<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: New hacking attempt</title>
	<atom:link href="http://alexrabe.de/2008/02/18/new-hacking-attempt/feed/" rel="self" type="application/rss+xml" />
	<link>http://alexrabe.de/2008/02/18/new-hacking-attempt/</link>
	<description>ALEX RABE &#124; learning by doing...</description>
	<lastBuildDate>Wed, 08 Feb 2012 16:33:11 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<item>
		<title>By: Jenny</title>
		<link>http://alexrabe.de/2008/02/18/new-hacking-attempt/#comment-5975</link>
		<dc:creator>Jenny</dc:creator>
		<pubDate>Sun, 02 Mar 2008 15:40:49 +0000</pubDate>
		<guid isPermaLink="false">http://alexrabe.de/2008/02/18/new-hacking-attempt/#comment-5975</guid>
		<description>when I changed to thickbox it seems to work, but I am afraid something could have happend to my db. How can I check?

Please send me an email and I will give you the address to my site.

Thanks for your help,
Jenny</description>
		<content:encoded><![CDATA[<p>when I changed to thickbox it seems to work, but I am afraid something could have happend to my db. How can I check?</p>
<p>Please send me an email and I will give you the address to my site.</p>
<p>Thanks for your help,<br />
Jenny</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: alex.rabe</title>
		<link>http://alexrabe.de/2008/02/18/new-hacking-attempt/#comment-5971</link>
		<dc:creator>alex.rabe</dc:creator>
		<pubDate>Sat, 01 Mar 2008 16:22:20 +0000</pubDate>
		<guid isPermaLink="false">http://alexrabe.de/2008/02/18/new-hacking-attempt/#comment-5971</guid>
		<description>@Jamas
keep in your mind that I&#039;m not free for failure, good luck...

@Jenny 
Give me a link to your page</description>
		<content:encoded><![CDATA[<p>@Jamas<br />
keep in your mind that I&#8217;m not free for failure, good luck&#8230;</p>
<p>@Jenny<br />
Give me a link to your page</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jamas</title>
		<link>http://alexrabe.de/2008/02/18/new-hacking-attempt/#comment-5970</link>
		<dc:creator>Jamas</dc:creator>
		<pubDate>Sat, 01 Mar 2008 16:09:13 +0000</pubDate>
		<guid isPermaLink="false">http://alexrabe.de/2008/02/18/new-hacking-attempt/#comment-5970</guid>
		<description>Hey Alex,

Well so far NextGEN Gallery is holding up much better then WPPA to hack attempts. The site slsc.ca which I admin was hacked twice in the last week. 

The first time they managed to replace all the files in my active theme.  Mostly my fault as I had the folder permissions and file permissions wide open on that page.  

However the second time they managed to insert a post into the site and replace the contents of several pages. I noticed that my stats show search hits for: &#039;allinurl: page_id album &quot;photo&quot;&#039; which is a WPPA format for pages.  They then managed to upload a .zip file into the uploads directory. The some how managed to unzip it which must then have given them access to the site.  Still trying to sort out all the details. 

So I am going to try an experiment.  Patch the site back up (clean copy of all wordpress files (just in case they managed to change anything). Remove WPPA  and install NextGEN Gallery.  The site slsc.ca now shows up on their hacking forum so will see if they managed to get in using NextGEN.  I will let you know the results. 

Jamas</description>
		<content:encoded><![CDATA[<p>Hey Alex,</p>
<p>Well so far NextGEN Gallery is holding up much better then WPPA to hack attempts. The site slsc.ca which I admin was hacked twice in the last week. </p>
<p>The first time they managed to replace all the files in my active theme.  Mostly my fault as I had the folder permissions and file permissions wide open on that page.  </p>
<p>However the second time they managed to insert a post into the site and replace the contents of several pages. I noticed that my stats show search hits for: &#8216;allinurl: page_id album &#8220;photo&#8221;&#8216; which is a WPPA format for pages.  They then managed to upload a .zip file into the uploads directory. The some how managed to unzip it which must then have given them access to the site.  Still trying to sort out all the details. </p>
<p>So I am going to try an experiment.  Patch the site back up (clean copy of all wordpress files (just in case they managed to change anything). Remove WPPA  and install NextGEN Gallery.  The site slsc.ca now shows up on their hacking forum so will see if they managed to get in using NextGEN.  I will let you know the results. </p>
<p>Jamas</p>
]]></content:encoded>
	</item>
</channel>
</rss>

