<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: My Sites Are Hacked – Here&#8217;s How I Fixed It</title>
	<atom:link href="http://www.abelcheng.com/my-sites-are-hacked-%e2%80%93-heres-how-i-fixed-it/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.abelcheng.com/my-sites-are-hacked-%e2%80%93-heres-how-i-fixed-it/</link>
	<description>The life of an Internet entrepreneur and stay-at-home dad</description>
	<lastBuildDate>Wed, 05 May 2010 10:04:16 -0500</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Eurania</title>
		<link>http://www.abelcheng.com/my-sites-are-hacked-%e2%80%93-heres-how-i-fixed-it/comment-page-1/#comment-1372</link>
		<dc:creator>Eurania</dc:creator>
		<pubDate>Sun, 13 Dec 2009 14:53:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.abelcheng.com/?p=37#comment-1372</guid>
		<description>I think this guy can help with that problem you have

http://www.eduardobaret.com/2009/12/07/my-site-was-hacked-and-my-files-were-changed-reported-attack-site/</description>
		<content:encoded><![CDATA[<p>I think this guy can help with that problem you have</p>
<p><a href="http://www.eduardobaret.com/2009/12/07/my-site-was-hacked-and-my-files-were-changed-reported-attack-site/" rel="nofollow">http://www.eduardobaret.com/2009/12/07/my-site-was-hacked-and-my-files-were-changed-reported-attack-site/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brian</title>
		<link>http://www.abelcheng.com/my-sites-are-hacked-%e2%80%93-heres-how-i-fixed-it/comment-page-1/#comment-1351</link>
		<dc:creator>Brian</dc:creator>
		<pubDate>Wed, 08 Jul 2009 16:36:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.abelcheng.com/?p=37#comment-1351</guid>
		<description>hi, i had a keylogger trojan on my home pc they caputured my username and password of ftp, then attack it using the iframe attack i pulled the whole site down, what a nightmare, you need to download keyscrambler straight away, this plugin will scramble  letters your typing into the  browser. Do not login to your ftp or website from anyones elses computer or internet cafe etc, incase the trojan is present, if it happens change your email passwords too,  store username and password on a piece of paper, do a weekly scan of computer with super anti spyware, trust me you will pull you head off if happens.</description>
		<content:encoded><![CDATA[<p>hi, i had a keylogger trojan on my home pc they caputured my username and password of ftp, then attack it using the iframe attack i pulled the whole site down, what a nightmare, you need to download keyscrambler straight away, this plugin will scramble  letters your typing into the  browser. Do not login to your ftp or website from anyones elses computer or internet cafe etc, incase the trojan is present, if it happens change your email passwords too,  store username and password on a piece of paper, do a weekly scan of computer with super anti spyware, trust me you will pull you head off if happens.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike</title>
		<link>http://www.abelcheng.com/my-sites-are-hacked-%e2%80%93-heres-how-i-fixed-it/comment-page-1/#comment-1350</link>
		<dc:creator>Mike</dc:creator>
		<pubDate>Mon, 08 Jun 2009 21:20:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.abelcheng.com/?p=37#comment-1350</guid>
		<description>My sites are being hacked.

I&#039;m using FileZilla.   I&#039;ve searched and found out that most of the hacked sites were suing FileZilla AND an older version of Adobe Reader 8.

Is everybody using Adobe Reader 8 when their sites were hacked?

http://blog.unmaskparasites.com/2009/04/15/malicious-income-iframes-from-cn-domains/

thanks,
Mike</description>
		<content:encoded><![CDATA[<p>My sites are being hacked.</p>
<p>I&#8217;m using FileZilla.   I&#8217;ve searched and found out that most of the hacked sites were suing FileZilla AND an older version of Adobe Reader 8.</p>
<p>Is everybody using Adobe Reader 8 when their sites were hacked?</p>
<p><a href="http://blog.unmaskparasites.com/2009/04/15/malicious-income-iframes-from-cn-domains/" rel="nofollow">http://blog.unmaskparasites.com/2009/04/15/malicious-income-iframes-from-cn-domains/</a></p>
<p>thanks,<br />
Mike</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: HyperXR &#124; Advanced Hypertext Tool &#187; Blog Archive &#187; Gumblar .cn Exploit - 12 Facts About This Injected Script</title>
		<link>http://www.abelcheng.com/my-sites-are-hacked-%e2%80%93-heres-how-i-fixed-it/comment-page-1/#comment-1348</link>
		<dc:creator>HyperXR &#124; Advanced Hypertext Tool &#187; Blog Archive &#187; Gumblar .cn Exploit - 12 Facts About This Injected Script</dc:creator>
		<pubDate>Mon, 01 Jun 2009 02:05:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.abelcheng.com/?p=37#comment-1348</guid>
		<description>[...] by compromised FTP credentials. So start with your own computer. Scan it for spyware. Some people reported good results with [...]</description>
		<content:encoded><![CDATA[<p>[...] by compromised FTP credentials. So start with your own computer. Scan it for spyware. Some people reported good results with [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jimi</title>
		<link>http://www.abelcheng.com/my-sites-are-hacked-%e2%80%93-heres-how-i-fixed-it/comment-page-1/#comment-1345</link>
		<dc:creator>Jimi</dc:creator>
		<pubDate>Tue, 19 May 2009 02:26:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.abelcheng.com/?p=37#comment-1345</guid>
		<description>I suppose to reason he was asking question 2 was: if the passwords were saved then the script could have just been able to locate them once it was on your computer, thus identifying how the script works.</description>
		<content:encoded><![CDATA[<p>I suppose to reason he was asking question 2 was: if the passwords were saved then the script could have just been able to locate them once it was on your computer, thus identifying how the script works.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Admin</title>
		<link>http://www.abelcheng.com/my-sites-are-hacked-%e2%80%93-heres-how-i-fixed-it/comment-page-1/#comment-1344</link>
		<dc:creator>Admin</dc:creator>
		<pubDate>Mon, 11 May 2009 05:27:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.abelcheng.com/?p=37#comment-1344</guid>
		<description>@ Dennis: Answers to your questions:

1. I used FTP mode only but I changed to SFTP after this incident.

2. It doesn&#039;t matter, I think. Either way is vulnerable as the login details are leaked via FTP connection.

3. No, I don&#039;t. But later I noticed Malwarebytes overlooked this spyware. I manually removed this culprit from the registry after I found out the exact spyware. I shoud have updated this post with the latest findings but didn&#039;t get the time to do it.</description>
		<content:encoded><![CDATA[<p>@ Dennis: Answers to your questions:</p>
<p>1. I used FTP mode only but I changed to SFTP after this incident.</p>
<p>2. It doesn&#8217;t matter, I think. Either way is vulnerable as the login details are leaked via FTP connection.</p>
<p>3. No, I don&#8217;t. But later I noticed Malwarebytes overlooked this spyware. I manually removed this culprit from the registry after I found out the exact spyware. I shoud have updated this post with the latest findings but didn&#8217;t get the time to do it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Name</title>
		<link>http://www.abelcheng.com/my-sites-are-hacked-%e2%80%93-heres-how-i-fixed-it/comment-page-1/#comment-1343</link>
		<dc:creator>Name</dc:creator>
		<pubDate>Sun, 10 May 2009 07:57:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.abelcheng.com/?p=37#comment-1343</guid>
		<description>Never mind, they work if I enter email and website.. Here is original comment I was trying to post:

First I didn&#039;t use my F-Secure anti-virus at all as it did slowdown my PC too much and I got wpv[NUMBERS].exe virus from my very own website, I immidently deleted it and 20 minutes later my computer crashed and didn&#039;t boot anymore.
I fully reinstalled Windows and noticed 2 of my website had been infected by the virus. I removed the code from PHP and HTML files, it got hacked again and again!
Its not keylogger as I fixed the website with FULLY clean Windows installion. (though I visited the website and noticed F-Secure block a virus)
Im not using any CMS/Forum system, I just have infosniper IP query script and PJIRC, nothing else.
I tried setting permissions to all my files to 555 but after it got hacked the permission were 755 again..

I also contacted my host, NO ONE has logged into cPanel or FTP with my logins!
According to them its done remotetly via internet browser using glitch in PHP scripting, blaims my PHP scripts.
Since no one logged in using my logins I though there were no use to change my passwords but now after getting hacked 3th time I finally changed myself and will see if it helps at all..

There is &quot;solution&quot; on cPanel forums which is similar to yours.
http://forums.cpanel.net/showthread.php?t=78595

This post of yours or the one on cPanel didn&#039;t help me.. :(</description>
		<content:encoded><![CDATA[<p>Never mind, they work if I enter email and website.. Here is original comment I was trying to post:</p>
<p>First I didn&#8217;t use my F-Secure anti-virus at all as it did slowdown my PC too much and I got wpv[NUMBERS].exe virus from my very own website, I immidently deleted it and 20 minutes later my computer crashed and didn&#8217;t boot anymore.<br />
I fully reinstalled Windows and noticed 2 of my website had been infected by the virus. I removed the code from PHP and HTML files, it got hacked again and again!<br />
Its not keylogger as I fixed the website with FULLY clean Windows installion. (though I visited the website and noticed F-Secure block a virus)<br />
Im not using any CMS/Forum system, I just have infosniper IP query script and PJIRC, nothing else.<br />
I tried setting permissions to all my files to 555 but after it got hacked the permission were 755 again..</p>
<p>I also contacted my host, NO ONE has logged into cPanel or FTP with my logins!<br />
According to them its done remotetly via internet browser using glitch in PHP scripting, blaims my PHP scripts.<br />
Since no one logged in using my logins I though there were no use to change my passwords but now after getting hacked 3th time I finally changed myself and will see if it helps at all..</p>
<p>There is &#8220;solution&#8221; on cPanel forums which is similar to yours.<br />
<a href="http://forums.cpanel.net/showthread.php?t=78595" rel="nofollow">http://forums.cpanel.net/showthread.php?t=78595</a></p>
<p>This post of yours or the one on cPanel didn&#8217;t help me.. <img src='http://www.abelcheng.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Name</title>
		<link>http://www.abelcheng.com/my-sites-are-hacked-%e2%80%93-heres-how-i-fixed-it/comment-page-1/#comment-1342</link>
		<dc:creator>Name</dc:creator>
		<pubDate>Sun, 10 May 2009 07:57:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.abelcheng.com/?p=37#comment-1342</guid>
		<description>Comments not working!</description>
		<content:encoded><![CDATA[<p>Comments not working!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: UnderForge of Lack &#187; Blog Archive &#187; JUNIK.LV host malicious site instead of gumblar.cn</title>
		<link>http://www.abelcheng.com/my-sites-are-hacked-%e2%80%93-heres-how-i-fixed-it/comment-page-1/#comment-1341</link>
		<dc:creator>UnderForge of Lack &#187; Blog Archive &#187; JUNIK.LV host malicious site instead of gumblar.cn</dc:creator>
		<pubDate>Fri, 08 May 2009 08:20:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.abelcheng.com/?p=37#comment-1341</guid>
		<description>[...] 04.30.2009) * dotcomnameshop .cn (added: 05.02.2009)  orz...   ??????????? My Sites Are Hacked – Here’s How I Fixed It  ????MalwareByte ???????  [...]</description>
		<content:encoded><![CDATA[<p>[...] 04.30.2009) * dotcomnameshop .cn (added: 05.02.2009)  orz&#8230;   ??????????? My Sites Are Hacked – Here’s How I Fixed It  ????MalwareByte ???????  [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Denis</title>
		<link>http://www.abelcheng.com/my-sites-are-hacked-%e2%80%93-heres-how-i-fixed-it/comment-page-1/#comment-1340</link>
		<dc:creator>Denis</dc:creator>
		<pubDate>Wed, 06 May 2009 22:22:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.abelcheng.com/?p=37#comment-1340</guid>
		<description>Hi,

Great post!

Just a few questions. 

Did you use the FileZilla in the FTP or SFTP mode? 
Did you store the passwords in FileZilla or typed them in every time you uploaded files?
Do you remember the malware names found by Malwarebytes?</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>Great post!</p>
<p>Just a few questions. </p>
<p>Did you use the FileZilla in the FTP or SFTP mode?<br />
Did you store the passwords in FileZilla or typed them in every time you uploaded files?<br />
Do you remember the malware names found by Malwarebytes?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
