<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: The Aftermath of a Wordpress Spam Injection (and a Tool to Prevent it)</title>
	<atom:link href="http://jungleg.com/2009/04/20/the-aftermath-of-a-wordpress-spam-injection-and-a-tool-to-prevent-it/feed/" rel="self" type="application/rss+xml" />
	<link>http://jungleg.com/2009/04/20/the-aftermath-of-a-wordpress-spam-injection-and-a-tool-to-prevent-it/</link>
	<description>Empowering businesses to leverage the new web economy</description>
	<lastBuildDate>Thu, 04 Mar 2010 22:28:37 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Spam&#8230;..Its True &#8211; I have been hacked!!!!! &#187; Gremlin&#8217;s Fireside Chat</title>
		<link>http://jungleg.com/2009/04/20/the-aftermath-of-a-wordpress-spam-injection-and-a-tool-to-prevent-it/comment-page-1/#comment-3281</link>
		<dc:creator>Spam&#8230;..Its True &#8211; I have been hacked!!!!! &#187; Gremlin&#8217;s Fireside Chat</dc:creator>
		<pubDate>Thu, 15 Oct 2009 20:23:02 +0000</pubDate>
		<guid isPermaLink="false">http://jungleg.com/?p=618#comment-3281</guid>
		<description>[...] now (I hope) in accordance with these guidelines. A  good site that helped me with this issue are JungleG and the usual Wordpress support &#8211; thanks guys.    &#160;   &#171; Michael Jackson and Farrah [...]</description>
		<content:encoded><![CDATA[<p>[...] now (I hope) in accordance with these guidelines. A  good site that helped me with this issue are JungleG and the usual Wordpress support &#8211; thanks guys.    &nbsp;   &laquo; Michael Jackson and Farrah [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Denton Gentry</title>
		<link>http://jungleg.com/2009/04/20/the-aftermath-of-a-wordpress-spam-injection-and-a-tool-to-prevent-it/comment-page-1/#comment-2527</link>
		<dc:creator>Denton Gentry</dc:creator>
		<pubDate>Sat, 12 Sep 2009 13:39:04 +0000</pubDate>
		<guid isPermaLink="false">http://jungleg.com/?p=618#comment-2527</guid>
		<description>&gt; curl --no-sessionid --user-agent &quot;Googlebot/2.1 ...

Might the next escalation in the spambot war be for them to start checking not only the user-agent, but also that the IP address resolves back to the google.com domain?</description>
		<content:encoded><![CDATA[<p>&gt; curl &#8211;no-sessionid &#8211;user-agent &#8220;Googlebot/2.1 &#8230;</p>
<p>Might the next escalation in the spambot war be for them to start checking not only the user-agent, but also that the IP address resolves back to the google.com domain?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Denton Gentry</title>
		<link>http://jungleg.com/2009/04/20/the-aftermath-of-a-wordpress-spam-injection-and-a-tool-to-prevent-it/comment-page-1/#comment-2526</link>
		<dc:creator>Denton Gentry</dc:creator>
		<pubDate>Sat, 12 Sep 2009 12:54:06 +0000</pubDate>
		<guid isPermaLink="false">http://jungleg.com/?p=618#comment-2526</guid>
		<description>&gt; “you’ll see the same ads in this post as well, as Google thinks this post is about that”

FYI regarding the health ads on this page, you can use HTML comments to provide hints to Google’s Ad crawler of which portions of the page should be emphasized or de-emphasized. To suppress the health-related keywords, you’d surround the paragraphs with those keywords with the following:

&lt;!– google_ad_section_start(weight=ignore) –&gt;
…
&lt;!– google_ad_section_end –&gt;

Google’s description of the technique is here:
https://www.google.com/adsense/support/bin/answer.py?hl=en&amp;answer=23168</description>
		<content:encoded><![CDATA[<p>&gt; “you’ll see the same ads in this post as well, as Google thinks this post is about that”</p>
<p>FYI regarding the health ads on this page, you can use HTML comments to provide hints to Google’s Ad crawler of which portions of the page should be emphasized or de-emphasized. To suppress the health-related keywords, you’d surround the paragraphs with those keywords with the following:</p>
<p>&lt;!– google_ad_section_start(weight=ignore) –&gt;<br />
…<br />
&lt;!– google_ad_section_end –&gt;</p>
<p>Google’s description of the technique is here:<br />
<a href="https://www.google.com/adsense/support/bin/answer.py?hl=en&amp;answer=23168" rel="nofollow">https://www.google.com/adsense/support/bin/answer.py?hl=en&amp;answer=23168</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adam Pieniazek</title>
		<link>http://jungleg.com/2009/04/20/the-aftermath-of-a-wordpress-spam-injection-and-a-tool-to-prevent-it/comment-page-1/#comment-2519</link>
		<dc:creator>Adam Pieniazek</dc:creator>
		<pubDate>Thu, 10 Sep 2009 15:24:31 +0000</pubDate>
		<guid isPermaLink="false">http://jungleg.com/?p=618#comment-2519</guid>
		<description>Another good idea is to setup Google alerts for spammy keywords for your domain. Hopefully you can catch it before it starts setting off Google alerts, but if not it&#039;s a nice, free fail safe.</description>
		<content:encoded><![CDATA[<p>Another good idea is to setup Google alerts for spammy keywords for your domain. Hopefully you can catch it before it starts setting off Google alerts, but if not it&#8217;s a nice, free fail safe.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dave Newman</title>
		<link>http://jungleg.com/2009/04/20/the-aftermath-of-a-wordpress-spam-injection-and-a-tool-to-prevent-it/comment-page-1/#comment-2151</link>
		<dc:creator>Dave Newman</dc:creator>
		<pubDate>Thu, 23 Jul 2009 15:27:48 +0000</pubDate>
		<guid isPermaLink="false">http://jungleg.com/?p=618#comment-2151</guid>
		<description>I just found this same sort of thing on my Wordpress install - version 2.8.2. There was a file in the wp-includes directory called feed-atom2.php and included the Base64_decode for a remote user. I&#039;ve saved the file if you&#039;d like to have it :)

I couldn&#039;t have found the problem without your post. Thank you.</description>
		<content:encoded><![CDATA[<p>I just found this same sort of thing on my Wordpress install &#8211; version 2.8.2. There was a file in the wp-includes directory called feed-atom2.php and included the Base64_decode for a remote user. I&#8217;ve saved the file if you&#8217;d like to have it :)</p>
<p>I couldn&#8217;t have found the problem without your post. Thank you.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mssmotorrd</title>
		<link>http://jungleg.com/2009/04/20/the-aftermath-of-a-wordpress-spam-injection-and-a-tool-to-prevent-it/comment-page-1/#comment-1457</link>
		<dc:creator>mssmotorrd</dc:creator>
		<pubDate>Sun, 03 May 2009 12:52:10 +0000</pubDate>
		<guid isPermaLink="false">http://jungleg.com/?p=618#comment-1457</guid>
		<description>It’s the first time I commented here and I must say you share us genuine, and quality information for bloggers! Good job. 
p.s. You have a very good template for your blog. Where did you find it?</description>
		<content:encoded><![CDATA[<p>It’s the first time I commented here and I must say you share us genuine, and quality information for bloggers! Good job.<br />
p.s. You have a very good template for your blog. Where did you find it?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joel Escobar</title>
		<link>http://jungleg.com/2009/04/20/the-aftermath-of-a-wordpress-spam-injection-and-a-tool-to-prevent-it/comment-page-1/#comment-1440</link>
		<dc:creator>Joel Escobar</dc:creator>
		<pubDate>Tue, 21 Apr 2009 03:51:21 +0000</pubDate>
		<guid isPermaLink="false">http://jungleg.com/?p=618#comment-1440</guid>
		<description>Very cool tool. My only problem is the name. I would have spelled it with an &quot;er&quot;. 

I don&#039;t run a blog, but I had a similar situation recently. In the last month or so, my installation of roundcube was compromised. The attacker able to execute code that replaced my index page with a redirect to a phishing bank site. It had been that way for like 10 days before I noticed. This installation is shared by all my clients, but no one complained so I assume that no one had tried using webmail in that time. My wife brought it to my attention when she was trying to use roundcube from her computer and complained that it kept sending her to a weird site. I thought for sure she was infected with some sort of malware. Then I tried from my machine and had the same problem so I knew it wasn&#039;t her computer. I went into panic mode thinking my server was hacked. After some investigation, it turned out my webmail vhost was the only one affected. So I deleted everything and installed the latest version from scratch. The new version is supposed to include some security updates that may or may not have been related to how my installation was compromised.</description>
		<content:encoded><![CDATA[<p>Very cool tool. My only problem is the name. I would have spelled it with an &#8220;er&#8221;. </p>
<p>I don&#8217;t run a blog, but I had a similar situation recently. In the last month or so, my installation of roundcube was compromised. The attacker able to execute code that replaced my index page with a redirect to a phishing bank site. It had been that way for like 10 days before I noticed. This installation is shared by all my clients, but no one complained so I assume that no one had tried using webmail in that time. My wife brought it to my attention when she was trying to use roundcube from her computer and complained that it kept sending her to a weird site. I thought for sure she was infected with some sort of malware. Then I tried from my machine and had the same problem so I knew it wasn&#8217;t her computer. I went into panic mode thinking my server was hacked. After some investigation, it turned out my webmail vhost was the only one affected. So I deleted everything and installed the latest version from scratch. The new version is supposed to include some security updates that may or may not have been related to how my installation was compromised.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
