
		<guid isPermaLink="false">http://ottodestruct.com/blog/?p=555#comment-7783</guid>
		<description>[...] How to find a backdoor in a hacked WordPress [...]</description>
		<content:encoded><![CDATA[<p>[...] How to find a backdoor in a hacked WordPress [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Obnoxious Clients - CLEARLY I&#39;M NOT A PEOPLE PERSON</title>
		<link>http://ottodestruct.com/blog/2009/hacked-wordpress-backdoors/comment-page-1/#comment-7484</link>
		<dc:creator>Obnoxious Clients - CLEARLY I&#39;M NOT A PEOPLE PERSON</dc:creator>
		<pubDate>Sun, 07 Feb 2010 08:09:05 +0000</pubDate>
		<guid isPermaLink="false">http://ottodestruct.com/blog/?p=555#comment-7484</guid>
		<description>[...] How to find a backdoor in a hacked WordPress [...]</description>
		<content:encoded><![CDATA[<p>[...] How to find a backdoor in a hacked WordPress [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sanaa</title>
		<link>http://ottodestruct.com/blog/2009/hacked-wordpress-backdoors/comment-page-1/#comment-7365</link>
		<dc:creator>Sanaa</dc:creator>
		<pubDate>Tue, 26 Jan 2010 22:43:38 +0000</pubDate>
		<guid isPermaLink="false">http://ottodestruct.com/blog/?p=555#comment-7365</guid>
		<description>one of my sites got hacked, I had it restored to a Jan 6th version...(I am adding the lost info and will do a backup). I did have the latest version of wordpress but like you said, the hack could have already been installed.

I had it restored to a previous date but...

HOW do I prevent this from happening again on this site, as well as, on my other sites which haven&#039;t been hacked --in other words, how do I find the backdoor and close it?</description>
		<content:encoded><![CDATA[<p>one of my sites got hacked, I had it restored to a Jan 6th version&#8230;(I am adding the lost info and will do a backup). I did have the latest version of wordpress but like you said, the hack could have already been installed.</p>
<p>I had it restored to a previous date but&#8230;</p>
<p>HOW do I prevent this from happening again on this site, as well as, on my other sites which haven&#8217;t been hacked &#8211;in other words, how do I find the backdoor and close it?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jillian</title>
		<link>http://ottodestruct.com/blog/2009/hacked-wordpress-backdoors/comment-page-1/#comment-7081</link>
		<dc:creator>Jillian</dc:creator>
		<pubDate>Fri, 11 Dec 2009 09:56:35 +0000</pubDate>
		<guid isPermaLink="false">http://ottodestruct.com/blog/?p=555#comment-7081</guid>
		<description>Does anyone know if people who installed WP into a randomly named sub-directory under the DocumentRoot were less likely to get hacked? It probably doesn&#039;t matter too much, but if any of the backdoors assumed where files were located with respect to the docroot -- then installing WP in a subdirectory would be another security measure. Not that injected code couldn&#039;t smarten up and add logic to compensate. I&#039;m just curious. Also, did it affect WPMU installations the same way?

Just curious.</description>
		<content:encoded><![CDATA[<p>Does anyone know if people who installed WP into a randomly named sub-directory under the DocumentRoot were less likely to get hacked? It probably doesn&#8217;t matter too much, but if any of the backdoors assumed where files were located with respect to the docroot &#8212; then installing WP in a subdirectory would be another security measure. Not that injected code couldn&#8217;t smarten up and add logic to compensate. I&#8217;m just curious. Also, did it affect WPMU installations the same way?</p>
<p>Just curious.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Averill</title>
		<link>http://ottodestruct.com/blog/2009/hacked-wordpress-backdoors/comment-page-1/#comment-7028</link>
		<dc:creator>Averill</dc:creator>
		<pubDate>Tue, 24 Nov 2009 15:04:30 +0000</pubDate>
		<guid isPermaLink="false">http://ottodestruct.com/blog/?p=555#comment-7028</guid>
		<description>Thanks, Otto. I&#039;m kinda compulsive, so I had to comb through the site to find whatever I could. There were, as you say, more backdoors, and I don&#039;t trust that I caught all of them. I also deleted multiple users from the database, and did lose the extra (hidden) admin person. I can see that they easily could have gained access through our plugin folder. I&#039;m learning a lot more about this than I ever planned to learn. I guess it&#039;s good. I appreciate your sharing this information.</description>
		<content:encoded><![CDATA[<p>Thanks, Otto. I&#8217;m kinda compulsive, so I had to comb through the site to find whatever I could. There were, as you say, more backdoors, and I don&#8217;t trust that I caught all of them. I also deleted multiple users from the database, and did lose the extra (hidden) admin person. I can see that they easily could have gained access through our plugin folder. I&#8217;m learning a lot more about this than I ever planned to learn. I guess it&#8217;s good. I appreciate your sharing this information.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Otto</title>
		<link>http://ottodestruct.com/blog/2009/hacked-wordpress-backdoors/comment-page-1/#comment-7026</link>
		<dc:creator>Otto</dc:creator>
		<pubDate>Mon, 23 Nov 2009 23:04:33 +0000</pubDate>
		<guid isPermaLink="false">http://ottodestruct.com/blog/?p=555#comment-7026</guid>
		<description>I don&#039;t think there is a wp-manager.php file, that whole thing is probably added by the hacker.

There&#039;s almost certain to be more than one backdoor in the system, I&#039;d go through and replace all the WP files with fresh ones, just to be sure. Anything else should be examined carefully.</description>
		<content:encoded><![CDATA[<p>I don&#8217;t think there is a wp-manager.php file, that whole thing is probably added by the hacker.</p>
<p>There&#8217;s almost certain to be more than one backdoor in the system, I&#8217;d go through and replace all the WP files with fresh ones, just to be sure. Anything else should be examined carefully.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Averill</title>
		<link>http://ottodestruct.com/blog/2009/hacked-wordpress-backdoors/comment-page-1/#comment-7025</link>
		<dc:creator>Averill</dc:creator>
		<pubDate>Mon, 23 Nov 2009 14:47:26 +0000</pubDate>
		<guid isPermaLink="false">http://ottodestruct.com/blog/?p=555#comment-7025</guid>
		<description>P.S. I&#039;ve found several other files that have been altered, including wp-manager.php, wp-blog-header.php... I can&#039;t even begin to figure out what to do with the wp-manager file, since I don&#039;t have the original. On to re-doing the site. Quite insidious, this invasion!</description>
		<content:encoded><![CDATA[<p>P.S. I&#8217;ve found several other files that have been altered, including wp-manager.php, wp-blog-header.php&#8230; I can&#8217;t even begin to figure out what to do with the wp-manager file, since I don&#8217;t have the original. On to re-doing the site. Quite insidious, this invasion!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Averill</title>
		<link>http://ottodestruct.com/blog/2009/hacked-wordpress-backdoors/comment-page-1/#comment-7024</link>
		<dc:creator>Averill</dc:creator>
		<pubDate>Mon, 23 Nov 2009 14:21:12 +0000</pubDate>
		<guid isPermaLink="false">http://ottodestruct.com/blog/?p=555#comment-7024</guid>
		<description>We&#039;ve been hacked. I found a file hidden in an upload folder, called 257409.php. No reason for a php file to be buried in one of those folders. It contained 203KB of random characters. It took me a bit to find the hidden eval and base64_decode within (it being on the first line helped, though). 
&lt;code&gt;&lt;?php $wvUJRFQ=&#039;###e####va#####l########(#ba##s##############e###########6###4############_##d##################e#c#########o####d#e##(&lt;/code&gt;

We are going to go to a brand new theme (ours is very old) and upgrading to the latest version of WordPress - and will follow the instructions in the article How To Completely Clean Your Hacked WordPress Installation. Should we be looking for more backdoors or other malicious code if we do this?</description>
		<content:encoded><![CDATA[<p>We&#8217;ve been hacked. I found a file hidden in an upload folder, called 257409.php. No reason for a php file to be buried in one of those folders. It contained 203KB of random characters. It took me a bit to find the hidden eval and base64_decode within (it being on the first line helped, though).<br />
<code>&lt;?php $wvUJRFQ=&#039;###e####va#####l########(#ba##s##############e###########6###4############_##d##################e#c#########o####d#e##(</code></p>
<p>We are going to go to a brand new theme (ours is very old) and upgrading to the latest version of WordPress &#8211; and will follow the instructions in the article How To Completely Clean Your Hacked WordPress Installation. Should we be looking for more backdoors or other malicious code if we do this?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gumblar blocheaza blogurile WordPress si alte websiteuri complexe in PHP &#124; WorldIT</title>
		<link>http://ottodestruct.com/blog/2009/hacked-wordpress-backdoors/comment-page-1/#comment-6976</link>
		<dc:creator>Gumblar blocheaza blogurile WordPress si alte websiteuri complexe in PHP &#124; WorldIT</dc:creator>
		<pubDate>Sat, 07 Nov 2009 10:24:58 +0000</pubDate>
		<guid isPermaLink="false">http://ottodestruct.com/blog/?p=555#comment-6976</guid>
		<description>[...] de el:  Botnet authors crash wordpress sites Revenge of gumblar zombies Wordpress exploit scanner How to find backdoor scripts Unmask [...]</description>
		<content:encoded><![CDATA[<p>[...] de el:  Botnet authors crash wordpress sites Revenge of gumblar zombies Wordpress exploit scanner How to find backdoor scripts Unmask [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Las penas del Agente Smith &#187; Cómo arreglé el blog sin morir en el intento</title>
		<link>http://ottodestruct.com/blog/2009/hacked-wordpress-backdoors/comment-page-1/#comment-6963</link>
		<dc:creator>Las penas del Agente Smith &#187; Cómo arreglé el blog sin morir en el intento</dc:creator>
		<pubDate>Thu, 05 Nov 2009 06:02:43 +0000</pubDate>
		<guid isPermaLink="false">http://ottodestruct.com/blog/?p=555#comment-6963</guid>
		<description>[...] Tras encontrar algunos trozos de código sospechoso en lugares donde nunca deberían estar, me pongo a rebuscar por Internet, a ver si alguien tiene experiencia solucionando algo parecido. Encuentro una entrada algo antigua pero con cerros de información valiosa: Wordpress exploit: we been hit by hidden spam link injection. Desde ahí también llego a How to find a backdoor in a hacked WordPress. [...]</description>
		<content:encoded><![CDATA[<p>[...] Tras encontrar algunos trozos de código sospechoso en lugares donde nunca deberían estar, me pongo a rebuscar por Internet, a ver si alguien tiene experiencia solucionando algo parecido. Encuentro una entrada algo antigua pero con cerros de información valiosa: Wordpress exploit: we been hit by hidden spam link injection. Desde ahí también llego a How to find a backdoor in a hacked WordPress. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Patrick Gibson</title>
		<link>http://ottodestruct.com/blog/2009/hacked-wordpress-backdoors/comment-page-1/#comment-6960</link>
		<dc:creator>Patrick Gibson</dc:creator>
		<pubDate>Tue, 03 Nov 2009 21:53:09 +0000</pubDate>
		<guid isPermaLink="false">http://ottodestruct.com/blog/?p=555#comment-6960</guid>
		<description>It&#039;s still early days, but I&#039;ve written a script to help seek out old versions of WordPress and even help with some of the clean-up. Introducing &lt;a href=&quot;http://code.google.com/p/wordpress-butler/&quot; rel=&quot;nofollow&quot;&gt;WordPress Butler!&lt;/a&gt;. It will be most useful for web hosting companies or individuals who manage multiple WordPress blogs on the same server.</description>
		<content:encoded><![CDATA[<p>It&#8217;s still early days, but I&#8217;ve written a script to help seek out old versions of WordPress and even help with some of the clean-up. Introducing <a href="http://code.google.com/p/wordpress-butler/" rel="nofollow">WordPress Butler!</a>. It will be most useful for web hosting companies or individuals who manage multiple WordPress blogs on the same server.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Password protected wordpress hack</title>
		<link>http://ottodestruct.com/blog/2009/hacked-wordpress-backdoors/comment-page-1/#comment-6947</link>
		<dc:creator>Password protected wordpress hack</dc:creator>
		<pubDate>Thu, 15 Oct 2009 09:03:19 +0000</pubDate>
		<guid isPermaLink="false">http://ottodestruct.com/blog/?p=555#comment-6947</guid>
		<description>[...] and messed up to a point that it is time to reinstall? This post by Otto makes for good reading, removing wordpress hacks , and is very informative , and give the main reasons why the upgrade does not necessarily get rid [...]</description>
		<content:encoded><![CDATA[<p>[...] and messed up to a point that it is time to reinstall? This post by Otto makes for good reading, removing wordpress hacks , and is very informative , and give the main reasons why the upgrade does not necessarily get rid [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: p</title>
		<link>http://ottodestruct.com/blog/2009/hacked-wordpress-backdoors/comment-page-1/#comment-6944</link>
		<dc:creator>p</dc:creator>
		<pubDate>Fri, 02 Oct 2009 01:54:31 +0000</pubDate>
		<guid isPermaLink="false">http://ottodestruct.com/blog/?p=555#comment-6944</guid>
		<description>great post, let me wonder about potential ways to avoid - at least - some hack attemps. first one: deny via htaccess any GET querystring with, let&#039;s say, &lt;em&gt;base64&lt;/em&gt; or &lt;em&gt;46esab&lt;/em&gt; (actually, who need them?). second one: a little plugin that looks around for the same things in POST queries. 

Just thougths, of course. But cleaning is so boring...</description>
		<content:encoded><![CDATA[<p>great post, let me wonder about potential ways to avoid &#8211; at least &#8211; some hack attemps. first one: deny via htaccess any GET querystring with, let&#8217;s say, <em>base64</em> or <em>46esab</em> (actually, who need them?). second one: a little plugin that looks around for the same things in POST queries. </p>
<p>Just thougths, of course. But cleaning is so boring&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lon</title>
		<link>http://ottodestruct.com/blog/2009/hacked-wordpress-backdoors/comment-page-1/#comment-6943</link>
		<dc:creator>Lon</dc:creator>
		<pubDate>Wed, 30 Sep 2009 03:02:46 +0000</pubDate>
		<guid isPermaLink="false">http://ottodestruct.com/blog/?p=555#comment-6943</guid>
		<description>Before switching to 2.8.4, our site was compromised.  The @*%$! spammers deployed two files to our system /wp-admin/fotter.php and /wp-admin/inclode.php (note the purposeful misspellings).  These were encrypted files that were web-based backdoors.  These were causing our theme footer to be overwritten nightly.</description>
		<content:encoded><![CDATA[<p>Before switching to 2.8.4, our site was compromised.  The @*%$! spammers deployed two files to our system /wp-admin/fotter.php and /wp-admin/inclode.php (note the purposeful misspellings).  These were encrypted files that were web-based backdoors.  These were causing our theme footer to be overwritten nightly.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Webdesigner from Berlin</title>
		<link>http://ottodestruct.com/blog/2009/hacked-wordpress-backdoors/comment-page-1/#comment-6942</link>
		<dc:creator>Webdesigner from Berlin</dc:creator>
		<pubDate>Fri, 25 Sep 2009 06:35:50 +0000</pubDate>
		<guid isPermaLink="false">http://ottodestruct.com/blog/?p=555#comment-6942</guid>
		<description>Hey, thanks for sharing. That&#039;s probably less work than clearing that stuff of an successful attack... ;)</description>
		<content:encoded><![CDATA[<p>Hey, thanks for sharing. That&#8217;s probably less work than clearing that stuff of an successful attack&#8230; <img src='http://ottodestruct.com/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Follow-Up To The Wordpress Exploit and Tips to Protect Your Blog &#124; CenterNetworks</title>
		<link>http://ottodestruct.com/blog/2009/hacked-wordpress-backdoors/comment-page-1/#comment-6937</link>
		<dc:creator>Follow-Up To The Wordpress Exploit and Tips to Protect Your Blog &#124; CenterNetworks</dc:creator>
		<pubDate>Tue, 22 Sep 2009 00:24:24 +0000</pubDate>
		<guid isPermaLink="false">http://ottodestruct.com/blog/?p=555#comment-6937</guid>
		<description>[...] How to check if you have any backdoors that the exploiters can use to get into your blog &#8211; Otto [...]</description>
		<content:encoded><![CDATA[<p>[...] How to check if you have any backdoors that the exploiters can use to get into your blog &#8211; Otto [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Allen</title>
		<link>http://ottodestruct.com/blog/2009/hacked-wordpress-backdoors/comment-page-1/#comment-6936</link>
		<dc:creator>Allen</dc:creator>
		<pubDate>Mon, 21 Sep 2009 21:52:10 +0000</pubDate>
		<guid isPermaLink="false">http://ottodestruct.com/blog/?p=555#comment-6936</guid>
		<description>great post otto - i will link it up when/if i make an update post.</description>
		<content:encoded><![CDATA[<p>great post otto &#8211; i will link it up when/if i make an update post.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
