<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Another Type of IFrame Hack (PHP Exploit)</title>
	<atom:link href="http://blog.unmaskparasites.com/2009/04/29/another-type-of-iframe-hack-php-exploit/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.unmaskparasites.com/2009/04/29/another-type-of-iframe-hack-php-exploit/</link>
	<description>Website insecurity by example</description>
	<lastBuildDate>Sun, 05 Feb 2012 10:06:25 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Eric Sebasta</title>
		<link>http://blog.unmaskparasites.com/2009/04/29/another-type-of-iframe-hack-php-exploit/comment-page-1/#comment-14082</link>
		<dc:creator>Eric Sebasta</dc:creator>
		<pubDate>Thu, 03 Nov 2011 15:37:26 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=171#comment-14082</guid>
		<description>Listen folks, for you games, keep windows. For work, use Linux or OS X. And for the love of God, do NOT use Adobe Acrobat reader. It has a worse track record then Fat Albert. If you must use windows use Sumatra PDF or FoxIt pdf, which both have a far better security record when it comes to PDF exploits.</description>
		<content:encoded><![CDATA[<p>Listen folks, for you games, keep windows. For work, use Linux or OS X. And for the love of God, do NOT use Adobe Acrobat reader. It has a worse track record then Fat Albert. If you must use windows use Sumatra PDF or FoxIt pdf, which both have a far better security record when it comes to PDF exploits.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Vishal Sharma</title>
		<link>http://blog.unmaskparasites.com/2009/04/29/another-type-of-iframe-hack-php-exploit/comment-page-1/#comment-7691</link>
		<dc:creator>Vishal Sharma</dc:creator>
		<pubDate>Fri, 04 Jun 2010 01:51:33 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=171#comment-7691</guid>
		<description>We have removed the script. The site was uploaded with IP Address and domain was pointed a day after . Now If I am using search by name its absolutely fine but other pages are still showing with IP which were crawled when domain was not pointed.

However , at some places its showing okay. I am not sure..
 
Does it takes some time ?</description>
		<content:encoded><![CDATA[<p>We have removed the script. The site was uploaded with IP Address and domain was pointed a day after . Now If I am using search by name its absolutely fine but other pages are still showing with IP which were crawled when domain was not pointed.</p>
<p>However , at some places its showing okay. I am not sure..</p>
<p>Does it takes some time ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Denis</title>
		<link>http://blog.unmaskparasites.com/2009/04/29/another-type-of-iframe-hack-php-exploit/comment-page-1/#comment-7624</link>
		<dc:creator>Denis</dc:creator>
		<pubDate>Mon, 31 May 2010 07:04:27 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=171#comment-7624</guid>
		<description>No, you didn&#039;t. The malicious script is still there.

And I provided you with the link to the article that contains everything you need to know to detect, clean up and prevent reinfection.</description>
		<content:encoded><![CDATA[<p>No, you didn&#8217;t. The malicious script is still there.</p>
<p>And I provided you with the link to the article that contains everything you need to know to detect, clean up and prevent reinfection.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Vishal Sharma</title>
		<link>http://blog.unmaskparasites.com/2009/04/29/another-type-of-iframe-hack-php-exploit/comment-page-1/#comment-7620</link>
		<dc:creator>Vishal Sharma</dc:creator>
		<pubDate>Mon, 31 May 2010 04:03:17 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=171#comment-7620</guid>
		<description>Whats the permanent solution to this ? We have removed the script ..</description>
		<content:encoded><![CDATA[<p>Whats the permanent solution to this ? We have removed the script ..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Denis</title>
		<link>http://blog.unmaskparasites.com/2009/04/29/another-type-of-iframe-hack-php-exploit/comment-page-1/#comment-7616</link>
		<dc:creator>Denis</dc:creator>
		<pubDate>Sun, 30 May 2010 21:34:09 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=171#comment-7616</guid>
		<description>Vishal,

I had to remove your site link from your signature, since it is infected with Gumblar:
http://www.UnmaskParasites.com/security-report/?page=www.realtygurgaon.com

You can read about Gumblar infection here:
http://blog.unmaskparasites.com/2009/10/23/revenge-of-gumblar-zombies/
this article contains some solutions</description>
		<content:encoded><![CDATA[<p>Vishal,</p>
<p>I had to remove your site link from your signature, since it is infected with Gumblar:<br />
<a href="http://www.UnmaskParasites.com/security-report/?page=www.realtygurgaon.com" rel="nofollow">http://www.UnmaskParasites.com/security-report/?page=www.realtygurgaon.com</a></p>
<p>You can read about Gumblar infection here:<br />
<a href="http://blog.unmaskparasites.com/2009/10/23/revenge-of-gumblar-zombies/" rel="nofollow">http://blog.unmaskparasites.com/2009/10/23/revenge-of-gumblar-zombies/</a><br />
this article contains some solutions</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Vishal Sharma</title>
		<link>http://blog.unmaskparasites.com/2009/04/29/another-type-of-iframe-hack-php-exploit/comment-page-1/#comment-7611</link>
		<dc:creator>Vishal Sharma</dc:creator>
		<pubDate>Sun, 30 May 2010 12:25:54 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=171#comment-7611</guid>
		<description>I have been facing Iframe and virus injuctions .


We have changed the front end from Asp to PHP with my sql support . 

Could you suggest with a permanent solution to this problem ? 

Look forward to hearing from you.


Regards,
Vishal Sharma
Email : realtygurgaon@gmail.com</description>
		<content:encoded><![CDATA[<p>I have been facing Iframe and virus injuctions .</p>
<p>We have changed the front end from Asp to PHP with my sql support . </p>
<p>Could you suggest with a permanent solution to this problem ? </p>
<p>Look forward to hearing from you.</p>
<p>Regards,<br />
Vishal Sharma<br />
Email : <a href="mailto:realtygurgaon@gmail.com">realtygurgaon@gmail.com</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dabbled &#187; Blog Archive &#187; iframe Hack &#8211; A Warning for readers and other bloggers</title>
		<link>http://blog.unmaskparasites.com/2009/04/29/another-type-of-iframe-hack-php-exploit/comment-page-1/#comment-4459</link>
		<dc:creator>Dabbled &#187; Blog Archive &#187; iframe Hack &#8211; A Warning for readers and other bloggers</dc:creator>
		<pubDate>Fri, 02 Oct 2009 12:27:48 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=171#comment-4459</guid>
		<description>[...] http://blog.unmaskparasites.com/2009/04/29/another-type-of-iframe-hack-php-exploit/ http://blog.unmaskparasites.com/2009/04/15/malicious-income-iframes-from-cn-domains/ [...]</description>
		<content:encoded><![CDATA[<p>[...] <a href="http://blog.unmaskparasites.com/2009/04/29/another-type-of-iframe-hack-php-exploit/" rel="nofollow">http://blog.unmaskparasites.com/2009/04/29/another-type-of-iframe-hack-php-exploit/</a> <a href="http://blog.unmaskparasites.com/2009/04/15/malicious-income-iframes-from-cn-domains/" rel="nofollow">http://blog.unmaskparasites.com/2009/04/15/malicious-income-iframes-from-cn-domains/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Vinz</title>
		<link>http://blog.unmaskparasites.com/2009/04/29/another-type-of-iframe-hack-php-exploit/comment-page-1/#comment-3904</link>
		<dc:creator>Vinz</dc:creator>
		<pubDate>Thu, 17 Sep 2009 10:51:16 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=171#comment-3904</guid>
		<description>Hello,
I suffered from the same. I&#039;m copying my M.O. here, which worked.
I got
/homepages/4/d134610354/htdocs/moebius77/blog2/wp-includes/default-widgets.php on line 423 as an error on my blog. No way to login or other. So:
1) re-install all your Wordpress blog, FTP it onto the server again, EXCEPT the WP-Content folder if you want to keep your images and themes.
2) Now you should be able to login. Go to your dashboard and install plugin &quot;Script Exploiter&quot;.
3) Run the plugin and look for malicious script. In my case, I had this baby:

copied on most of my install.php files, on all the themes (default, etc.), on the plugins and others.
4) Download the files with the added script, open them with an editor and erase all the garbage.
5) FTP them back on the server, change your password, you should be all right.
Cheers, hope this helps,
Vinz</description>
		<content:encoded><![CDATA[<p>Hello,<br />
I suffered from the same. I&#8217;m copying my M.O. here, which worked.<br />
I got<br />
/homepages/4/d134610354/htdocs/moebius77/blog2/wp-includes/default-widgets.php on line 423 as an error on my blog. No way to login or other. So:<br />
1) re-install all your Wordpress blog, FTP it onto the server again, EXCEPT the WP-Content folder if you want to keep your images and themes.<br />
2) Now you should be able to login. Go to your dashboard and install plugin &#8220;Script Exploiter&#8221;.<br />
3) Run the plugin and look for malicious script. In my case, I had this baby:</p>
<p>copied on most of my install.php files, on all the themes (default, etc.), on the plugins and others.<br />
4) Download the files with the added script, open them with an editor and erase all the garbage.<br />
5) FTP them back on the server, change your password, you should be all right.<br />
Cheers, hope this helps,<br />
Vinz</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DNS_Serva</title>
		<link>http://blog.unmaskparasites.com/2009/04/29/another-type-of-iframe-hack-php-exploit/comment-page-1/#comment-3486</link>
		<dc:creator>DNS_Serva</dc:creator>
		<pubDate>Mon, 14 Sep 2009 05:50:11 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=171#comment-3486</guid>
		<description>Technically that is incorrect, 
ActiveX scripting is used to exploit (Blame Microsft, Why oh why do they assume every ActiveX scripting call is safe? :sigh:)

Simple answer to internet users. Ditch Internet Explorer (if you use it) and goto Firefox, Install the No/Script add-on. Now you have control over scripting and nothing can exploit you via your browser!</description>
		<content:encoded><![CDATA[<p>Technically that is incorrect,<br />
ActiveX scripting is used to exploit (Blame Microsft, Why oh why do they assume every ActiveX scripting call is safe? :sigh:)</p>
<p>Simple answer to internet users. Ditch Internet Explorer (if you use it) and goto Firefox, Install the No/Script add-on. Now you have control over scripting and nothing can exploit you via your browser!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mary</title>
		<link>http://blog.unmaskparasites.com/2009/04/29/another-type-of-iframe-hack-php-exploit/comment-page-1/#comment-2418</link>
		<dc:creator>Mary</dc:creator>
		<pubDate>Thu, 03 Sep 2009 19:47:08 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=171#comment-2418</guid>
		<description>If your system is completely free of viruses and spyware (I use a firewall and used four different scanners including a rootkit scanner)...

If you change your FTP passwords often...

If you have deleted your website and uploaded a clean version of all your files...

But you are still being hit by iframe injections...

Chances are you are not using Secure FTP because you either didn&#039;t know it existed or your host doesn&#039;t provide it. This is exactly what happened to me. All of the helpful websites that provide information about iframe injections blame viruses, trojans or insecure passwords, and most do not point to another obvious solution. GO WITH A GOOD HOST that provides secure FTP and the option to use mod_security automatically on your domain panel. I switched to DreamHost, immediately switched ON Secure FTP, switched OFF regular FTP, and switched on extra security, and the attacks have finally stopped. 

IXWebHosting was of no help and was the cause of my problem. Even after I blocked all other IP addresses than mine to FTP, I continued to get hacked. I suspect that the problem was due to insecure FTP (password easily sniffed during transmission) and insecure hosting (hacker able to access my site even though they were disallowed from FTPing to it). 

When all else fails - do some really good research and change hosts.</description>
		<content:encoded><![CDATA[<p>If your system is completely free of viruses and spyware (I use a firewall and used four different scanners including a rootkit scanner)&#8230;</p>
<p>If you change your FTP passwords often&#8230;</p>
<p>If you have deleted your website and uploaded a clean version of all your files&#8230;</p>
<p>But you are still being hit by iframe injections&#8230;</p>
<p>Chances are you are not using Secure FTP because you either didn&#8217;t know it existed or your host doesn&#8217;t provide it. This is exactly what happened to me. All of the helpful websites that provide information about iframe injections blame viruses, trojans or insecure passwords, and most do not point to another obvious solution. GO WITH A GOOD HOST that provides secure FTP and the option to use mod_security automatically on your domain panel. I switched to DreamHost, immediately switched ON Secure FTP, switched OFF regular FTP, and switched on extra security, and the attacks have finally stopped. </p>
<p>IXWebHosting was of no help and was the cause of my problem. Even after I blocked all other IP addresses than mine to FTP, I continued to get hacked. I suspect that the problem was due to insecure FTP (password easily sniffed during transmission) and insecure hosting (hacker able to access my site even though they were disallowed from FTPing to it). </p>
<p>When all else fails &#8211; do some really good research and change hosts.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

