<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Another Type of IFrame Hack (PHP Exploit)</title>
	<atom:link href="http://blog.unmaskparasites.com/2009/04/29/another-type-of-iframe-hack-php-exploit/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.unmaskparasites.com/2009/04/29/another-type-of-iframe-hack-php-exploit/</link>
	<description>Website insecurity by example</description>
	<lastBuildDate>Thu, 18 Mar 2010 09:08:28 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Dabbled &#187; Blog Archive &#187; iframe Hack &#8211; A Warning for readers and other bloggers</title>
		<link>http://blog.unmaskparasites.com/2009/04/29/another-type-of-iframe-hack-php-exploit/comment-page-1/#comment-4459</link>
		<dc:creator>Dabbled &#187; Blog Archive &#187; iframe Hack &#8211; A Warning for readers and other bloggers</dc:creator>
		<pubDate>Fri, 02 Oct 2009 12:27:48 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=171#comment-4459</guid>
		<description>[...] http://blog.unmaskparasites.com/2009/04/29/another-type-of-iframe-hack-php-exploit/ http://blog.unmaskparasites.com/2009/04/15/malicious-income-iframes-from-cn-domains/ [...]</description>
		<content:encoded><![CDATA[<p>[...] <a href="http://blog.unmaskparasites.com/2009/04/29/another-type-of-iframe-hack-php-exploit/" rel="nofollow">http://blog.unmaskparasites.com/2009/04/29/another-type-of-iframe-hack-php-exploit/</a> <a href="http://blog.unmaskparasites.com/2009/04/15/malicious-income-iframes-from-cn-domains/" rel="nofollow">http://blog.unmaskparasites.com/2009/04/15/malicious-income-iframes-from-cn-domains/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Vinz</title>
		<link>http://blog.unmaskparasites.com/2009/04/29/another-type-of-iframe-hack-php-exploit/comment-page-1/#comment-3904</link>
		<dc:creator>Vinz</dc:creator>
		<pubDate>Thu, 17 Sep 2009 10:51:16 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=171#comment-3904</guid>
		<description>Hello,
I suffered from the same. I&#039;m copying my M.O. here, which worked.
I got
/homepages/4/d134610354/htdocs/moebius77/blog2/wp-includes/default-widgets.php on line 423 as an error on my blog. No way to login or other. So:
1) re-install all your Wordpress blog, FTP it onto the server again, EXCEPT the WP-Content folder if you want to keep your images and themes.
2) Now you should be able to login. Go to your dashboard and install plugin &quot;Script Exploiter&quot;.
3) Run the plugin and look for malicious script. In my case, I had this baby:

copied on most of my install.php files, on all the themes (default, etc.), on the plugins and others.
4) Download the files with the added script, open them with an editor and erase all the garbage.
5) FTP them back on the server, change your password, you should be all right.
Cheers, hope this helps,
Vinz</description>
		<content:encoded><![CDATA[<p>Hello,<br />
I suffered from the same. I&#8217;m copying my M.O. here, which worked.<br />
I got<br />
/homepages/4/d134610354/htdocs/moebius77/blog2/wp-includes/default-widgets.php on line 423 as an error on my blog. No way to login or other. So:<br />
1) re-install all your Wordpress blog, FTP it onto the server again, EXCEPT the WP-Content folder if you want to keep your images and themes.<br />
2) Now you should be able to login. Go to your dashboard and install plugin &#8220;Script Exploiter&#8221;.<br />
3) Run the plugin and look for malicious script. In my case, I had this baby:</p>
<p>copied on most of my install.php files, on all the themes (default, etc.), on the plugins and others.<br />
4) Download the files with the added script, open them with an editor and erase all the garbage.<br />
5) FTP them back on the server, change your password, you should be all right.<br />
Cheers, hope this helps,<br />
Vinz</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DNS_Serva</title>
		<link>http://blog.unmaskparasites.com/2009/04/29/another-type-of-iframe-hack-php-exploit/comment-page-1/#comment-3486</link>
		<dc:creator>DNS_Serva</dc:creator>
		<pubDate>Mon, 14 Sep 2009 05:50:11 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=171#comment-3486</guid>
		<description>Technically that is incorrect, 
ActiveX scripting is used to exploit (Blame Microsft, Why oh why do they assume every ActiveX scripting call is safe? :sigh:)

Simple answer to internet users. Ditch Internet Explorer (if you use it) and goto Firefox, Install the No/Script add-on. Now you have control over scripting and nothing can exploit you via your browser!</description>
		<content:encoded><![CDATA[<p>Technically that is incorrect,<br />
ActiveX scripting is used to exploit (Blame Microsft, Why oh why do they assume every ActiveX scripting call is safe? :sigh:)</p>
<p>Simple answer to internet users. Ditch Internet Explorer (if you use it) and goto Firefox, Install the No/Script add-on. Now you have control over scripting and nothing can exploit you via your browser!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mary</title>
		<link>http://blog.unmaskparasites.com/2009/04/29/another-type-of-iframe-hack-php-exploit/comment-page-1/#comment-2418</link>
		<dc:creator>Mary</dc:creator>
		<pubDate>Thu, 03 Sep 2009 19:47:08 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=171#comment-2418</guid>
		<description>If your system is completely free of viruses and spyware (I use a firewall and used four different scanners including a rootkit scanner)...

If you change your FTP passwords often...

If you have deleted your website and uploaded a clean version of all your files...

But you are still being hit by iframe injections...

Chances are you are not using Secure FTP because you either didn&#039;t know it existed or your host doesn&#039;t provide it. This is exactly what happened to me. All of the helpful websites that provide information about iframe injections blame viruses, trojans or insecure passwords, and most do not point to another obvious solution. GO WITH A GOOD HOST that provides secure FTP and the option to use mod_security automatically on your domain panel. I switched to DreamHost, immediately switched ON Secure FTP, switched OFF regular FTP, and switched on extra security, and the attacks have finally stopped. 

IXWebHosting was of no help and was the cause of my problem. Even after I blocked all other IP addresses than mine to FTP, I continued to get hacked. I suspect that the problem was due to insecure FTP (password easily sniffed during transmission) and insecure hosting (hacker able to access my site even though they were disallowed from FTPing to it). 

When all else fails - do some really good research and change hosts.</description>
		<content:encoded><![CDATA[<p>If your system is completely free of viruses and spyware (I use a firewall and used four different scanners including a rootkit scanner)&#8230;</p>
<p>If you change your FTP passwords often&#8230;</p>
<p>If you have deleted your website and uploaded a clean version of all your files&#8230;</p>
<p>But you are still being hit by iframe injections&#8230;</p>
<p>Chances are you are not using Secure FTP because you either didn&#8217;t know it existed or your host doesn&#8217;t provide it. This is exactly what happened to me. All of the helpful websites that provide information about iframe injections blame viruses, trojans or insecure passwords, and most do not point to another obvious solution. GO WITH A GOOD HOST that provides secure FTP and the option to use mod_security automatically on your domain panel. I switched to DreamHost, immediately switched ON Secure FTP, switched OFF regular FTP, and switched on extra security, and the attacks have finally stopped. </p>
<p>IXWebHosting was of no help and was the cause of my problem. Even after I blocked all other IP addresses than mine to FTP, I continued to get hacked. I suspect that the problem was due to insecure FTP (password easily sniffed during transmission) and insecure hosting (hacker able to access my site even though they were disallowed from FTPing to it). </p>
<p>When all else fails &#8211; do some really good research and change hosts.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: oscarif</title>
		<link>http://blog.unmaskparasites.com/2009/04/29/another-type-of-iframe-hack-php-exploit/comment-page-1/#comment-1954</link>
		<dc:creator>oscarif</dc:creator>
		<pubDate>Tue, 04 Aug 2009 21:02:29 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=171#comment-1954</guid>
		<description>Hi

I had the same problem and I write two scripts to fix my site automatically.

I posted the solution and the script I used, the solution is here:

http://oscarif.wordpress.com/2009/08/04/eliminacion-automatica-de-iframe-oculto/

Unfortunatelly that post is in Spanish because my English is not good, but if someone wants to help me or wants to translate it to English, I&#039;ll try to explain for a good translation.

I hope my solution works fine and everyone can fix his site.</description>
		<content:encoded><![CDATA[<p>Hi</p>
<p>I had the same problem and I write two scripts to fix my site automatically.</p>
<p>I posted the solution and the script I used, the solution is here:</p>
<p><a href="http://oscarif.wordpress.com/2009/08/04/eliminacion-automatica-de-iframe-oculto/" rel="nofollow">http://oscarif.wordpress.com/2009/08/04/eliminacion-automatica-de-iframe-oculto/</a></p>
<p>Unfortunatelly that post is in Spanish because my English is not good, but if someone wants to help me or wants to translate it to English, I&#8217;ll try to explain for a good translation.</p>
<p>I hope my solution works fine and everyone can fix his site.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Denis</title>
		<link>http://blog.unmaskparasites.com/2009/04/29/another-type-of-iframe-hack-php-exploit/comment-page-1/#comment-1720</link>
		<dc:creator>Denis</dc:creator>
		<pubDate>Fri, 24 Jul 2009 09:49:22 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=171#comment-1720</guid>
		<description>The scripts use browser vulnerabilities to silently infect visitors&#039; computers with all sorts of malicious programs that steal personal (and financial) information, send spam from infected computers, hack other legitimate web sites and do all other illegal staff. It&#039;s a multimillion dollar &quot;business&quot;.</description>
		<content:encoded><![CDATA[<p>The scripts use browser vulnerabilities to silently infect visitors&#8217; computers with all sorts of malicious programs that steal personal (and financial) information, send spam from infected computers, hack other legitimate web sites and do all other illegal staff. It&#8217;s a multimillion dollar &#8220;business&#8221;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Musa</title>
		<link>http://blog.unmaskparasites.com/2009/04/29/another-type-of-iframe-hack-php-exploit/comment-page-1/#comment-1715</link>
		<dc:creator>Musa</dc:creator>
		<pubDate>Fri, 24 Jul 2009 08:52:05 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=171#comment-1715</guid>
		<description>I came across the iframe scripts on two of my websites in the past month. What don&#039;t understand &quot;call me retarded&quot; but why do they do this? or what is the script suppose to do?
The two that I came across were already blocked by google so I have not witnessed it in execution. Might I add, I am a freshmen to this invasion so this is a learning curve for me.</description>
		<content:encoded><![CDATA[<p>I came across the iframe scripts on two of my websites in the past month. What don&#8217;t understand &#8220;call me retarded&#8221; but why do they do this? or what is the script suppose to do?<br />
The two that I came across were already blocked by google so I have not witnessed it in execution. Might I add, I am a freshmen to this invasion so this is a learning curve for me.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mauren</title>
		<link>http://blog.unmaskparasites.com/2009/04/29/another-type-of-iframe-hack-php-exploit/comment-page-1/#comment-1556</link>
		<dc:creator>Mauren</dc:creator>
		<pubDate>Tue, 07 Jul 2009 22:45:42 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=171#comment-1556</guid>
		<description>Hi web owners,

I had that  cn.  Aka Gumblar on a couple of websites 3 weeks ago.

This one looks like it&#039;s about the same.. but im a security noob so maybe there are some big differences.

Solution for gumblar is:

Scan your pc with http://malwarebytes.org/

Then fix your FTP passwords, don&#039;t save them in any program and delete all the malicious code in de /index.php / html.

Note: make sure your the only one who&#039;s able to connect to the FTP.</description>
		<content:encoded><![CDATA[<p>Hi web owners,</p>
<p>I had that  cn.  Aka Gumblar on a couple of websites 3 weeks ago.</p>
<p>This one looks like it&#8217;s about the same.. but im a security noob so maybe there are some big differences.</p>
<p>Solution for gumblar is:</p>
<p>Scan your pc with <a href="http://malwarebytes.org/" rel="nofollow">http://malwarebytes.org/</a></p>
<p>Then fix your FTP passwords, don&#8217;t save them in any program and delete all the malicious code in de /index.php / html.</p>
<p>Note: make sure your the only one who&#8217;s able to connect to the FTP.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Denis</title>
		<link>http://blog.unmaskparasites.com/2009/04/29/another-type-of-iframe-hack-php-exploit/comment-page-1/#comment-1555</link>
		<dc:creator>Denis</dc:creator>
		<pubDate>Tue, 07 Jul 2009 18:39:29 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=171#comment-1555</guid>
		<description>It&#039;s good that you care about your site visitors. However I would be also concerned about the fact the your local computer is infected and that criminals have access to your site and can modify it the way they want.</description>
		<content:encoded><![CDATA[<p>It&#8217;s good that you care about your site visitors. However I would be also concerned about the fact the your local computer is infected and that criminals have access to your site and can modify it the way they want.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Shah Hussain</title>
		<link>http://blog.unmaskparasites.com/2009/04/29/another-type-of-iframe-hack-php-exploit/comment-page-1/#comment-1550</link>
		<dc:creator>Shah Hussain</dc:creator>
		<pubDate>Tue, 07 Jul 2009 10:13:21 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=171#comment-1550</guid>
		<description>hello all,
i read all the comments on this page because my site has also one of the infected like your with iframe injections.
But I have got some other solution for my site to keep away from the viruses. I have embed some javascript code which remove the iframe from my index pages with onload or init() time of my page.
and it works fine 
if some one else also have any good solution for removing this virus attack (IFrame Attack) then please also share with me... 
thanks you all</description>
		<content:encoded><![CDATA[<p>hello all,<br />
i read all the comments on this page because my site has also one of the infected like your with iframe injections.<br />
But I have got some other solution for my site to keep away from the viruses. I have embed some javascript code which remove the iframe from my index pages with onload or init() time of my page.<br />
and it works fine<br />
if some one else also have any good solution for removing this virus attack (IFrame Attack) then please also share with me&#8230;<br />
thanks you all</p>
]]></content:encoded>
	</item>
</channel>
</rss>
