<?xml version="1.0" encoding="UTF-8"?><rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
> <channel><title>Comments on: My Sites Are Hacked – Here&#8217;s How I Fixed It</title> <atom:link href="http://www.abelcheng.com/my-sites-are-hacked-%e2%80%93-heres-how-i-fixed-it/feed/" rel="self" type="application/rss+xml" /><link>http://www.abelcheng.com/my-sites-are-hacked-%e2%80%93-heres-how-i-fixed-it/</link> <description>Online Entrepreneurship. Blogging. Life.</description> <lastBuildDate>Mon, 25 Oct 2010 22:20:36 +0000</lastBuildDate> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.2</generator> <item><title>By: Zoran</title><link>http://www.abelcheng.com/my-sites-are-hacked-%e2%80%93-heres-how-i-fixed-it/comment-page-1/#comment-1410</link> <dc:creator>Zoran</dc:creator> <pubDate>Mon, 25 Oct 2010 22:20:36 +0000</pubDate> <guid
isPermaLink="false">http://www.abelcheng.com/?p=37#comment-1410</guid> <description>The virus can get into your computer by visiting some bad site and it targets especially the FileZilla directory in the AppData folder where FileZilla keeps username/password pairs from all of your websites in plain text, then the virus connects to ftp and starts writing javascript code to your files, but not all, only index.php in the root, then it searches for index.html (because js will execute in index.html file) and these files are seen as virus from any decent antivirus software. Once the damage is done, first step is to change the access to ftp, access to cpanel if you have one and also check in the CPANEL for unusual FTP user, cause the virus will create new FTP user if it has credentials for it. That&#039;s why always keep a backup of all files and websites you have, if you don&#039;t then start cleaning your files one by one, usually the infected files will have similar date of last edit.
At the end, stop using FileZilla, (i got nothing against it, it&#039;s the best ftp software i ever used), cause of the password thing, or just don&#039;t keep your passwords saved.</description> <content:encoded><![CDATA[<p>The virus can get into your computer by visiting some bad site and it targets especially the FileZilla directory in the AppData folder where FileZilla keeps username/password pairs from all of your websites in plain text, then the virus connects to ftp and starts writing javascript code to your files, but not all, only index.php in the root, then it searches for index.html (because js will execute in index.html file) and these files are seen as virus from any decent antivirus software. Once the damage is done, first step is to change the access to ftp, access to cpanel if you have one and also check in the CPANEL for unusual FTP user, cause the virus will create new FTP user if it has credentials for it. That&#8217;s why always keep a backup of all files and websites you have, if you don&#8217;t then start cleaning your files one by one, usually the infected files will have similar date of last edit.<br
/> At the end, stop using FileZilla, (i got nothing against it, it&#8217;s the best ftp software i ever used), cause of the password thing, or just don&#8217;t keep your passwords saved.</p> ]]></content:encoded> </item> <item><title>By: Eurania</title><link>http://www.abelcheng.com/my-sites-are-hacked-%e2%80%93-heres-how-i-fixed-it/comment-page-1/#comment-1372</link> <dc:creator>Eurania</dc:creator> <pubDate>Sun, 13 Dec 2009 14:53:20 +0000</pubDate> <guid
isPermaLink="false">http://www.abelcheng.com/?p=37#comment-1372</guid> <description>I think this guy can help with that problem you havehttp://www.eduardobaret.com/2009/12/07/my-site-was-hacked-and-my-files-were-changed-reported-attack-site/</description> <content:encoded><![CDATA[<p>I think this guy can help with that problem you have</p><p><a
href="http://www.eduardobaret.com/2009/12/07/my-site-was-hacked-and-my-files-were-changed-reported-attack-site/" rel="nofollow">http://www.eduardobaret.com/2009/12/07/my-site-was-hacked-and-my-files-were-changed-reported-attack-site/</a></p> ]]></content:encoded> </item> <item><title>By: Brian</title><link>http://www.abelcheng.com/my-sites-are-hacked-%e2%80%93-heres-how-i-fixed-it/comment-page-1/#comment-1351</link> <dc:creator>Brian</dc:creator> <pubDate>Wed, 08 Jul 2009 16:36:55 +0000</pubDate> <guid
isPermaLink="false">http://www.abelcheng.com/?p=37#comment-1351</guid> <description>hi, i had a keylogger trojan on my home pc they caputured my username and password of ftp, then attack it using the iframe attack i pulled the whole site down, what a nightmare, you need to download keyscrambler straight away, this plugin will scramble  letters your typing into the  browser. Do not login to your ftp or website from anyones elses computer or internet cafe etc, incase the trojan is present, if it happens change your email passwords too,  store username and password on a piece of paper, do a weekly scan of computer with super anti spyware, trust me you will pull you head off if happens.</description> <content:encoded><![CDATA[<p>hi, i had a keylogger trojan on my home pc they caputured my username and password of ftp, then attack it using the iframe attack i pulled the whole site down, what a nightmare, you need to download keyscrambler straight away, this plugin will scramble  letters your typing into the  browser. Do not login to your ftp or website from anyones elses computer or internet cafe etc, incase the trojan is present, if it happens change your email passwords too,  store username and password on a piece of paper, do a weekly scan of computer with super anti spyware, trust me you will pull you head off if happens.</p> ]]></content:encoded> </item> <item><title>By: Mike</title><link>http://www.abelcheng.com/my-sites-are-hacked-%e2%80%93-heres-how-i-fixed-it/comment-page-1/#comment-1350</link> <dc:creator>Mike</dc:creator> <pubDate>Mon, 08 Jun 2009 21:20:55 +0000</pubDate> <guid
isPermaLink="false">http://www.abelcheng.com/?p=37#comment-1350</guid> <description>My sites are being hacked.I&#039;m using FileZilla.   I&#039;ve searched and found out that most of the hacked sites were suing FileZilla AND an older version of Adobe Reader 8.Is everybody using Adobe Reader 8 when their sites were hacked?http://blog.unmaskparasites.com/2009/04/15/malicious-income-iframes-from-cn-domains/thanks,
Mike</description> <content:encoded><![CDATA[<p>My sites are being hacked.</p><p>I&#8217;m using FileZilla.   I&#8217;ve searched and found out that most of the hacked sites were suing FileZilla AND an older version of Adobe Reader 8.</p><p>Is everybody using Adobe Reader 8 when their sites were hacked?</p><p><a
href="http://blog.unmaskparasites.com/2009/04/15/malicious-income-iframes-from-cn-domains/" rel="nofollow">http://blog.unmaskparasites.com/2009/04/15/malicious-income-iframes-from-cn-domains/</a></p><p>thanks,<br
/> Mike</p> ]]></content:encoded> </item> <item><title>By: HyperXR &#124; Advanced Hypertext Tool &#187; Blog Archive &#187; Gumblar .cn Exploit - 12 Facts About This Injected Script</title><link>http://www.abelcheng.com/my-sites-are-hacked-%e2%80%93-heres-how-i-fixed-it/comment-page-1/#comment-1348</link> <dc:creator>HyperXR &#124; Advanced Hypertext Tool &#187; Blog Archive &#187; Gumblar .cn Exploit - 12 Facts About This Injected Script</dc:creator> <pubDate>Mon, 01 Jun 2009 02:05:46 +0000</pubDate> <guid
isPermaLink="false">http://www.abelcheng.com/?p=37#comment-1348</guid> <description>[...] by compromised FTP credentials. So start with your own computer. Scan it for spyware. Some people reported good results with [...]</description> <content:encoded><![CDATA[<p>[...] by compromised FTP credentials. So start with your own computer. Scan it for spyware. Some people reported good results with [...]</p> ]]></content:encoded> </item> <item><title>By: Jimi</title><link>http://www.abelcheng.com/my-sites-are-hacked-%e2%80%93-heres-how-i-fixed-it/comment-page-1/#comment-1345</link> <dc:creator>Jimi</dc:creator> <pubDate>Tue, 19 May 2009 02:26:43 +0000</pubDate> <guid
isPermaLink="false">http://www.abelcheng.com/?p=37#comment-1345</guid> <description>I suppose to reason he was asking question 2 was: if the passwords were saved then the script could have just been able to locate them once it was on your computer, thus identifying how the script works.</description> <content:encoded><![CDATA[<p>I suppose to reason he was asking question 2 was: if the passwords were saved then the script could have just been able to locate them once it was on your computer, thus identifying how the script works.</p> ]]></content:encoded> </item> <item><title>By: Admin</title><link>http://www.abelcheng.com/my-sites-are-hacked-%e2%80%93-heres-how-i-fixed-it/comment-page-1/#comment-1344</link> <dc:creator>Admin</dc:creator> <pubDate>Mon, 11 May 2009 05:27:25 +0000</pubDate> <guid
isPermaLink="false">http://www.abelcheng.com/?p=37#comment-1344</guid> <description>@ Dennis: Answers to your questions:1. I used FTP mode only but I changed to SFTP after this incident.2. It doesn&#039;t matter, I think. Either way is vulnerable as the login details are leaked via FTP connection.3. No, I don&#039;t. But later I noticed Malwarebytes overlooked this spyware. I manually removed this culprit from the registry after I found out the exact spyware. I shoud have updated this post with the latest findings but didn&#039;t get the time to do it.</description> <content:encoded><![CDATA[<p>@ Dennis: Answers to your questions:</p><p>1. I used FTP mode only but I changed to SFTP after this incident.</p><p>2. It doesn&#8217;t matter, I think. Either way is vulnerable as the login details are leaked via FTP connection.</p><p>3. No, I don&#8217;t. But later I noticed Malwarebytes overlooked this spyware. I manually removed this culprit from the registry after I found out the exact spyware. I shoud have updated this post with the latest findings but didn&#8217;t get the time to do it.</p> ]]></content:encoded> </item> <item><title>By: Name</title><link>http://www.abelcheng.com/my-sites-are-hacked-%e2%80%93-heres-how-i-fixed-it/comment-page-1/#comment-1343</link> <dc:creator>Name</dc:creator> <pubDate>Sun, 10 May 2009 07:57:33 +0000</pubDate> <guid
isPermaLink="false">http://www.abelcheng.com/?p=37#comment-1343</guid> <description>Never mind, they work if I enter email and website.. Here is original comment I was trying to post:First I didn&#039;t use my F-Secure anti-virus at all as it did slowdown my PC too much and I got wpv[NUMBERS].exe virus from my very own website, I immidently deleted it and 20 minutes later my computer crashed and didn&#039;t boot anymore.
I fully reinstalled Windows and noticed 2 of my website had been infected by the virus. I removed the code from PHP and HTML files, it got hacked again and again!
Its not keylogger as I fixed the website with FULLY clean Windows installion. (though I visited the website and noticed F-Secure block a virus)
Im not using any CMS/Forum system, I just have infosniper IP query script and PJIRC, nothing else.
I tried setting permissions to all my files to 555 but after it got hacked the permission were 755 again..I also contacted my host, NO ONE has logged into cPanel or FTP with my logins!
According to them its done remotetly via internet browser using glitch in PHP scripting, blaims my PHP scripts.
Since no one logged in using my logins I though there were no use to change my passwords but now after getting hacked 3th time I finally changed myself and will see if it helps at all..There is &quot;solution&quot; on cPanel forums which is similar to yours.
http://forums.cpanel.net/showthread.php?t=78595This post of yours or the one on cPanel didn&#039;t help me.. :(</description> <content:encoded><![CDATA[<p>Never mind, they work if I enter email and website.. Here is original comment I was trying to post:</p><p>First I didn&#8217;t use my F-Secure anti-virus at all as it did slowdown my PC too much and I got wpv[NUMBERS].exe virus from my very own website, I immidently deleted it and 20 minutes later my computer crashed and didn&#8217;t boot anymore.<br
/> I fully reinstalled Windows and noticed 2 of my website had been infected by the virus. I removed the code from PHP and HTML files, it got hacked again and again!<br
/> Its not keylogger as I fixed the website with FULLY clean Windows installion. (though I visited the website and noticed F-Secure block a virus)<br
/> Im not using any CMS/Forum system, I just have infosniper IP query script and PJIRC, nothing else.<br
/> I tried setting permissions to all my files to 555 but after it got hacked the permission were 755 again..</p><p>I also contacted my host, NO ONE has logged into cPanel or FTP with my logins!<br
/> According to them its done remotetly via internet browser using glitch in PHP scripting, blaims my PHP scripts.<br
/> Since no one logged in using my logins I though there were no use to change my passwords but now after getting hacked 3th time I finally changed myself and will see if it helps at all..</p><p>There is &#8220;solution&#8221; on cPanel forums which is similar to yours.<br
/> <a
href="http://forums.cpanel.net/showthread.php?t=78595" rel="nofollow">http://forums.cpanel.net/showthread.php?t=78595</a></p><p>This post of yours or the one on cPanel didn&#8217;t help me.. <img
src='http://www.abelcheng.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /></p> ]]></content:encoded> </item> <item><title>By: Name</title><link>http://www.abelcheng.com/my-sites-are-hacked-%e2%80%93-heres-how-i-fixed-it/comment-page-1/#comment-1342</link> <dc:creator>Name</dc:creator> <pubDate>Sun, 10 May 2009 07:57:01 +0000</pubDate> <guid
isPermaLink="false">http://www.abelcheng.com/?p=37#comment-1342</guid> <description>Comments not working!</description> <content:encoded><![CDATA[<p>Comments not working!</p> ]]></content:encoded> </item> <item><title>By: UnderForge of Lack &#187; Blog Archive &#187; JUNIK.LV host malicious site instead of gumblar.cn</title><link>http://www.abelcheng.com/my-sites-are-hacked-%e2%80%93-heres-how-i-fixed-it/comment-page-1/#comment-1341</link> <dc:creator>UnderForge of Lack &#187; Blog Archive &#187; JUNIK.LV host malicious site instead of gumblar.cn</dc:creator> <pubDate>Fri, 08 May 2009 08:20:47 +0000</pubDate> <guid
isPermaLink="false">http://www.abelcheng.com/?p=37#comment-1341</guid> <description>[...] 04.30.2009) * dotcomnameshop .cn (added: 05.02.2009)  orz...   ??????????? My Sites Are Hacked – Here’s How I Fixed It  ????MalwareByte ???????  [...]</description> <content:encoded><![CDATA[<p>[...] 04.30.2009) * dotcomnameshop .cn (added: 05.02.2009)  orz&#8230;   ??????????? My Sites Are Hacked – Here’s How I Fixed It  ????MalwareByte ???????  [...]</p> ]]></content:encoded> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk
Page Caching using disk (enhanced)

Served from: www.abelcheng.com @ 2012-02-04 03:16:46 -->
