<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Interesting WP Spam Hack</title>
	<atom:link href="http://jasongriffey.net/wp/2008/07/14/interesting-wp-spam-hack/feed/" rel="self" type="application/rss+xml" />
	<link>http://jasongriffey.net/wp/2008/07/14/interesting-wp-spam-hack/</link>
	<description></description>
	<lastBuildDate>Mon, 14 May 2012 13:18:49 -0500</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>By: Ryan Deschamps</title>
		<link>http://jasongriffey.net/wp/2008/07/14/interesting-wp-spam-hack/#comment-1636</link>
		<dc:creator>Ryan Deschamps</dc:creator>
		<pubDate>Fri, 18 Dec 2009 03:15:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.jasongriffey.net/wp/?p=1437#comment-1636</guid>
		<description>SQL Injection would be my first guess, but its possible that a javascript attack could work as well.   Untested, but I wonder if the permitted emphasis or bold tags could be exploited to make that happen.I&#039;d also check within the email or website fields. . .</description>
		<content:encoded><![CDATA[<p>SQL Injection would be my first guess, but its possible that a javascript attack could work as well.   Untested, but I wonder if the permitted emphasis or bold tags could be exploited to make that happen.I&#039;d also check within the email or website fields. . .</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jason Griffey</title>
		<link>http://jasongriffey.net/wp/2008/07/14/interesting-wp-spam-hack/#comment-1635</link>
		<dc:creator>Jason Griffey</dc:creator>
		<pubDate>Tue, 15 Jul 2008 02:16:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.jasongriffey.net/wp/?p=1437#comment-1635</guid>
		<description>Well...its not an out of date install. We&#039;re current on that. It&#039;s not a single password/user combo, because it was done on 5 different posts with 3 different users. Possibly a plugin...3 of the posts were podcasts, with associated plugin goodness.

I&#039;ll keep digging. For now, everything is fixed.</description>
		<content:encoded><![CDATA[<p>Well&#8230;its not an out of date install. We&#8217;re current on that. It&#8217;s not a single password/user combo, because it was done on 5 different posts with 3 different users. Possibly a plugin&#8230;3 of the posts were podcasts, with associated plugin goodness.</p>
<p>I&#8217;ll keep digging. For now, everything is fixed.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Justin</title>
		<link>http://jasongriffey.net/wp/2008/07/14/interesting-wp-spam-hack/#comment-1634</link>
		<dc:creator>Justin</dc:creator>
		<pubDate>Tue, 15 Jul 2008 01:54:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.jasongriffey.net/wp/?p=1437#comment-1634</guid>
		<description>Did you ever see my post, &lt;a href=&quot;http://justinsomnia.org/2007/08/search-engine-marketeers-are-the-new-script-kiddies/&quot; rel=&quot;nofollow&quot;&gt;Search Engine Marketeers are the new script kiddies&lt;/a&gt;? This is different though, in my case, my template got hacked.

Sounds like either an out of date WP with a xmlrpc vulnerability, or someone&#039;s password got cracked. Another possibility is an evil plugin? Searching for similar posts would be easy, just look for &lt;code&gt;&quot;display:none&quot;&lt;/code&gt;</description>
		<content:encoded><![CDATA[<p>Did you ever see my post, <a href="http://justinsomnia.org/2007/08/search-engine-marketeers-are-the-new-script-kiddies/" rel="nofollow">Search Engine Marketeers are the new script kiddies</a>? This is different though, in my case, my template got hacked.</p>
<p>Sounds like either an out of date WP with a xmlrpc vulnerability, or someone&#8217;s password got cracked. Another possibility is an evil plugin? Searching for similar posts would be easy, just look for <code>"display:none"</code></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: amy</title>
		<link>http://jasongriffey.net/wp/2008/07/14/interesting-wp-spam-hack/#comment-1633</link>
		<dc:creator>amy</dc:creator>
		<pubDate>Mon, 14 Jul 2008 23:45:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.jasongriffey.net/wp/?p=1437#comment-1633</guid>
		<description>this happened to the Library Student Journal blog which is hosted by LISHost. the wonderful Blake helped me out but it was too late - the blog was not salvageable. but maybe he knows how to fix it?</description>
		<content:encoded><![CDATA[<p>this happened to the Library Student Journal blog which is hosted by LISHost. the wonderful Blake helped me out but it was too late &#8211; the blog was not salvageable. but maybe he knows how to fix it?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: joshua m. neff</title>
		<link>http://jasongriffey.net/wp/2008/07/14/interesting-wp-spam-hack/#comment-1632</link>
		<dc:creator>joshua m. neff</dc:creator>
		<pubDate>Mon, 14 Jul 2008 21:38:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.jasongriffey.net/wp/?p=1437#comment-1632</guid>
		<description>More weirdness: when it happened to me, it didn&#039;t show up in Bloglines but it did in Google Reader.

I removed the spam from the two posts on my blog and that seemed to solve the problem. Haven&#039;t had it happen since.</description>
		<content:encoded><![CDATA[<p>More weirdness: when it happened to me, it didn&#8217;t show up in Bloglines but it did in Google Reader.</p>
<p>I removed the spam from the two posts on my blog and that seemed to solve the problem. Haven&#8217;t had it happen since.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ryan Deschamps</title>
		<link>http://jasongriffey.net/wp/2008/07/14/interesting-wp-spam-hack/#comment-1631</link>
		<dc:creator>Ryan Deschamps</dc:creator>
		<pubDate>Mon, 14 Jul 2008 21:36:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.jasongriffey.net/wp/?p=1437#comment-1631</guid>
		<description>SQL Injection would be my first guess, but its possible that a javascript attack could work as well.   Untested, but I wonder if the permitted emphasis or bold tags could be exploited to make that happen.

I&#039;d also check within the email or website fields. . .</description>
		<content:encoded><![CDATA[<p>SQL Injection would be my first guess, but its possible that a javascript attack could work as well.   Untested, but I wonder if the permitted emphasis or bold tags could be exploited to make that happen.</p>
<p>I&#8217;d also check within the email or website fields. . .</p>
]]></content:encoded>
	</item>
</channel>
</rss>

