<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
xmlns:rawvoice="http://www.rawvoice.com/rawvoiceRssModule/"
	>
<channel>
	<title>Comments on: WordPress Injection Attack</title>
	<atom:link href="http://dannedelko.com/wordpress/wordpress-injection-attack.html/feed" rel="self" type="application/rss+xml" />
	<link>http://dannedelko.com/wordpress/wordpress-injection-attack.html</link>
	<description>Media. Music. Business. Interwebz. </description>
	<lastBuildDate>Sun, 29 Jan 2012 04:12:34 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: Wordpress Spam Injection &#171; techniclog</title>
		<link>http://dannedelko.com/wordpress/wordpress-injection-attack.html/comment-page-1#comment-2264</link>
		<dc:creator>Wordpress Spam Injection &#171; techniclog</dc:creator>
		<pubDate>Sat, 29 Jan 2011 12:37:20 +0000</pubDate>
		<guid isPermaLink="false">http://dannedelko.com/?p=53#comment-2264</guid>
		<description>[...] on the registration page.Update 3: I am getting a pro at it now! Learnt about this plugin from here. I have installed it &#8211; it&#8217;s a great tool for securing your WP [...]</description>
		<content:encoded><![CDATA[[...] on the registration page.Update 3: I am getting a pro at it now! Learnt about this plugin from here. I have installed it &#8211; it&#8217;s a great tool for securing your WP [...]]]></content:encoded>
	</item>
	<item>
		<title>By: Wordpress Injection &#124; Free Wordpress Themes</title>
		<link>http://dannedelko.com/wordpress/wordpress-injection-attack.html/comment-page-1#comment-508</link>
		<dc:creator>Wordpress Injection &#124; Free Wordpress Themes</dc:creator>
		<pubDate>Fri, 30 Oct 2009 14:55:44 +0000</pubDate>
		<guid isPermaLink="false">http://dannedelko.com/?p=53#comment-508</guid>
		<description>[...] View Results     Loading &#8230; [...]</description>
		<content:encoded><![CDATA[[...] View Results     Loading &#8230; [...]]]></content:encoded>
	</item>
	<item>
		<title>By: Dave Yates</title>
		<link>http://dannedelko.com/wordpress/wordpress-injection-attack.html/comment-page-1#comment-345</link>
		<dc:creator>Dave Yates</dc:creator>
		<pubDate>Thu, 17 Sep 2009 13:16:03 +0000</pubDate>
		<guid isPermaLink="false">http://dannedelko.com/?p=53#comment-345</guid>
		<description>Hi Dan

Thanks for this and for the email. I am onto the server config advice now. Hosrting could be an issue - I use Heart in the UK. They are a bit &#039;pile it high sell it cheap&#039;, but the support is good and they know what they are doing - I tend to think the problem was of my own making. For those wanting to learn, read on…

Historically, the site was first put up some years ago when I was still merrily creating several sites a day, full of enthusiasm for the ease and power of WordPress. Whereas, these days I tend to change everything including the WP-admin folder name, most of the file names and always delete the admin user name straight away and otherwise alter a lot of the out-of-the-box defaults, back then I did not. 

It is not so feasible to retro-fit some of those practices unfortunately and once some nasty little germ has blown a hole in your installation, prevention doesn&#039;t work any more and a cure cannot always be easily found.

Cautionary advice for everyone out there:

1. Consider adding .htpasswd and .htaccess protection to the wp-admin directory.
2. Try changing the wp-admin folder name. See: http://wp123.info/modifications/change-wp-admin-folder-name/
3. I would add the login lockdown plugin to Dan&#039;s two excellent suggestions: http://wordpress.org/extend/plugins/login-lockdown/</description>
		<content:encoded><![CDATA[Hi Dan

Thanks for this and for the email. I am onto the server config advice now. Hosrting could be an issue &#8211; I use Heart in the UK. They are a bit &#8216;pile it high sell it cheap&#8217;, but the support is good and they know what they are doing &#8211; I tend to think the problem was of my own making. For those wanting to learn, read on…

Historically, the site was first put up some years ago when I was still merrily creating several sites a day, full of enthusiasm for the ease and power of WordPress. Whereas, these days I tend to change everything including the WP-admin folder name, most of the file names and always delete the admin user name straight away and otherwise alter a lot of the out-of-the-box defaults, back then I did not. 

It is not so feasible to retro-fit some of those practices unfortunately and once some nasty little germ has blown a hole in your installation, prevention doesn&#8217;t work any more and a cure cannot always be easily found.

Cautionary advice for everyone out there:

1. Consider adding .htpasswd and .htaccess protection to the wp-admin directory.
2. Try changing the wp-admin folder name. See: <a href="http://wp123.info/modifications/change-wp-admin-folder-name/">http://wp123.info/modifications/change-wp-admin-folder-name/</a>
3. I would add the login lockdown plugin to Dan&#8217;s two excellent suggestions: <a href="http://wordpress.org/extend/plugins/login-lockdown/">http://wordpress.org/extend/plugins/login-lockdown/</a>]]></content:encoded>
	</item>
	<item>
		<title>By: Dan Nedelko</title>
		<link>http://dannedelko.com/wordpress/wordpress-injection-attack.html/comment-page-1#comment-343</link>
		<dc:creator>Dan Nedelko</dc:creator>
		<pubDate>Thu, 17 Sep 2009 11:39:10 +0000</pubDate>
		<guid isPermaLink="false">http://dannedelko.com/?p=53#comment-343</guid>
		<description>Hey Dave,

These should help alot - I&#039;m also going to email you directly but you&#039;ll want to look at the server config. Years ago I had an account with Neureal, whose servers were hopelessly out of date. No matter what I did injections kept happening. You might want to try out a new host or have them lock some things down.

Especially openbasedir restrictions - add them - locking that down removes some functionality but helps alot.</description>
		<content:encoded><![CDATA[Hey Dave,

These should help alot &#8211; I&#8217;m also going to email you directly but you&#8217;ll want to look at the server config. Years ago I had an account with Neureal, whose servers were hopelessly out of date. No matter what I did injections kept happening. You might want to try out a new host or have them lock some things down.

Especially openbasedir restrictions &#8211; add them &#8211; locking that down removes some functionality but helps alot.]]></content:encoded>
	</item>
	<item>
		<title>By: Dave Yates</title>
		<link>http://dannedelko.com/wordpress/wordpress-injection-attack.html/comment-page-1#comment-342</link>
		<dc:creator>Dave Yates</dc:creator>
		<pubDate>Thu, 17 Sep 2009 11:27:18 +0000</pubDate>
		<guid isPermaLink="false">http://dannedelko.com/?p=53#comment-342</guid>
		<description>Good article. Hope it works!!

I have a client&#039;s site that has been getting filled up hidden injected links in the footer for months. I am at my wits end with it. I have been through the code with a fine tooth-comb (I&#039;m not a hard-core code monkey, but I know my way around), I have deleted any number of plugins, installed as many preventative plugins, I have changed every username and password, done a complete reinstall of WP …and guess what - the hidden links keep coming back. Hopefully these plugins will finally see them off.</description>
		<content:encoded><![CDATA[Good article. Hope it works!!

I have a client&#8217;s site that has been getting filled up hidden injected links in the footer for months. I am at my wits end with it. I have been through the code with a fine tooth-comb (I&#8217;m not a hard-core code monkey, but I know my way around), I have deleted any number of plugins, installed as many preventative plugins, I have changed every username and password, done a complete reinstall of WP …and guess what &#8211; the hidden links keep coming back. Hopefully these plugins will finally see them off.]]></content:encoded>
	</item>
	<item>
		<title>By: Maxxx</title>
		<link>http://dannedelko.com/wordpress/wordpress-injection-attack.html/comment-page-1#comment-84</link>
		<dc:creator>Maxxx</dc:creator>
		<pubDate>Sun, 05 Apr 2009 13:46:54 +0000</pubDate>
		<guid isPermaLink="false">http://dannedelko.com/?p=53#comment-84</guid>
		<description>Oh, it&#039;s a useful page! Thanks for it. (-:</description>
		<content:encoded><![CDATA[Oh, it&#8217;s a useful page! Thanks for it. (-:]]></content:encoded>
	</item>
	<item>
		<title>By: We Got Hacked&#8230; &#124; aimusic.com [the official A.i. website]</title>
		<link>http://dannedelko.com/wordpress/wordpress-injection-attack.html/comment-page-1#comment-83</link>
		<dc:creator>We Got Hacked&#8230; &#124; aimusic.com [the official A.i. website]</dc:creator>
		<pubDate>Sun, 05 Apr 2009 12:34:38 +0000</pubDate>
		<guid isPermaLink="false">http://dannedelko.com/?p=53#comment-83</guid>
		<description>[...] If you own a wordpress site that got hacked and are trying to figure out what to do, here&#8217;s a great article on how to solve it.&#160; [...]</description>
		<content:encoded><![CDATA[[...] If you own a wordpress site that got hacked and are trying to figure out what to do, here&#8217;s a great article on how to solve it.&nbsp; [...]]]></content:encoded>
	</item>
	<item>
		<title>By: RaiulBaztepo</title>
		<link>http://dannedelko.com/wordpress/wordpress-injection-attack.html/comment-page-1#comment-46</link>
		<dc:creator>RaiulBaztepo</dc:creator>
		<pubDate>Sat, 28 Mar 2009 16:27:49 +0000</pubDate>
		<guid isPermaLink="false">http://dannedelko.com/?p=53#comment-46</guid>
		<description>Hello!
Very Interesting post! Thank you for such interesting resource! 
PS: Sorry for my bad english, I&#039;v just started to learn this language ;)
See you! 
Your, Raiul Baztepo</description>
		<content:encoded><![CDATA[Hello!
Very Interesting post! Thank you for such interesting resource! 
PS: Sorry for my bad english, I&#8217;v just started to learn this language <img src='http://dannedelko.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> 
See you! 
Your, Raiul Baztepo]]></content:encoded>
	</item>
	<item>
		<title>By: Dan Nedelko</title>
		<link>http://dannedelko.com/wordpress/wordpress-injection-attack.html/comment-page-1#comment-20</link>
		<dc:creator>Dan Nedelko</dc:creator>
		<pubDate>Thu, 12 Mar 2009 15:36:08 +0000</pubDate>
		<guid isPermaLink="false">http://dannedelko.com/?p=53#comment-20</guid>
		<description>Thanks WuWu - glad you liked it. Hope to see you back soon!</description>
		<content:encoded><![CDATA[Thanks WuWu &#8211; glad you liked it. Hope to see you back soon!]]></content:encoded>
	</item>
	<item>
		<title>By: WuWu</title>
		<link>http://dannedelko.com/wordpress/wordpress-injection-attack.html/comment-page-1#comment-19</link>
		<dc:creator>WuWu</dc:creator>
		<pubDate>Thu, 12 Mar 2009 13:04:18 +0000</pubDate>
		<guid isPermaLink="false">http://dannedelko.com/?p=53#comment-19</guid>
		<description>Very nice post, thanks!!!</description>
		<content:encoded><![CDATA[Very nice post, thanks!!!]]></content:encoded>
	</item>
</channel>
</rss>

