<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Wordpress Doorway Spam Attacks</title>
	<atom:link href="http://cyberinsecure.com/wordpress-doorway-spam-attacks/feed/" rel="self" type="application/rss+xml" />
	<link>http://cyberinsecure.com/wordpress-doorway-spam-attacks/</link>
	<description>Daily cyber threats and internet security news: network security, online safety and latest security alerts</description>
	<pubDate>Fri, 12 Mar 2010 13:07:06 +0000</pubDate>
	<generator>http://wordpress.org/?v=abc</generator>
		<item>
		<title>By: CyberInsecure</title>
		<link>http://cyberinsecure.com/wordpress-doorway-spam-attacks/#comment-18</link>
		<dc:creator>CyberInsecure</dc:creator>
		<pubDate>Fri, 28 Mar 2008 15:00:50 +0000</pubDate>
		<guid isPermaLink="false">http://cyberinsecure.com/wordpress-doorway-spam-attacks/#comment-18</guid>
		<description>Here is a good analysis and explanation of whats going on:


http://websecurity.ro/blog/2008/03/28/wordpress-233-probably-a-0day-exploit/

It seems a 0-day SQL injection is involved and wordpress blogs that DO NOT use mod rewrite are vulnerable.</description>
		<content:encoded><![CDATA[<p>Here is a good analysis and explanation of whats going on:</p>
<p><a href="http://websecurity.ro/blog/2008/03/28/wordpress-233-probably-a-0day-exploit/" rel="nofollow">http://websecurity.ro/blog/2008/03/28/wordpress-233-probably-a-0day-exploit/</a></p>
<p>It seems a 0-day SQL injection is involved and wordpress blogs that DO NOT use mod rewrite are vulnerable.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: CyberInsecure</title>
		<link>http://cyberinsecure.com/wordpress-doorway-spam-attacks/#comment-17</link>
		<dc:creator>CyberInsecure</dc:creator>
		<pubDate>Thu, 27 Mar 2008 03:11:52 +0000</pubDate>
		<guid isPermaLink="false">http://cyberinsecure.com/wordpress-doorway-spam-attacks/#comment-17</guid>
		<description>First hit might (and probably was) by a bot, second might be a "custom" job.
I got some deeply google-indexed WP blogs, versions 2.2.2 and newer. No hits so far... I always change all defaults during install though.</description>
		<content:encoded><![CDATA[<p>First hit might (and probably was) by a bot, second might be a &#8220;custom&#8221; job.<br />
I got some deeply google-indexed WP blogs, versions 2.2.2 and newer. No hits so far&#8230; I always change all defaults during install though.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael VanDeMar</title>
		<link>http://cyberinsecure.com/wordpress-doorway-spam-attacks/#comment-16</link>
		<dc:creator>Michael VanDeMar</dc:creator>
		<pubDate>Thu, 27 Mar 2008 03:07:20 +0000</pubDate>
		<guid isPermaLink="false">http://cyberinsecure.com/wordpress-doorway-spam-attacks/#comment-16</guid>
		<description>There have been a few. Neither email nor server were compromised, either. It's a bot attack, not targeting my blogs specifically. Different  passwords on each blog as well.</description>
		<content:encoded><![CDATA[<p>There have been a few. Neither email nor server were compromised, either. It&#8217;s a bot attack, not targeting my blogs specifically. Different  passwords on each blog as well.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: CyberInsecure</title>
		<link>http://cyberinsecure.com/wordpress-doorway-spam-attacks/#comment-15</link>
		<dc:creator>CyberInsecure</dc:creator>
		<pubDate>Thu, 27 Mar 2008 03:01:46 +0000</pubDate>
		<guid isPermaLink="false">http://cyberinsecure.com/wordpress-doorway-spam-attacks/#comment-15</guid>
		<description>Michael VanDeMar:
There can be few explanations. You used same password or your email got compromised and someone recovered new password. Your web hosting might be compromised and so on.
I never heard any cases on WP 2.3.3 except yours.

I first saw this on a russian language forum, in a topic related to Xrumer spam software.</description>
		<content:encoded><![CDATA[<p>Michael VanDeMar:<br />
There can be few explanations. You used same password or your email got compromised and someone recovered new password. Your web hosting might be compromised and so on.<br />
I never heard any cases on WP 2.3.3 except yours.</p>
<p>I first saw this on a russian language forum, in a topic related to Xrumer spam software.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael VanDeMar</title>
		<link>http://cyberinsecure.com/wordpress-doorway-spam-attacks/#comment-14</link>
		<dc:creator>Michael VanDeMar</dc:creator>
		<pubDate>Thu, 27 Mar 2008 02:19:31 +0000</pubDate>
		<guid isPermaLink="false">http://cyberinsecure.com/wordpress-doorway-spam-attacks/#comment-14</guid>
		<description>I had this happen to a fresh install of Wordpress 2.3.3, so I don't know that upgrading will definitely fix the issue. This attack started widespread back on the 15th or 16th, I do believe:

&lt;a href="http://smackdown.blogsblogsblogs.com/2008/03/23/new-wordpress-233-exploitvulnerability-adds-spam-directory-wp-content1/" rel="nofollow"&gt;New Wordpress 2.3.3 Exploit/Vulnerability - Adds Spam Directory /wp-content/1/&lt;/a&gt;

The 2 blogs that I had hit were hit on the 18th.

Curious, where did you discover this first?</description>
		<content:encoded><![CDATA[<p>I had this happen to a fresh install of Wordpress 2.3.3, so I don&#8217;t know that upgrading will definitely fix the issue. This attack started widespread back on the 15th or 16th, I do believe:</p>
<p><a href="http://smackdown.blogsblogsblogs.com/2008/03/23/new-wordpress-233-exploitvulnerability-adds-spam-directory-wp-content1/" rel="nofollow">New Wordpress 2.3.3 Exploit/Vulnerability - Adds Spam Directory /wp-content/1/</a></p>
<p>The 2 blogs that I had hit were hit on the 18th.</p>
<p>Curious, where did you discover this first?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
