<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: MediaTemple Kinda Admits WordPress Sites They Host May Have Been Hacked by JohnnyA</title>
	<atom:link href="http://domainshane.com/mediatemple-kinda-admits-wordpress-sites-they-host-may-have-been-hacked-by-johnnya/feed/" rel="self" type="application/rss+xml" />
	<link>http://domainshane.com/mediatemple-kinda-admits-wordpress-sites-they-host-may-have-been-hacked-by-johnnya/</link>
	<description>Part Time Domaining for Full Time Profits</description>
	<lastBuildDate>Fri, 10 Feb 2012 13:38:37 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Chris Cavalluci</title>
		<link>http://domainshane.com/mediatemple-kinda-admits-wordpress-sites-they-host-may-have-been-hacked-by-johnnya/comment-page-1/#comment-2709</link>
		<dc:creator>Chris Cavalluci</dc:creator>
		<pubDate>Sat, 17 Jul 2010 16:42:54 +0000</pubDate>
		<guid isPermaLink="false">http://domainshane.com/?p=3480#comment-2709</guid>
		<description>There&#039;s a WP topic which is directly related to this exploit:
http://wordpress.org/support/topic/421834

So far, I&#039;ve found the malicious code in footer.php and archive.php 
mt could provide a little more assistance by scanning the server&#039;s php files are removing the malicious code as we learn more about the WP vulnerability.

Solving the problem is not so simple because the exploit may involve MySQL account access.

There goes my Saturday.</description>
		<content:encoded><![CDATA[<p>There&#8217;s a WP topic which is directly related to this exploit:<br />
<a href="http://wordpress.org/support/topic/421834" rel="nofollow">http://wordpress.org/support/topic/421834</a></p>
<p>So far, I&#8217;ve found the malicious code in footer.php and archive.php<br />
mt could provide a little more assistance by scanning the server&#8217;s php files are removing the malicious code as we learn more about the WP vulnerability.</p>
<p>Solving the problem is not so simple because the exploit may involve MySQL account access.</p>
<p>There goes my Saturday.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ener Hax</title>
		<link>http://domainshane.com/mediatemple-kinda-admits-wordpress-sites-they-host-may-have-been-hacked-by-johnnya/comment-page-1/#comment-2693</link>
		<dc:creator>Ener Hax</dc:creator>
		<pubDate>Fri, 16 Jul 2010 17:56:47 +0000</pubDate>
		<guid isPermaLink="false">http://domainshane.com/?p=3480#comment-2693</guid>
		<description>too bad they did not even mention this in their knowledge base or give the heads up on the 13th</description>
		<content:encoded><![CDATA[<p>too bad they did not even mention this in their knowledge base or give the heads up on the 13th</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aaron</title>
		<link>http://domainshane.com/mediatemple-kinda-admits-wordpress-sites-they-host-may-have-been-hacked-by-johnnya/comment-page-1/#comment-2648</link>
		<dc:creator>Aaron</dc:creator>
		<pubDate>Wed, 14 Jul 2010 13:53:39 +0000</pubDate>
		<guid isPermaLink="false">http://domainshane.com/?p=3480#comment-2648</guid>
		<description>We have about 40 websites on Media Temple&#039;s Grid Service - a ton of WordPress installs were hacked. We found the malicious code inside jquery js files - encrypted code is added to the top. We are also double-checking our htaccess files for anything else weird. I&#039;m betting they are gaining access via jquery calls or something similiar</description>
		<content:encoded><![CDATA[<p>We have about 40 websites on Media Temple&#8217;s Grid Service &#8211; a ton of WordPress installs were hacked. We found the malicious code inside jquery js files &#8211; encrypted code is added to the top. We are also double-checking our htaccess files for anything else weird. I&#8217;m betting they are gaining access via jquery calls or something similiar</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Antonio</title>
		<link>http://domainshane.com/mediatemple-kinda-admits-wordpress-sites-they-host-may-have-been-hacked-by-johnnya/comment-page-1/#comment-2647</link>
		<dc:creator>Antonio</dc:creator>
		<pubDate>Wed, 14 Jul 2010 13:49:23 +0000</pubDate>
		<guid isPermaLink="false">http://domainshane.com/?p=3480#comment-2647</guid>
		<description>Dear Travis of Mediatemple,
i would like to have these clarification too, just because in the support request i opened last night about the issue, the answer from the company was:

Unfortunately scanning your websites for vulnerabilities falls outside the (mt) Media Temple scope of support.  For information on working with a hacked or compromised server see our article at http://kb.mediatemple.net/questions/1577.

I was not asking for this, i ask you to tell me if mysites are exposed to a more dangerous type of hacking. A defacement is still a problem we can handle, but having 10-20 sites put down is an isssue. For me, MONEY! Money that i gave you to host my sites. I am sure a small buyer, sure not a big company. So, i don&#039;t deserve explanations?</description>
		<content:encoded><![CDATA[<p>Dear Travis of Mediatemple,<br />
i would like to have these clarification too, just because in the support request i opened last night about the issue, the answer from the company was:</p>
<p>Unfortunately scanning your websites for vulnerabilities falls outside the (mt) Media Temple scope of support.  For information on working with a hacked or compromised server see our article at <a href="http://kb.mediatemple.net/questions/1577" rel="nofollow">http://kb.mediatemple.net/questions/1577</a>.</p>
<p>I was not asking for this, i ask you to tell me if mysites are exposed to a more dangerous type of hacking. A defacement is still a problem we can handle, but having 10-20 sites put down is an isssue. For me, MONEY! Money that i gave you to host my sites. I am sure a small buyer, sure not a big company. So, i don&#8217;t deserve explanations?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ShaneCultra</title>
		<link>http://domainshane.com/mediatemple-kinda-admits-wordpress-sites-they-host-may-have-been-hacked-by-johnnya/comment-page-1/#comment-2646</link>
		<dc:creator>ShaneCultra</dc:creator>
		<pubDate>Wed, 14 Jul 2010 11:50:41 +0000</pubDate>
		<guid isPermaLink="false">http://domainshane.com/?p=3480#comment-2646</guid>
		<description>I appreciate the response MT.    I have and will stick with you as a host because you&#039;ve always taken care of any problems I&#039;ve ever had.  I am not as concerned with the problems as much as how they are handled</description>
		<content:encoded><![CDATA[<p>I appreciate the response MT.    I have and will stick with you as a host because you&#8217;ve always taken care of any problems I&#8217;ve ever had.  I am not as concerned with the problems as much as how they are handled</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Antonio</title>
		<link>http://domainshane.com/mediatemple-kinda-admits-wordpress-sites-they-host-may-have-been-hacked-by-johnnya/comment-page-1/#comment-2644</link>
		<dc:creator>Antonio</dc:creator>
		<pubDate>Wed, 14 Jul 2010 09:22:13 +0000</pubDate>
		<guid isPermaLink="false">http://domainshane.com/?p=3480#comment-2644</guid>
		<description>Not alone. I had all my sites hacked as well by a turkish hacker named RD-Z3RO.

I had all my top domains defaced (joomla, wordpress and plain html sites, not only wordpress, so dont bother please with &quot;hard your wordpress installation&quot;).

The hacker did void the .htaccess and pulled in a index.html, a logo.ong and a flag.jpg file.

I searched thru the entire domains and it seems that nothing else has been touched, except for those strange guys in my wordpress users (johnnyA but others as well).

I spent half an hour to change ALL the passwords (root, ftp&#039;s, emails, databases) and reconfigure them all.

I have to be honest: it seems to be a breach in the server, not in the software. But i am waiting for Mediatemple to clarify.
I have to be honest</description>
		<content:encoded><![CDATA[<p>Not alone. I had all my sites hacked as well by a turkish hacker named RD-Z3RO.</p>
<p>I had all my top domains defaced (joomla, wordpress and plain html sites, not only wordpress, so dont bother please with &#8220;hard your wordpress installation&#8221;).</p>
<p>The hacker did void the .htaccess and pulled in a index.html, a logo.ong and a flag.jpg file.</p>
<p>I searched thru the entire domains and it seems that nothing else has been touched, except for those strange guys in my wordpress users (johnnyA but others as well).</p>
<p>I spent half an hour to change ALL the passwords (root, ftp&#8217;s, emails, databases) and reconfigure them all.</p>
<p>I have to be honest: it seems to be a breach in the server, not in the software. But i am waiting for Mediatemple to clarify.<br />
I have to be honest</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: (mt) Travis</title>
		<link>http://domainshane.com/mediatemple-kinda-admits-wordpress-sites-they-host-may-have-been-hacked-by-johnnya/comment-page-1/#comment-2641</link>
		<dc:creator>(mt) Travis</dc:creator>
		<pubDate>Wed, 14 Jul 2010 01:59:59 +0000</pubDate>
		<guid isPermaLink="false">http://domainshane.com/?p=3480#comment-2641</guid>
		<description>Hi Shane-

It appears that you may need a bit more information to understand the scope of vulnerabilities on the internet  as a whole. We are more than happy to discuss these with you (and any client) that wants clarification on the impact and function of various security issues on the internet.  If you have the time, please email your contact information directly  to andrew[at]mediatemple[dot]net and we will contact you ASAP to  discuss  the matter.

The simple fact is, this hack is related to vulnerabilities within WordPress and/or plugins.  It is also possible that a backdoor was planted in your software previously. Think about it this way, when your PC gets a virus, do you blame the computer manufaturer for the vulnerabilities built into the Windows OS?

The simple fact that there are commonalities across the compromised sites indicates that this is a large scale attack being run against websites with similar configurations. If this were a vulnerability unique only to (mt) Media Temple hosted domains, there would be no other reports of simlar hacks against sites hosted on our competitors. However, over the past few months, we have seen a significant increase in WordPress and related PHP application compromises:

Nearly identical hack at Rackspace:
http://blog.sucuri.net/2010/06/mass-attack-of-wordpress-blogs-on-rackspace.html
http://blog.unmaskparasites.com/2010/06/14/attack-on-wordpress-blogs-on-rackspace/

The notorious Pharma Hack:
http://blog.sucuri.net/2010/07/understanding-and-cleaning-the-pharma-hack-on-wordpress.html
http://www.pearsonified.com/2010/04/wordpress-pharma-hack.php

We are looking into the possibility of offering a new service to our customers that would help ensure the security of their websites. We don&#039;t like hearing that our customer&#039;s sites are exposed to attack without any chance for resolution. Please help us determine the best way to proceed by filling out this quick survey:

http://mdtm.pl/a3lhQc</description>
		<content:encoded><![CDATA[<p>Hi Shane-</p>
<p>It appears that you may need a bit more information to understand the scope of vulnerabilities on the internet  as a whole. We are more than happy to discuss these with you (and any client) that wants clarification on the impact and function of various security issues on the internet.  If you have the time, please email your contact information directly  to andrew[at]mediatemple[dot]net and we will contact you ASAP to  discuss  the matter.</p>
<p>The simple fact is, this hack is related to vulnerabilities within WordPress and/or plugins.  It is also possible that a backdoor was planted in your software previously. Think about it this way, when your PC gets a virus, do you blame the computer manufaturer for the vulnerabilities built into the Windows OS?</p>
<p>The simple fact that there are commonalities across the compromised sites indicates that this is a large scale attack being run against websites with similar configurations. If this were a vulnerability unique only to (mt) Media Temple hosted domains, there would be no other reports of simlar hacks against sites hosted on our competitors. However, over the past few months, we have seen a significant increase in WordPress and related PHP application compromises:</p>
<p>Nearly identical hack at Rackspace:<br />
<a href="http://blog.sucuri.net/2010/06/mass-attack-of-wordpress-blogs-on-rackspace.html" rel="nofollow">http://blog.sucuri.net/2010/06/mass-attack-of-wordpress-blogs-on-rackspace.html</a><br />
<a href="http://blog.unmaskparasites.com/2010/06/14/attack-on-wordpress-blogs-on-rackspace/" rel="nofollow">http://blog.unmaskparasites.com/2010/06/14/attack-on-wordpress-blogs-on-rackspace/</a></p>
<p>The notorious Pharma Hack:<br />
<a href="http://blog.sucuri.net/2010/07/understanding-and-cleaning-the-pharma-hack-on-wordpress.html" rel="nofollow">http://blog.sucuri.net/2010/07/understanding-and-cleaning-the-pharma-hack-on-wordpress.html</a><br />
<a href="http://www.pearsonified.com/2010/04/wordpress-pharma-hack.php" rel="nofollow">http://www.pearsonified.com/2010/04/wordpress-pharma-hack.php</a></p>
<p>We are looking into the possibility of offering a new service to our customers that would help ensure the security of their websites. We don&#8217;t like hearing that our customer&#8217;s sites are exposed to attack without any chance for resolution. Please help us determine the best way to proceed by filling out this quick survey:</p>
<p><a href="http://mdtm.pl/a3lhQc" rel="nofollow">http://mdtm.pl/a3lhQc</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ShaneCultra</title>
		<link>http://domainshane.com/mediatemple-kinda-admits-wordpress-sites-they-host-may-have-been-hacked-by-johnnya/comment-page-1/#comment-2639</link>
		<dc:creator>ShaneCultra</dc:creator>
		<pubDate>Tue, 13 Jul 2010 21:39:04 +0000</pubDate>
		<guid isPermaLink="false">http://domainshane.com/?p=3480#comment-2639</guid>
		<description>Not sure if that was an attack against me or mediatemple so I&#039;ll leave it alone.  It was on my site for less that 12 hours and hopefully it didn&#039;t infect anyone.  I certainly am not going to make any money off it</description>
		<content:encoded><![CDATA[<p>Not sure if that was an attack against me or mediatemple so I&#8217;ll leave it alone.  It was on my site for less that 12 hours and hopefully it didn&#8217;t infect anyone.  I certainly am not going to make any money off it</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Soundly Reasoned</title>
		<link>http://domainshane.com/mediatemple-kinda-admits-wordpress-sites-they-host-may-have-been-hacked-by-johnnya/comment-page-1/#comment-2638</link>
		<dc:creator>Soundly Reasoned</dc:creator>
		<pubDate>Tue, 13 Jul 2010 21:08:26 +0000</pubDate>
		<guid isPermaLink="false">http://domainshane.com/?p=3480#comment-2638</guid>
		<description>&quot;... our best suggestion for recovering from this is a fresh installation of WordPress and then hardening your site against future attack attempts.&quot; MT

Yes, and a fresh Windows installation for those who visited your unsecured website mr. cultra. Meanwhile, it&#039;s great to see you are &#039;... going to make a ton of money because of it. DS&#039;. 

P.O.S.</description>
		<content:encoded><![CDATA[<p>&#8220;&#8230; our best suggestion for recovering from this is a fresh installation of WordPress and then hardening your site against future attack attempts.&#8221; MT</p>
<p>Yes, and a fresh Windows installation for those who visited your unsecured website mr. cultra. Meanwhile, it&#8217;s great to see you are &#8216;&#8230; going to make a ton of money because of it. DS&#8217;. </p>
<p>P.O.S.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Served from: domainshane.com @ 2012-02-10 12:38:29 -->
