<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Attack on WordPress Blogs on RackSpace</title>
	<atom:link href="http://blog.unmaskparasites.com/2010/06/14/attack-on-wordpress-blogs-on-rackspace/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.unmaskparasites.com/2010/06/14/attack-on-wordpress-blogs-on-rackspace/</link>
	<description>Website insecurity by example</description>
	<lastBuildDate>Sun, 05 Feb 2012 10:06:25 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Denis</title>
		<link>http://blog.unmaskparasites.com/2010/06/14/attack-on-wordpress-blogs-on-rackspace/comment-page-1/#comment-8604</link>
		<dc:creator>Denis</dc:creator>
		<pubDate>Sun, 01 Aug 2010 21:18:25 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=637#comment-8604</guid>
		<description>Hi Lee,

What sort of problems now? The same as described in this article or something different?</description>
		<content:encoded><![CDATA[<p>Hi Lee,</p>
<p>What sort of problems now? The same as described in this article or something different?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lee Adler</title>
		<link>http://blog.unmaskparasites.com/2010/06/14/attack-on-wordpress-blogs-on-rackspace/comment-page-1/#comment-8595</link>
		<dc:creator>Lee Adler</dc:creator>
		<pubDate>Fri, 30 Jul 2010 22:59:15 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=637#comment-8595</guid>
		<description>I&#039;m on Rackspace Cloud and have started having problems again in the past two days. Their response is always the same- &quot;Not our problem. We don&#039;t support coding issues.&quot;</description>
		<content:encoded><![CDATA[<p>I&#8217;m on Rackspace Cloud and have started having problems again in the past two days. Their response is always the same- &#8220;Not our problem. We don&#8217;t support coding issues.&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BC</title>
		<link>http://blog.unmaskparasites.com/2010/06/14/attack-on-wordpress-blogs-on-rackspace/comment-page-1/#comment-8031</link>
		<dc:creator>BC</dc:creator>
		<pubDate>Fri, 25 Jun 2010 13:02:40 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=637#comment-8031</guid>
		<description>Thanks at ton for your article.  I have found 3 of our WP sites that got hacked.  I have had WP sites on the cloud for a while and I have had a good amount of them hacked.  I was asking their support about 3-4 months ago if there is a reason the sites hosted there seemed to get hacked more often than other host I still have some other domains on and of course there is nothing they are doing wrong.  That kind of bugs me.  They do have good support and I will most likely stay with them as hopefully they are more aware now, but I wish they would take a little ownership and admit that they had some part in this. I just got another email this morning, http://status.mosso.com/2010/06/current-investigation-of-security-incident-update.html, I was running the latest version 2.9.2, had good Passwords, File permissions etc.  Also, I think the main reason I will likely stay is it would be a pain to move all sites elsewhere.  Lets just hope this awakens them.  :-)  Thanks again for your post!</description>
		<content:encoded><![CDATA[<p>Thanks at ton for your article.  I have found 3 of our WP sites that got hacked.  I have had WP sites on the cloud for a while and I have had a good amount of them hacked.  I was asking their support about 3-4 months ago if there is a reason the sites hosted there seemed to get hacked more often than other host I still have some other domains on and of course there is nothing they are doing wrong.  That kind of bugs me.  They do have good support and I will most likely stay with them as hopefully they are more aware now, but I wish they would take a little ownership and admit that they had some part in this. I just got another email this morning, <a href="http://status.mosso.com/2010/06/current-investigation-of-security-incident-update.html" rel="nofollow">http://status.mosso.com/2010/06/current-investigation-of-security-incident-update.html</a>, I was running the latest version 2.9.2, had good Passwords, File permissions etc.  Also, I think the main reason I will likely stay is it would be a pain to move all sites elsewhere.  Lets just hope this awakens them.  :-)  Thanks again for your post!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Otto</title>
		<link>http://blog.unmaskparasites.com/2010/06/14/attack-on-wordpress-blogs-on-rackspace/comment-page-1/#comment-8010</link>
		<dc:creator>Otto</dc:creator>
		<pubDate>Thu, 24 Jun 2010 16:27:46 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=637#comment-8010</guid>
		<description>I don&#039;t know what you&#039;re talking about. Neither of those is a security hole, as to access any of those functions from the backend, you must be authenticated to begin with.</description>
		<content:encoded><![CDATA[<p>I don&#8217;t know what you&#8217;re talking about. Neither of those is a security hole, as to access any of those functions from the backend, you must be authenticated to begin with.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DE</title>
		<link>http://blog.unmaskparasites.com/2010/06/14/attack-on-wordpress-blogs-on-rackspace/comment-page-1/#comment-7999</link>
		<dc:creator>DE</dc:creator>
		<pubDate>Thu, 24 Jun 2010 08:04:47 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=637#comment-7999</guid>
		<description>Actually just read the most recent update here from Rackspace.  Looks like they have been proactively addressing things and helping to make recommendations on proper secure setup.

http://status.mosso.com/2010/06/current-investigation-of-security-incident.html</description>
		<content:encoded><![CDATA[<p>Actually just read the most recent update here from Rackspace.  Looks like they have been proactively addressing things and helping to make recommendations on proper secure setup.</p>
<p><a href="http://status.mosso.com/2010/06/current-investigation-of-security-incident.html" rel="nofollow">http://status.mosso.com/2010/06/current-investigation-of-security-incident.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DE</title>
		<link>http://blog.unmaskparasites.com/2010/06/14/attack-on-wordpress-blogs-on-rackspace/comment-page-1/#comment-7998</link>
		<dc:creator>DE</dc:creator>
		<pubDate>Thu, 24 Jun 2010 07:44:21 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=637#comment-7998</guid>
		<description>@Rob La Gesse

Any word on Rackspace Cloud and WordPress and what the issues were for Rackspace hosted sites?

Am/was considering hosting there.</description>
		<content:encoded><![CDATA[<p>@Rob La Gesse</p>
<p>Any word on Rackspace Cloud and WordPress and what the issues were for Rackspace hosted sites?</p>
<p>Am/was considering hosting there.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: max</title>
		<link>http://blog.unmaskparasites.com/2010/06/14/attack-on-wordpress-blogs-on-rackspace/comment-page-1/#comment-7961</link>
		<dc:creator>max</dc:creator>
		<pubDate>Mon, 21 Jun 2010 07:02:42 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=637#comment-7961</guid>
		<description>@Otto

Known isn&#039;t the same as none. Just because YOU don&#039;t know doesn&#039;t mean other individuals don&#039;t know.

Two great starting points for example:

http://core.trac.wordpress.org/ticket/12416
http://core.trac.wordpress.org/ticket/11819

Wordpress is as about as bug free as an ant farm and about as secure as a safe with no doors.

Interesting that you also happen to work for Wordpress.</description>
		<content:encoded><![CDATA[<p>@Otto</p>
<p>Known isn&#8217;t the same as none. Just because YOU don&#8217;t know doesn&#8217;t mean other individuals don&#8217;t know.</p>
<p>Two great starting points for example:</p>
<p><a href="http://core.trac.wordpress.org/ticket/12416" rel="nofollow">http://core.trac.wordpress.org/ticket/12416</a><br />
<a href="http://core.trac.wordpress.org/ticket/11819" rel="nofollow">http://core.trac.wordpress.org/ticket/11819</a></p>
<p>Wordpress is as about as bug free as an ant farm and about as secure as a safe with no doors.</p>
<p>Interesting that you also happen to work for Wordpress.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rohit Bansal</title>
		<link>http://blog.unmaskparasites.com/2010/06/14/attack-on-wordpress-blogs-on-rackspace/comment-page-1/#comment-7939</link>
		<dc:creator>Rohit Bansal</dc:creator>
		<pubDate>Sun, 20 Jun 2010 04:44:35 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=637#comment-7939</guid>
		<description>Some other datacenter also infected like hodtdime (big datacenter)

wordpress bugs are here

http://core.trac.wordpress.org/query?status=accepted&amp;status=assigned&amp;status=new&amp;status=reopened&amp;status=reviewing&amp;order=priority&amp;col=id&amp;col=summary&amp;col=status&amp;col=owner&amp;col=type&amp;col=priority&amp;col=milestone&amp;type=defect+%28bug%29</description>
		<content:encoded><![CDATA[<p>Some other datacenter also infected like hodtdime (big datacenter)</p>
<p>wordpress bugs are here</p>
<p><a href="http://core.trac.wordpress.org/query?status=accepted&amp;status=assigned&amp;status=new&amp;status=reopened&amp;status=reviewing&amp;order=priority&amp;col=id&amp;col=summary&amp;col=status&amp;col=owner&amp;col=type&amp;col=priority&amp;col=milestone&amp;type=defect+%28bug%29" rel="nofollow">http://core.trac.wordpress.org/query?status=accepted&amp;status=assigned&amp;status=new&amp;status=reopened&amp;status=reviewing&amp;order=priority&amp;col=id&amp;col=summary&amp;col=status&amp;col=owner&amp;col=type&amp;col=priority&amp;col=milestone&amp;type=defect+%28bug%29</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BugSlayer</title>
		<link>http://blog.unmaskparasites.com/2010/06/14/attack-on-wordpress-blogs-on-rackspace/comment-page-1/#comment-7886</link>
		<dc:creator>BugSlayer</dc:creator>
		<pubDate>Thu, 17 Jun 2010 19:43:52 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=637#comment-7886</guid>
		<description>The proposed PhpMyAdmin attack vector seems unlikely to me, because it would be hard to have such a ubiquitous attack targeted at a single host using an XSRF vulnerability (unless maybe it was a Rackspace tech that was hit...).</description>
		<content:encoded><![CDATA[<p>The proposed PhpMyAdmin attack vector seems unlikely to me, because it would be hard to have such a ubiquitous attack targeted at a single host using an XSRF vulnerability (unless maybe it was a Rackspace tech that was hit&#8230;).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: N</title>
		<link>http://blog.unmaskparasites.com/2010/06/14/attack-on-wordpress-blogs-on-rackspace/comment-page-1/#comment-7881</link>
		<dc:creator>N</dc:creator>
		<pubDate>Thu, 17 Jun 2010 13:33:16 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=637#comment-7881</guid>
		<description>Some posts about it here... maybe we can all gather info in one place?
http://wordpress.org/support/topic/405684?replies=42</description>
		<content:encoded><![CDATA[<p>Some posts about it here&#8230; maybe we can all gather info in one place?<br />
<a href="http://wordpress.org/support/topic/405684?replies=42" rel="nofollow">http://wordpress.org/support/topic/405684?replies=42</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>

