<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Blog error</title>
	<atom:link href="http://adrianspender.com/blog/2007/11/30/blog-error/feed/" rel="self" type="application/rss+xml" />
	<link>http://adrianspender.com/blog/2007/11/30/blog-error/</link>
	<description>Cycling, software and random other thoughts</description>
	<lastBuildDate>Fri, 13 Jan 2012 10:17:02 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Andy Piper</title>
		<link>http://adrianspender.com/blog/2007/11/30/blog-error/comment-page-1/#comment-14341</link>
		<dc:creator>Andy Piper</dc:creator>
		<pubDate>Thu, 13 Dec 2007 04:31:34 +0000</pubDate>
		<guid isPermaLink="false">http://adrianspender.com/blog/2007/11/30/blog-error/#comment-14341</guid>
		<description>Eek. Well I assume that WP.com blogs are not vulnerable to whatever backdoor these folks found.</description>
		<content:encoded><![CDATA[<p>Eek. Well I assume that WP.com blogs are not vulnerable to whatever backdoor these folks found.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adrian Spender</title>
		<link>http://adrianspender.com/blog/2007/11/30/blog-error/comment-page-1/#comment-12631</link>
		<dc:creator>Adrian Spender</dc:creator>
		<pubDate>Sat, 01 Dec 2007 17:15:39 +0000</pubDate>
		<guid isPermaLink="false">http://adrianspender.com/blog/2007/11/30/blog-error/#comment-12631</guid>
		<description>Edited to add. This happened well after I recently upgraded to Wordpress 2.3.1 as well!</description>
		<content:encoded><![CDATA[<p>Edited to add. This happened well after I recently upgraded to WordPress 2.3.1 as well!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adrian Spender</title>
		<link>http://adrianspender.com/blog/2007/11/30/blog-error/comment-page-1/#comment-12630</link>
		<dc:creator>Adrian Spender</dc:creator>
		<pubDate>Sat, 01 Dec 2007 17:14:27 +0000</pubDate>
		<guid isPermaLink="false">http://adrianspender.com/blog/2007/11/30/blog-error/#comment-12630</guid>
		<description>Unfortunately it looks like you are right. class-mail.php isn&#039;t part of Wordpress and seems to have been inserted into my wp-includes directory somehow, probably by the method you highlight. How somebody got the backdoor in in the first place is unknown. There is nothing to suggest that they gained access to the filesystem on my host (and no it isn&#039;t world-writable either) 

The contents of class-mail.php contained the assignment of two variables to the contents of a couple of Base 64 encode strings. One contained a load of binary data and some links to an innocuous looking web site blog at digitalsweeties.com The second decoded into a Javascript function to display an ad from googlesyndication.com

Looks like it has &lt;a HREF=&quot;http://www.howardowens.com/2007/this-blog-was-hacked/&quot; rel=&quot;nofollow&quot;&gt;happened to others&lt;/a&gt; as well, and is probably an exploit of a Wordpress vulnerability</description>
		<content:encoded><![CDATA[<p>Unfortunately it looks like you are right. class-mail.php isn&#8217;t part of WordPress and seems to have been inserted into my wp-includes directory somehow, probably by the method you highlight. How somebody got the backdoor in in the first place is unknown. There is nothing to suggest that they gained access to the filesystem on my host (and no it isn&#8217;t world-writable either) </p>
<p>The contents of class-mail.php contained the assignment of two variables to the contents of a couple of Base 64 encode strings. One contained a load of binary data and some links to an innocuous looking web site blog at digitalsweeties.com The second decoded into a Javascript function to display an ad from googlesyndication.com</p>
<p>Looks like it has <a HREF="http://www.howardowens.com/2007/this-blog-was-hacked/" rel="nofollow">happened to others</a> as well, and is probably an exploit of a WordPress vulnerability</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anton Piatek</title>
		<link>http://adrianspender.com/blog/2007/11/30/blog-error/comment-page-1/#comment-12618</link>
		<dc:creator>Anton Piatek</dc:creator>
		<pubDate>Sat, 01 Dec 2007 16:23:23 +0000</pubDate>
		<guid isPermaLink="false">http://adrianspender.com/blog/2007/11/30/blog-error/#comment-12618</guid>
		<description>Looks to me like your blog got hacked and that is the code for a backdoor...
The first line looks like it allows someone to load a file into your blog via a http post, which means they can do whatever they want.

I would change passwords on the blog and start checking for other security problems - That code is not benign!</description>
		<content:encoded><![CDATA[<p>Looks to me like your blog got hacked and that is the code for a backdoor&#8230;<br />
The first line looks like it allows someone to load a file into your blog via a http post, which means they can do whatever they want.</p>
<p>I would change passwords on the blog and start checking for other security problems &#8211; That code is not benign!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

