<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Ivan Kuznetsov &#187; blog</title>
	<atom:link href="http://www.ivankuznetsov.com/tag/blog/feed" rel="self" type="application/rss+xml" />
	<link>http://www.ivankuznetsov.com</link>
	<description>Entrepreneur, Ruby on Rails and Ubuntu fanatic, consultant</description>
	<lastBuildDate>Fri, 01 Jul 2011 22:03:56 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
		<item>
		<title>I have been hacked</title>
		<link>http://www.ivankuznetsov.com/2008/04/i-have-been-hacked.html</link>
		<comments>http://www.ivankuznetsov.com/2008/04/i-have-been-hacked.html#comments</comments>
		<pubDate>Sat, 26 Apr 2008 20:13:59 +0000</pubDate>
		<dc:creator>Ivan Kuznetsov</dc:creator>
				<category><![CDATA[Web/Tech]]></category>
		<category><![CDATA[Weblogs]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://www.ivankuznetsov.com/?p=99</guid>
		<description><![CDATA[Yes, for the second time in my life. First time it was still in my university years. In those times if you had internet access at home, you were priveleged. Companies were paying quite a lot of money to get a slow 28K dial-up connection, and internet providers were charging per minute, not by gigabyte. [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-100" title="hacked" src="http://www.ivankuznetsov.com/wp-content/uploads/hacked.png" alt="Ivan Kuznetsov - blog hacked" width="300" height="187" />Yes, for the second time in my life. First time it was still in my university years. In those times if you had internet access at home, you were priveleged. Companies were paying quite a lot of money to get a slow 28K dial-up connection, and internet providers were charging per minute, not by gigabyte. I set up access to the university internet connection via modem in our lab &#8211; I was running <a href="http://en.wikipedia.org/wiki/FidoNet">FIDO net</a> node on the same machine. One guy (I later on found him) noticed that there&#8217;s a <a href="http://en.wikipedia.org/wiki/Point-to-Point_Protocol">PPP</a> connection attempt before FIDO mail software kicks in and successfully <a href="http://en.wikipedia.org/wiki/Brute_force_attack">brute forced</a> the password. I should admit that I didn&#8217;t bother that much when I was setting the password &#8211; it was not the default one, but pretty close. It was quite easy to spot the attack &#8211; phone line was busy all the time. What the attacker didn&#8217;t know is that the modem I used was a sophisticated US Robotics Sportster model with CallerID detection, so it was rather easy to trace the attacker.</p>
<p>But that was more than 10 years ago. Now I noticed that something is wrong when I started recieving a lot of comment spam from this blog. Captcha plugin was doing an excellent job before, so I decided to check what&#8217;s going on. Somehow all plugins were disabled. Re-enabling them solved the problem with comment spam, but then Goolge started generating weird excerpts for <a href="http://www.ivankuznetsov.com">ivankuznetsov.com</a> search results. That&#8217;s when I started digging deeper and discovered that a hidden div with advertisments was inserted into <a href="http://www.wordpress.org">WordPress</a> PHP scripts.</p>
<p><a href="http://www.dreamhost.com">Dreamhost</a> support was kind enough to point me to the <a href="http://iboughtamac.com/2008/03/28/protecting-wordpress-from-magic-include-shell/">description of the attack</a> that was used to break my blog. This particular problem, as well as some other security issues have been fixed in the latest Word Press release &#8211; 2.5.1. Lesson learned &#8211; update software on time and make backups.</p>
<p>If you are using WordPress older than 2.5.1 I would recommend you to upgrade ASAP.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.ivankuznetsov.com%2F2008%2F04%2Fi-have-been-hacked.html&amp;title=I%20have%20been%20hacked" id="wpa2a_2"><img src="http://www.ivankuznetsov.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.ivankuznetsov.com/2008/04/i-have-been-hacked.html/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

