<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Google Cloaking Hack Targeting WordPress &amp; How to Fix It</title>
	<atom:link href="http://wpblogger.com/google-cloacking-wordpress-hack.php/feed" rel="self" type="application/rss+xml" />
	<link>http://wpblogger.com/google-cloacking-wordpress-hack.php</link>
	<description>All things WordPress</description>
	<lastBuildDate>Thu, 22 Mar 2012 14:27:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<item>
		<title>By: PreservationNation &#187; Blog Archive &#187; Bad news: Our Blog was Hacked</title>
		<link>http://wpblogger.com/google-cloacking-wordpress-hack.php#comment-6677</link>
		<dc:creator>PreservationNation &#187; Blog Archive &#187; Bad news: Our Blog was Hacked</dc:creator>
		<pubDate>Tue, 13 Jul 2010 13:01:18 +0000</pubDate>
		<guid isPermaLink="false">http://wpblogger.com/?p=551#comment-6677</guid>
		<description>[...] This kind of attack is called a “cloaking hack,” “pharma hack” or “injection hack.” If you are interested in more information on this, check out: http://wpblogger.com/google-cloacking-wordpress-hack.php. [...]</description>
		<content:encoded><![CDATA[<p>[...] This kind of attack is called a “cloaking hack,” “pharma hack” or “injection hack.” If you are interested in more information on this, check out: <a href="http://wpblogger.com/google-cloacking-wordpress-hack.php" rel="nofollow">http://wpblogger.com/google-cloacking-wordpress-hack.php</a>. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mimi</title>
		<link>http://wpblogger.com/google-cloacking-wordpress-hack.php#comment-6449</link>
		<dc:creator>Mimi</dc:creator>
		<pubDate>Mon, 05 Jul 2010 23:42:02 +0000</pubDate>
		<guid isPermaLink="false">http://wpblogger.com/?p=551#comment-6449</guid>
		<description>I host several WordPress sites as well a few HTML sites.  The hack seemed to happen around the time that I tried to use the WPbook plugin (June 23-26) to link a site to a Facebook Page.  Can&#039;t be completely certain of the timing but that seems to make sense to me.  The hacker got in and placed several PHP files in an old and definitely non-secure HTML site.  The PHP files all had one piece of PHP code with tons of encrypted letter in between.  They referred back to a directory called &quot;set&quot; which I found in an image file in the HTML site that had tons of HTML files that were all named with various pharma drugs and had links to other sites.  Every single WordPress site I have had been cloned and given the extension .old - seems like all of the files in the .old extension are pretty clean but the newly cloned files had a new file called wp-includes&gt;pomo&gt;set.php.  I assume it refers back to the set directory found in the HTML site.  If having these files will help someone diagnose the hacker - please let me know.  I am painstakingly going through each WP site, exporting current posts/pages and reinstalling databases and plugins.  I don&#039;t know enough about MySQL to search through tables and find offending files.  Oh and I use Dreamhost.</description>
		<content:encoded><![CDATA[<p>I host several WordPress sites as well a few HTML sites.  The hack seemed to happen around the time that I tried to use the WPbook plugin (June 23-26) to link a site to a Facebook Page.  Can&#8217;t be completely certain of the timing but that seems to make sense to me.  The hacker got in and placed several PHP files in an old and definitely non-secure HTML site.  The PHP files all had one piece of PHP code with tons of encrypted letter in between.  They referred back to a directory called &#8220;set&#8221; which I found in an image file in the HTML site that had tons of HTML files that were all named with various pharma drugs and had links to other sites.  Every single WordPress site I have had been cloned and given the extension .old &#8211; seems like all of the files in the .old extension are pretty clean but the newly cloned files had a new file called wp-includes&gt;pomo&gt;set.php.  I assume it refers back to the set directory found in the HTML site.  If having these files will help someone diagnose the hacker &#8211; please let me know.  I am painstakingly going through each WP site, exporting current posts/pages and reinstalling databases and plugins.  I don&#8217;t know enough about MySQL to search through tables and find offending files.  Oh and I use Dreamhost.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ben Wilcox</title>
		<link>http://wpblogger.com/google-cloacking-wordpress-hack.php#comment-4857</link>
		<dc:creator>Ben Wilcox</dc:creator>
		<pubDate>Fri, 14 May 2010 02:28:31 +0000</pubDate>
		<guid isPermaLink="false">http://wpblogger.com/?p=551#comment-4857</guid>
		<description>Got hacked today, the default login account name was changed back to admin and from the logs it shows that the hacker was over in china.   I saw the access in the raw http logs and they went directly to the admin site.      They logged right in so there must be a script in the background that has hit the shared hosting box.    Wordpress 2.9.2</description>
		<content:encoded><![CDATA[<p>Got hacked today, the default login account name was changed back to admin and from the logs it shows that the hacker was over in china.   I saw the access in the raw http logs and they went directly to the admin site.      They logged right in so there must be a script in the background that has hit the shared hosting box.    WordPress 2.9.2</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: whyme</title>
		<link>http://wpblogger.com/google-cloacking-wordpress-hack.php#comment-4729</link>
		<dc:creator>whyme</dc:creator>
		<pubDate>Sun, 09 May 2010 02:03:52 +0000</pubDate>
		<guid isPermaLink="false">http://wpblogger.com/?p=551#comment-4729</guid>
		<description>my site is down, i got hacked 

i use wordpress with go daddy and i had an updated version of wordpress when it came out. but i still got hacked. 

my dashboard is messed up..... and a website link shows up on the bottom of the left screen and disappears.  

can someone stop whoever is doing this.  wt................</description>
		<content:encoded><![CDATA[<p>my site is down, i got hacked </p>
<p>i use wordpress with go daddy and i had an updated version of wordpress when it came out. but i still got hacked. </p>
<p>my dashboard is messed up&#8230;.. and a website link shows up on the bottom of the left screen and disappears.  </p>
<p>can someone stop whoever is doing this.  wt&#8230;&#8230;&#8230;&#8230;&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://wpblogger.com/google-cloacking-wordpress-hack.php#comment-4629</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Wed, 05 May 2010 09:28:39 +0000</pubDate>
		<guid isPermaLink="false">http://wpblogger.com/?p=551#comment-4629</guid>
		<description>Anyone checked the .htaccess file?</description>
		<content:encoded><![CDATA[<p>Anyone checked the .htaccess file?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ben Cook</title>
		<link>http://wpblogger.com/google-cloacking-wordpress-hack.php#comment-4512</link>
		<dc:creator>Ben Cook</dc:creator>
		<pubDate>Sun, 02 May 2010 03:43:41 +0000</pubDate>
		<guid isPermaLink="false">http://wpblogger.com/?p=551#comment-4512</guid>
		<description>Eric, I don&#039;t think the hack you&#039;re discussing is quite the same one as we&#039;ve been seeing discussing here. The hack this post was about is only visible when viewing your site in Google&#039;s search results and (from what I&#039;ve been told) hid the code in plugin folders, not injecting things into the bottom of your pages. Are you sure we&#039;re talking about the same hack?</description>
		<content:encoded><![CDATA[<p>Eric, I don&#8217;t think the hack you&#8217;re discussing is quite the same one as we&#8217;ve been seeing discussing here. The hack this post was about is only visible when viewing your site in Google&#8217;s search results and (from what I&#8217;ve been told) hid the code in plugin folders, not injecting things into the bottom of your pages. Are you sure we&#8217;re talking about the same hack?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eric Hamilton</title>
		<link>http://wpblogger.com/google-cloacking-wordpress-hack.php#comment-4511</link>
		<dc:creator>Eric Hamilton</dc:creator>
		<pubDate>Sun, 02 May 2010 02:13:19 +0000</pubDate>
		<guid isPermaLink="false">http://wpblogger.com/?p=551#comment-4511</guid>
		<description>One more clue - a simple upload of WordPress 2.9.2 over-writing the files fixes the problems and removes the javascript from the bottom of the files. I haven&#039;t searched the database files very thoroughly yet, though. It&#039;s likely there are backdoors still hidden. I&#039;m looking forward to a more permanent fix!</description>
		<content:encoded><![CDATA[<p>One more clue &#8211; a simple upload of WordPress 2.9.2 over-writing the files fixes the problems and removes the javascript from the bottom of the files. I haven&#8217;t searched the database files very thoroughly yet, though. It&#8217;s likely there are backdoors still hidden. I&#8217;m looking forward to a more permanent fix!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eric Hamilton</title>
		<link>http://wpblogger.com/google-cloacking-wordpress-hack.php#comment-4510</link>
		<dc:creator>Eric Hamilton</dc:creator>
		<pubDate>Sun, 02 May 2010 02:06:26 +0000</pubDate>
		<guid isPermaLink="false">http://wpblogger.com/?p=551#comment-4510</guid>
		<description>I have many WordPress 2.9.2 installs (currently latest and greatest) on Lunarpages shared hosting. Several of my sites got hit. Because several of them were hit (including one in development that should not even appear in Google search results), I believe that the exploit is gaining access to the filesystem (perhaps through php / wordpress vulnerability, perhaps not) and searching for other blogs to target.

Some of the sites were broken. Those ones spit out this error:

Parse error: syntax error, unexpected &#039;&lt;&#039; in /home/train22/public_html/blog/wp-includes/default-filters.php  on line 230

The ones, I believe, that were NOT running WP-Supercache plugins broke. The ones that were running it had obfuscated javascript code appended below the final /html tag at the bottom of the page. I was unable to find the source of the injection in the template files.

One of the broken target sites was running only one plugin - exclude pages. However, I believe it to be highly unlikely that it was the attack vector. I think one of the other sites was exploited, and they used a filesystem search to locate and attack the other installs.</description>
		<content:encoded><![CDATA[<p>I have many WordPress 2.9.2 installs (currently latest and greatest) on Lunarpages shared hosting. Several of my sites got hit. Because several of them were hit (including one in development that should not even appear in Google search results), I believe that the exploit is gaining access to the filesystem (perhaps through php / wordpress vulnerability, perhaps not) and searching for other blogs to target.</p>
<p>Some of the sites were broken. Those ones spit out this error:</p>
<p>Parse error: syntax error, unexpected &#8216;&lt;&#039; in /home/train22/public_html/blog/wp-includes/default-filters.php  on line 230</p>
<p>The ones, I believe, that were NOT running WP-Supercache plugins broke. The ones that were running it had obfuscated javascript code appended below the final /html tag at the bottom of the page. I was unable to find the source of the injection in the template files.</p>
<p>One of the broken target sites was running only one plugin &#8211; exclude pages. However, I believe it to be highly unlikely that it was the attack vector. I think one of the other sites was exploited, and they used a filesystem search to locate and attack the other installs.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike</title>
		<link>http://wpblogger.com/google-cloacking-wordpress-hack.php#comment-4378</link>
		<dc:creator>Mike</dc:creator>
		<pubDate>Wed, 28 Apr 2010 05:48:20 +0000</pubDate>
		<guid isPermaLink="false">http://wpblogger.com/?p=551#comment-4378</guid>
		<description>Thanks for the clues, but none have removed the hack on my site, placed on behalf of a Turkish dating site. 

I&#039;m at MediaTemple with latest, greatest WordPress. App WP suggests is to scrub, backup and and reinstall everything (until this mystery hack strikes again. Nice work, WP!) Deliver me from cut, paste and post solutions.

I&#039;m getting the same MySQL syntax error as Yohan Perera, above. Can anyone help?</description>
		<content:encoded><![CDATA[<p>Thanks for the clues, but none have removed the hack on my site, placed on behalf of a Turkish dating site. </p>
<p>I&#8217;m at MediaTemple with latest, greatest WordPress. App WP suggests is to scrub, backup and and reinstall everything (until this mystery hack strikes again. Nice work, WP!) Deliver me from cut, paste and post solutions.</p>
<p>I&#8217;m getting the same MySQL syntax error as Yohan Perera, above. Can anyone help?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: How to Fix Your Hacked WordPress Blog</title>
		<link>http://wpblogger.com/google-cloacking-wordpress-hack.php#comment-4151</link>
		<dc:creator>How to Fix Your Hacked WordPress Blog</dc:creator>
		<pubDate>Wed, 21 Apr 2010 03:09:10 +0000</pubDate>
		<guid isPermaLink="false">http://wpblogger.com/?p=551#comment-4151</guid>
		<description>[...] drug addiction. Your once mild-mannered blog is a now a nasty Hollywood tart, reeling around, blowing toxic breath in random stranger’s faces, accosting people in the street and making depraved sexual suggestions, showing up at high-society [...]</description>
		<content:encoded><![CDATA[<p>[...] drug addiction. Your once mild-mannered blog is a now a nasty Hollywood tart, reeling around, blowing toxic breath in random stranger’s faces, accosting people in the street and making depraved sexual suggestions, showing up at high-society [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

