<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Gumblar Breaks WordPress blogs and other complex PHP sites</title>
	<atom:link href="http://blog.unmaskparasites.com/2009/11/04/gumblar-breaks-wordpress-blogs-and-other-complex-php-sites/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.unmaskparasites.com/2009/11/04/gumblar-breaks-wordpress-blogs-and-other-complex-php-sites/</link>
	<description>Website insecurity by example</description>
	<lastBuildDate>Sun, 05 Feb 2012 10:06:25 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: 0-day wordpress vulnerability results in many Media Temple malware infections - Page 5 - WordPress Tavern Forum</title>
		<link>http://blog.unmaskparasites.com/2009/11/04/gumblar-breaks-wordpress-blogs-and-other-complex-php-sites/comment-page-1/#comment-6857</link>
		<dc:creator>0-day wordpress vulnerability results in many Media Temple malware infections - Page 5 - WordPress Tavern Forum</dc:creator>
		<pubDate>Fri, 12 Mar 2010 15:07:23 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=384#comment-6857</guid>
		<description>[...] the corrupted files to your own server.  http://www.pcantivirusreviews.com/up...rculating.html http://blog.unmaskparasites.com/2009...lex-php-sites/ http://blog.unmaskparasites.com/2009...jected-script/ [...]</description>
		<content:encoded><![CDATA[<p>[...] the corrupted files to your own server.  <a href="http://www.pcantivirusreviews.com/up...rculating.html" rel="nofollow">http://www.pcantivirusreviews.com/up&#8230;rculating.html</a> <a href="http://blog.unmaskparasites.com/2009...lex-php-sites/" rel="nofollow">http://blog.unmaskparasites.com/2009&#8230;lex-php-sites/</a> <a href="http://blog.unmaskparasites.com/2009...jected-script/" rel="nofollow">http://blog.unmaskparasites.com/2009&#8230;jected-script/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gagner de l'argent sur internet</title>
		<link>http://blog.unmaskparasites.com/2009/11/04/gumblar-breaks-wordpress-blogs-and-other-complex-php-sites/comment-page-1/#comment-6779</link>
		<dc:creator>Gagner de l'argent sur internet</dc:creator>
		<pubDate>Sat, 20 Feb 2010 09:32:23 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=384#comment-6779</guid>
		<description>I just recently purchased a software program that will protect and eradicate this virus while restoring your infected files to their original state.

You can see a video on it at: &lt;a href=&quot;http://www.webserversguardian.com&quot; rel=&quot;nofollow&quot;&gt;www.webserversguardian.com&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>I just recently purchased a software program that will protect and eradicate this virus while restoring your infected files to their original state.</p>
<p>You can see a video on it at: <a href="http://www.webserversguardian.com" rel="nofollow">http://www.webserversguardian.com</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Content Management System Blog, Latest news on Joomla, Drupal, Wordpress, Mod-x</title>
		<link>http://blog.unmaskparasites.com/2009/11/04/gumblar-breaks-wordpress-blogs-and-other-complex-php-sites/comment-page-1/#comment-6769</link>
		<dc:creator>Content Management System Blog, Latest news on Joomla, Drupal, Wordpress, Mod-x</dc:creator>
		<pubDate>Thu, 18 Feb 2010 11:28:20 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=384#comment-6769</guid>
		<description>[...] a set of tools and ways for admins to retake their sites back, which can be found on his blog at this link. ﻿   Filed under the category Joomla   Rating: 0.00 (login to vote)    Tags Gumblar Crashes [...]</description>
		<content:encoded><![CDATA[<p>[...] a set of tools and ways for admins to retake their sites back, which can be found on his blog at this link. ﻿   Filed under the category Joomla   Rating: 0.00 (login to vote)    Tags Gumblar Crashes [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pamela18</title>
		<link>http://blog.unmaskparasites.com/2009/11/04/gumblar-breaks-wordpress-blogs-and-other-complex-php-sites/comment-page-1/#comment-6762</link>
		<dc:creator>pamela18</dc:creator>
		<pubDate>Mon, 15 Feb 2010 22:00:53 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=384#comment-6762</guid>
		<description>How to remove Trojan: Backdoor

http://www.tips29.com/2009/01/how-to-remove-trojan-backdoor.html</description>
		<content:encoded><![CDATA[<p>How to remove Trojan: Backdoor</p>
<p><a href="http://www.tips29.com/2009/01/how-to-remove-trojan-backdoor.html" rel="nofollow">http://www.tips29.com/2009/01/how-to-remove-trojan-backdoor.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Obnoxious Clients - CLEARLY I&#39;M NOT A PEOPLE PERSON</title>
		<link>http://blog.unmaskparasites.com/2009/11/04/gumblar-breaks-wordpress-blogs-and-other-complex-php-sites/comment-page-1/#comment-6731</link>
		<dc:creator>Obnoxious Clients - CLEARLY I&#39;M NOT A PEOPLE PERSON</dc:creator>
		<pubDate>Sun, 07 Feb 2010 08:13:39 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=384#comment-6731</guid>
		<description>[...] Gumblar Breaks WordPress blogs and other complex PHP sites [...]</description>
		<content:encoded><![CDATA[<p>[...] Gumblar Breaks WordPress blogs and other complex PHP sites [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: &#187; PHP Sites Infected By BotNet Outbreak Official Geek Blog</title>
		<link>http://blog.unmaskparasites.com/2009/11/04/gumblar-breaks-wordpress-blogs-and-other-complex-php-sites/comment-page-1/#comment-5465</link>
		<dc:creator>&#187; PHP Sites Infected By BotNet Outbreak Official Geek Blog</dc:creator>
		<pubDate>Sat, 07 Nov 2009 13:01:09 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=384#comment-5465</guid>
		<description>[...] to the blog Unmask Parasites, there is a new version of the Gumblar botnet making the rounds on PHP based websites. Back in May of this year, this malicious botnet was [...]</description>
		<content:encoded><![CDATA[<p>[...] to the blog Unmask Parasites, there is a new version of the Gumblar botnet making the rounds on PHP based websites. Back in May of this year, this malicious botnet was [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Watch Out, Watchout the Gumblar Botnets About &#124; Blogging And...</title>
		<link>http://blog.unmaskparasites.com/2009/11/04/gumblar-breaks-wordpress-blogs-and-other-complex-php-sites/comment-page-1/#comment-5462</link>
		<dc:creator>Watch Out, Watchout the Gumblar Botnets About &#124; Blogging And...</dc:creator>
		<pubDate>Sat, 07 Nov 2009 07:33:02 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=384#comment-5462</guid>
		<description>[...] to Weblog Tools Collection and the blog Unmask Parasites, there is a new version of the Gumblar botnet making the rounds on PHP based [...]</description>
		<content:encoded><![CDATA[<p>[...] to Weblog Tools Collection and the blog Unmask Parasites, there is a new version of the Gumblar botnet making the rounds on PHP based [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Denis</title>
		<link>http://blog.unmaskparasites.com/2009/11/04/gumblar-breaks-wordpress-blogs-and-other-complex-php-sites/comment-page-1/#comment-5443</link>
		<dc:creator>Denis</dc:creator>
		<pubDate>Fri, 06 Nov 2009 15:23:43 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=384#comment-5443</guid>
		<description>They don&#039;t specifically target WordPress. They infect any PHP driven websites.

However, the PHP code they inject into existing files doesn&#039;t take into account complex WordPress architecture, which leads to &quot;redeclaration errors&quot; and breaks compromised blogs.

So any version of WordPress can be broken. Just like any other complex PHP sites (i.e. Joomla, Drupal, phpBB, etc.)

In this attack, hackers use &lt;a href=&quot;http://blog.unmaskparasites.com/2009/09/23/10-ftp-clients-malware-steals-credentials-from/&quot; rel=&quot;nofollow&quot;&gt;FTP credentials stolen from computers of webmaster&lt;/a&gt;, so WordPress itself is not to blame.</description>
		<content:encoded><![CDATA[<p>They don&#8217;t specifically target WordPress. They infect any PHP driven websites.</p>
<p>However, the PHP code they inject into existing files doesn&#8217;t take into account complex WordPress architecture, which leads to &#8220;redeclaration errors&#8221; and breaks compromised blogs.</p>
<p>So any version of WordPress can be broken. Just like any other complex PHP sites (i.e. Joomla, Drupal, phpBB, etc.)</p>
<p>In this attack, hackers use <a href="http://blog.unmaskparasites.com/2009/09/23/10-ftp-clients-malware-steals-credentials-from/" rel="nofollow">FTP credentials stolen from computers of webmaster</a>, so WordPress itself is not to blame.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Watch Out For The Gumblar Botnet &#171; Weblog Tools Collection</title>
		<link>http://blog.unmaskparasites.com/2009/11/04/gumblar-breaks-wordpress-blogs-and-other-complex-php-sites/comment-page-1/#comment-5442</link>
		<dc:creator>Watch Out For The Gumblar Botnet &#171; Weblog Tools Collection</dc:creator>
		<pubDate>Fri, 06 Nov 2009 15:18:10 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=384#comment-5442</guid>
		<description>[...] to the blog Unmask Parasites, there is a new version of the Gumblar botnet making the rounds on PHP based websites. Back in May of this year, this malicious botnet was [...]</description>
		<content:encoded><![CDATA[<p>[...] to the blog Unmask Parasites, there is a new version of the Gumblar botnet making the rounds on PHP based websites. Back in May of this year, this malicious botnet was [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Will Anderson</title>
		<link>http://blog.unmaskparasites.com/2009/11/04/gumblar-breaks-wordpress-blogs-and-other-complex-php-sites/comment-page-1/#comment-5441</link>
		<dc:creator>Will Anderson</dc:creator>
		<pubDate>Fri, 06 Nov 2009 15:10:54 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=384#comment-5441</guid>
		<description>Of course it stinks that someone would create something like this in the first place, but part of me has to smile at their newbish mistake.</description>
		<content:encoded><![CDATA[<p>Of course it stinks that someone would create something like this in the first place, but part of me has to smile at their newbish mistake.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

