Gmail Calendar Documents Reader Web more »
Recently Visited Groups | Help | Sign in
Google Groups Home
Discussions > Something Is Broken > my feed showing up as spam all of a sudden
There are currently too many topics in this group that display first. To make this topic appear first, remove this option from another topic.
There was an error processing your request. Please try again.
flag
  Messages 1 - 25 of 33 - Collapse all  -  Translate all to Translated (View all originals)   Newer >
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
 
From:
To:
Cc:
Followup To:
Add Cc | Add Followup-to | Edit Subject
Subject:
Validation:
For verification purposes please type the characters you see in the picture below or the numbers you hear by clicking the accessibility icon. Listen and type the numbers you hear
 
jennifermfrederick@gmail. com  
View profile  
 More options Jun 17, 11:08 pm
From: "[email address]"
Date: Wed, 17 Jun 2009 20:08:30 -0700 (PDT)
Local: Wed, Jun 17 2009 11:08 pm
Subject: my feed showing up as spam all of a sudden
One of my readers alerted me that my latest blog post appears in
googlereader as spam, but when you click to go to my website, the post
is just fine on the website.

Here is what the text appears as in googlereader:
Buying Synthroid Proventil Price Natural Motilium Starlix Pill Order
Myambutol Purchase Rituxan Accutane Pill Natural Indocin Zyprexa Pill
Buy Zyrtec Online Order Noroxin Purchase Ventolin Pamelor For Sale
Natural Cytoxan Mentax For Sale Natural Emsam Requip Without
Prescription Generic Paxil Buy Vytorin Online Purchase Penisole
Purchase Ophthacare Natural Wellbutrin Sr Fludarabine Without
Prescription Azulfidine Without Prescription Protonix Pill Purchase
Gyne-lotrimin Topamax Without Prescription Purchase Motilium Evecare
For Sale Buy Yerba Diet Online Viramune Price Order Azulfidine Generic
Vermox Zerit Without Prescription Generic Flonase Natural Epivir-hbv
Diet Maxx Price Purchase Mevacor Buying Cialis Soft Generic [...]

Also, in the last ten or so posts, the body text has dissapeared, and
just the title appears, but when you click to go to my website,
everything is fine.

My blog address is: www.lovelettertypewriter.com.

Can anyone help me?


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Manshu  
View profile  
 More options Jun 18, 11:39 am
From: Manshu
Date: Thu, 18 Jun 2009 08:39:11 -0700 (PDT)
Local: Thurs, Jun 18 2009 11:39 am
Subject: Re: my feed showing up as spam all of a sudden
I faced the same problem today. I see that this problem only appears
for old users. If you subscribe to this feed today, the new feed will
appear fine.

I don't know how to fix the problem, one work around would be for old
users to unsubcribe and then subscribe to the feed again.

On Jun 17, 11:08 pm, "[email address]" wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
AllanSun  
View profile  
 More options Jun 19, 4:36 am
From: AllanSun
Date: Fri, 19 Jun 2009 01:36:53 -0700 (PDT)
Local: Fri, Jun 19 2009 4:36 am
Subject: Re: my feed showing up as spam all of a sudden
My friend is experiencing the same problem. In the last two days, new
post contents have been changed to:

Free Order Shipping SomaBuy Cod SomaArchive Blog Buy Inurl SomaBuy
Watson SomaBuy Cod Day Next SomaBuy Discount SomaBuy Cod Online
Soma1234.blogspot.com Buy SomaBuy Soma ValiumBuy Card Master Soma
UsingBuy Soma DanBuy F.blogspot.com SomaBuy Watson Brand SomaBuy Soma
Cash On DeliveryBuy Soma 1Buy Soma WhereBuy Soma WallaceBuy Generic
SomaOrder Soma OnlineCheap Soma Order OnlineOrder Soma CodOrder [...]

Her feed address is http://blog.donglu.org/feed.

Any ideas what's going on?

On Jun 18, 11:39 pm, Manshu wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
DanOestreich  
View profile  
 More options Jun 19, 10:05 am
From: DanOestreich
Date: Fri, 19 Jun 2009 07:05:20 -0700 (PDT)
Local: Fri, Jun 19 2009 10:05 am
Subject: Re: my feed showing up as spam all of a sudden
I am facing exactly the same problem as jennifer, including the loss
of body text -- which goes back to April '09.  I am getting the
following spam on my new posts:

Three Sisters Pharmacy Valium Rehab List Painkillers Benzodiazepines
Buy Viagra Alternative Phentermine Lortab Online Can I Get A Buzz From
Ultram Does The Faa Test For Xanax Order Hydrocodone Online Getting
High On Valium Search Phentermine Adipex Cheap Diflucan Buy No
Phentermine Script Purchase Soma Xanax Deaths Viagra Clones Cheap
Fastin Ultram Withdrawls Order Cheap Viagra Buy Diazepam Inexpensive
Tenuate Online Pharmacies Discount Lexapro Valium Abuse And Effects
Buy Bontril Online Pharmacy Tenuate Buy Dospan Line Tenuate Medical
Uses Of Valium Buy [...]

I was notified of the problem yesterday by a reader.

My blog address is: http://www.unfoldingleadership.com/blog

Obviously, there's something amiss. The spam is not showing up in
Bloglines.

On Jun 17, 8:08 pm, "[email address]" wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Nick120  
View profile  
 More options Jun 19, 11:30 am
From: Nick120
Date: Fri, 19 Jun 2009 08:30:51 -0700 (PDT)
Local: Fri, Jun 19 2009 11:30 am
Subject: Re: my feed showing up as spam all of a sudden
When looking at the Google Cache for your latest post "My Apologies
for Spam in Google Reader (Click this Title)", there is a <div
id="_wp_footer"> that contains the same spam that appears in Google
Reader. The spam isn't there when visiting your website directly.

Have you made any recent changes to your blog? If not, maybe this is a
clever PHP script injection that adds spam only to requests from
Google?

- Nick

On Jun 19, 10:05 pm, DanOestreich wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
DanOestreich  
View profile  
 More options Jun 19, 11:42 am
From: DanOestreich
Date: Fri, 19 Jun 2009 08:42:43 -0700 (PDT)
Local: Fri, Jun 19 2009 11:42 am
Subject: Re: my feed showing up as spam all of a sudden
Hmm. Thanks, Nick.

The only change I've made to my blog is upgrading from Wordpress 2.7.1
to 2.8. Do you think that could be involved?  Otherwise, no changes.

On Jun 19, 8:30 am, Nick120 wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Nick120  
View profile  
 More options Jun 19, 1:52 pm
From: Nick120
Date: Fri, 19 Jun 2009 10:52:35 -0700 (PDT)
Local: Fri, Jun 19 2009 1:52 pm
Subject: Re: my feed showing up as spam all of a sudden
Hi Dan,

There is a program called "curl" that you can use to help you diagnose
this problem: http://en.wikipedia.org/wiki/CURL

Here's a command line example for getting an html file that should
look the same as what Google is getting:

 curl --no-sessionid --user-agent "Googlebot/2.1 (+http://
www.googlebot.com/bot.html)" http://www.unfoldingleadership.com/blog

I had a similar problem and traced it to a hacked database entry
called "active_plugins" in the "wp_options" table. Look for any
additional "plugins" aside from the ones that you have enabled in your
general Wordpress admin area. I found a reference to an additional
file in an images subdirectory. It contained PHP code was getting
called and injecting a whole bunch of links into anything read by
Google.

Hope this helps; Good Luck!

- Nick

On Jun 19, 11:42 pm, DanOestreich wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
DanOestreich  
View profile  
 More options Jun 19, 2:05 pm
From: DanOestreich
Date: Fri, 19 Jun 2009 11:05:40 -0700 (PDT)
Local: Fri, Jun 19 2009 2:05 pm
Subject: Re: my feed showing up as spam all of a sudden
Nick

Thanks so much!  I'll give it a try.

Many best wishes to you

Dan

On Jun 19, 10:52 am, Nick120 wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
bitzer  
View profile  
 More options Jun 20, 12:16 am
From: bitzer
Date: Fri, 19 Jun 2009 21:16:40 -0700 (PDT)
Local: Sat, Jun 20 2009 12:16 am
Subject: Re: my feed showing up as spam all of a sudden
I've discovered the same problem using curl.  I haven't been able to
track down the source, though.

On Jun 19, 11:05 am, DanOestreich wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
bitzer  
View profile  
 More options Jun 20, 2:09 am
From: bitzer
Date: Fri, 19 Jun 2009 23:09:19 -0700 (PDT)
Local: Sat, Jun 20 2009 2:09 am
Subject: Re: my feed showing up as spam all of a sudden
Hrm.  I renamed my wp-content/plugins dir to plugins.old and once it
was recreated by refreshing the plugins admin page in the Dashboard,
the spam was no longer there after a Google Reader refresh.
Annoyingly, though, I've moved all the plugins back, one by one, and
can't get it to happen again.

On Jun 19, 9:16 pm, bitzer wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
jennifermfrederick@gmail. com  
View profile  
 More options Jun 20, 9:27 am
From: "[email address]"
Date: Sat, 20 Jun 2009 06:27:17 -0700 (PDT)
Local: Sat, Jun 20 2009 9:27 am
Subject: Re: my feed showing up as spam all of a sudden
Thanks for the help everyone!

Nick - I have not changed anything about my blog recently.  Thanks for
the curl tip - I will check that out.

Please continue to post here, everyone, if you figure anything else
out. I am a bit relieved that it is not just me having this issue -
hopefully we can get it resloved faster that way.


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Adrianne  
View profile  
 More options Jun 20, 11:20 am
From: Adrianne
Date: Sat, 20 Jun 2009 08:20:36 -0700 (PDT)
Local: Sat, Jun 20 2009 11:20 am
Subject: Re: my feed showing up as spam all of a sudden
Same problem here. I also recently upgraded to 2.8, using the auto-
update (which I've now read can be problematic). My feed only looks
spammy in Google Reader.

I've been looking through my directories but haven't seen anything
suspicious, and nothing new with the plugins: although I did briefly
have an error on my plugins page claiming it was missing a cache file,
that has gone away today.

On Jun 20, 9:27 am, "[email address]" wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
DanOestreich  
View profile  
 More options Jun 20, 3:37 pm
From: DanOestreich
Date: Sat, 20 Jun 2009 12:37:17 -0700 (PDT)
Local: Sat, Jun 20 2009 3:37 pm
Subject: Re: my feed showing up as spam all of a sudden
My host support team at oxxus.net reports it has found some but not
all of the hacker's code. I've asked them for more information and
will pass it along as I learn more. Thanks everybody.

On Jun 20, 8:20 am, Adrianne wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
KrisV  
View profile  
 More options Jun 20, 10:29 pm
From: KrisV
Date: Sat, 20 Jun 2009 19:29:18 -0700 (PDT)
Local: Sat, Jun 20 2009 10:29 pm
Subject: Re: my feed showing up as spam all of a sudden
I am having the same issue at http://www.theworldaroundyou.com

    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
ChrisZ  
View profile  
 More options Jun 22, 3:06 pm
From: ChrisZ
Date: Mon, 22 Jun 2009 12:06:13 -0700 (PDT)
Local: Mon, Jun 22 2009 3:06 pm
Subject: Re: my feed showing up as spam all of a sudden
I found two files in ironically the akismet plugin directory that look
to be the cause of the problem. .akismet.cache.php
and .akismet.cache_01072008.php. Haven't been able to figure out yet
though how they got there. Unfortunately my access logs do not go back
far enough to see what might have caused the infection.

    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
DanOestreich  
View profile  
 More options Jun 23, 12:02 pm
From: DanOestreich
Date: Tue, 23 Jun 2009 09:02:11 -0700 (PDT)
Local: Tues, Jun 23 2009 12:02 pm
Subject: Re: my feed showing up as spam all of a sudden
Chris

Where are those files exactly? How could I locate them or view them?
I do not see them in my askimet plugin directory.

This is interesting because just before I posted -- and learned that
Google Reader was showing spam -- I noticed that there were six large
spam comments that Askimet had caught. I deleted them all as spam. My
recollection is that they followed exactly the same format we now see
on the spam posts -- line after line after line of websites being
listed.

On Jun 22, 12:06 pm, ChrisZ wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
KrisV  
View profile  
 More options Jun 23, 2:02 pm
From: KrisV
Date: Tue, 23 Jun 2009 11:02:10 -0700 (PDT)
Local: Tues, Jun 23 2009 2:02 pm
Subject: Re: my feed showing up as spam all of a sudden
I have not been able to find anything off either...no suspicious files
that I can find...can't figure out what is creating the issue.

On Jun 23, 12:02 pm, DanOestreich wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Google Reader Guide Google employee  
View profile  
 More options Jun 23, 2:44 pm
From: Google Reader Guide
Date: Tue, 23 Jun 2009 11:44:55 -0700 (PDT)
Local: Tues, Jun 23 2009 2:44 pm
Subject: Re: my feed showing up as spam all of a sudden
Hi everyone,

Thanks for reporting this problem. Unfortunately, we've seen similar
problems with WordPress feeds being compromised in the past:

http://groups.google.com/group/google-reader-troubleshoot/browse_thre...

We'll look into it further, but in the meantime, I encourage you all
to alert WordPress to this issue via their support forums.

Roger


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
ChrisZ  
View profile  
 More options Jun 24, 3:48 pm
From: ChrisZ
Date: Wed, 24 Jun 2009 12:48:23 -0700 (PDT)
Local: Wed, Jun 24 2009 3:48 pm
Subject: Re: my feed showing up as spam all of a sudden
Check for files owned by nobody if your using mod_php and make sure
your showing hidden dot files (eg .file) when you ls. (using ls -al )

I found them in the akiskmet plugin directory but perhaps they can be
in other plugin directories as well.


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Jim Goldstein  
View profile  
 More options Jun 25, 1:02 am
From: Jim Goldstein
Date: Wed, 24 Jun 2009 22:02:43 -0700 (PDT)
Local: Thurs, Jun 25 2009 1:02 am
Subject: Re: my feed showing up as spam all of a sudden
I'm in the same boat. I've been seeing spam links in my RSS feed only
on Google Reader both on Mac and PC computers.  Site: http://www.jmg-galleries.com/blog/

and here is a screenshot of the links in the feed:
 http://www.jmg-galleries.com/temp/spam_links.png

I've upgraded from WP 2.7.1 to WP 2.8 and still have the issue in old
posts. I'm waiting to see if the problem persists in new posts.


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Jim Goldstein  
View profile  
 More options Jun 25, 2:10 am
From: Jim Goldstein
Date: Wed, 24 Jun 2009 23:10:46 -0700 (PDT)
Local: Thurs, Jun 25 2009 2:10 am
Subject: Re: my feed showing up as spam all of a sudden
After scouring my blog root directory I think I may have found the
culprit.

A file named "wp-xmlrpc.php" had the following code that looks mildly
suspicious and begins with:

<?php
if ($_REQUEST["r"] != "df92d2bbeb38b7834deaa41c192550b3") exit;
/
*************************************************************************** ***************************/
/*
/*                                     #    #        #
#
/*                                     #   #          #   #
/*                                    #    #          #    #
/*                                    #   ##   ####   ##   #
/*                                   ##   ##  ######  ##   ##
/*                                   ##   ##  ######  ##   ##
/*                                   ##   ##   ####   ##   ##
/*                                   ###   ############   ###
/*                                   ########################
/*                                        ##############
/*                                 ######## ########## #######
/*                                ###   ##  ##########  ##   ###
/*                                ###   ##  ##########  ##   ###
/*                                 ###   #  ##########  #   ###
/*                                 ###   ##  ########  ##   ###
/*                                  ##    #   ######   #    ##
/*                                   ##   #    ####   #    ##
/*                                     ##                 ##
/*
/*
/*
/*  r57shell.php - скрипт на пхп позволяющий вам выполнять системные
команды на сервере через браузер
/*  Вы можете скачать новую версию на нашем сайте: http://rst.void.ru
/*  Версия: 1.31
/
*~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~~~~~~~~~~~~~~~~~~~~*/
/*  Отдельная благодарность за помощь и идеи: blf, phoenix, virus,
NorD и всем чертям из RST/GHC.
/*  Если у Вас есть какие-либо идеи по поводу того какие функции
следует добавить в скрипт то пишите
/*  на [email address]. Все предложения будут рассмотрены.
/
*~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~~~~~~~~~~~~~~~~~~~~*/
/*  (c)oded by 1dt.w0lf
/*  RST/GHC http://rst.void.ru , http://ghc.ru
/*  ANY MODIFIED REPUBLISHING IS RESTRICTED
/
*************************************************************************** ***************************/
/* ~~~ Настройки | Options  ~~~ */

I've since removed the file and have repinged my feedburner feed. I'm
keeping my fingers crossed that the spam links disappear.

Anyone else seeing such a thing?

A quick google search showed this post which details the cause of the
issue:

http://www.markturner.net/2009/05/27/mt-net-recovers-from-another-hack/

"The attacker installed r57shell.php, which is basically a rootkit for
webservers. It showed up as wp-xmlrpc.php in my uploads directory."

I'd post the entire code, but I don't want people finding it and
modifying it for future use.  If someone at Google would like to see
it I can be reached through my web site.

Regards,

Jim
http://www.jmg-galleries.com

On Jun 24, 10:02 pm, Jim Goldstein wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
DanOestreich  
View profile  
 More options Jun 25, 11:56 pm
From: DanOestreich
Date: Thu, 25 Jun 2009 20:56:20 -0700 (PDT)
Local: Thurs, Jun 25 2009 11:56 pm
Subject: Re: my feed showing up as spam all of a sudden
I have been looking diligently, but have not found any similar on my
blog.

On Jun 24, 11:10 pm, Jim Goldstein wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Discussion subject changed to "Spam Feed: Culprit/How to Remove" by Today, I Read... Something
Today, I Read... Something  
View profile  
(3 users)  More options Jun 26, 4:25 pm
From: Today, I Read... Something
Date: Fri, 26 Jun 2009 13:25:28 -0700 (PDT)
Local: Fri, Jun 26 2009 4:25 pm
Subject: Spam Feed: Culprit/How to Remove
Yesterday, one of my awesome readers alerted me of the problem on my
blog. My feed was showing spammy content in Google reader, but when I
viewed the feed using my browser, it showed up fine. I checked it out
in Google Reader/Google Cache and realized *something* was amiss.

After investigating, I found the culprit (for WP users) and a solution
which may get some people up and running again.

First off, as a few have already mentioned, the first place to check
is your plugin folder. On my site, the script was hiding in the wp-
amazon plugin folder and on another it was hiding in *both* the
akismet and statpress/def/ folders. The files that are the problem are
*hidden* files, meaning they are preceded with a period --
example: .akismet.bak.php or .README.bak.php, etc. (No plugins that
I've come across require hidden files, but you may want to double
check with the plugin author before following the next step.)

1. Immediately delete those hidden plugin files. Remember, check *all*
of your plugins/plugin folders for those files.

That's only the first bit.

I decided to open up one of the files and at first, I was greeted by a
whole bunch of gibberish (ultimately commented out PHP text), but
scattered in between was actual executable PHP code. That lead me to
strip out the comments and what I found was *not good* by any
definition.

It turns out that there was a chunk of PHP code hidden in one of the
WordPress options table (specifically, the option table related to
showing you random plugins in your dashboard). To someone not
specifically looking for it, it's quite easy to miss.

So, that brings me to step two...and it's important that if you're
worried about altering a DB table, that you make a back up of the
content first or ask someone you trust to help you.

2. In the wp_options table (it might be different if you're using a
different prefix than 'wp_') and search for
option_name='rss_f541b3abd05e7962fcab37737f40fad8'; *or something
similar*.

One thing I've noticed is that it will be one of the few, if not the
only, 'rss_randomstring' option that's listed as 'yes' for autoload.

Once you've located that particular option row, copy the contents and
paste it into a blank plain text document (i.e. Notepad) and save it
as a back up. Then, search for the chunk that starts with "events or a
cale";s:7:';))"==" (it will be followed by a *huge* chunk of gibberish
letters and numbers) and delete all of it through to "edoced_46esab
(lave';s:150:"There are options under the widget options to specify
the view of the calendar in the sidebar.  The widget can be a list for
upcoming".

After deleting the offending code, update the row.

That should take care of the immediate problem. However, there are
still a couple things I'd recommend doing afterward...

1. Disable user registration if it's open and immediately delete any
suspicious user accounts from your blog
2. Change your WordPress username/password from the MySQL level
3. Change your database user/password combination (update your wp-
config.php file according)
4, Make sure your wp-config.php file is up to late with the latest
security stuff (especially if you've successively upgraded from a
version of WP prior to 2.6.x) and if not, make sure you've actually
*changed* the AUTH_KEY, SECURE_AUTH_KEY, LOGGED_IN_KEY, and 'NONCE_KEY
from their default values.

Since this is a tricky one to spot as it's not visible to the naked
eye and the spammer went so far as to add your host's IP to a block
list so it won't be immediately visible (I decrypted all the files/
code involved and it is *NASTY*), I recommend going through and check
*all* of your blogs if you have more than one.

Finally, keep a vigilant eye out for any suspicious activity on your
blog.

I hope this helps.


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Chris Merlo  
View profile  
(1 user)  More options Jun 30, 2:48 am
From: Chris Merlo
Date: Mon, 29 Jun 2009 23:48:13 -0700 (PDT)
Local: Tues, Jun 30 2009 2:48 am
Subject: Re: Spam Feed: Culprit/How to Remove
Thank you so much for tracking down this much of the problem.  I was
able to take your information and go a step further.  I posted my
findings here:  http://www.theyellowbox.com/?p=252  In short, all that
gibberish-looking stuff is actually backward PHP code to evaluate some
other code, which is hidden from the non-programmer by a function
called base64_decode.  I hope this helps Google, or WordPress, or one
or more of you, to figure out who's behind these attacks.

What I can't figure out is how they get the backwards code turned
around and evaluated.  I will be following this thread to see if
anyone figures that part out.  Thanks again "Today".
-Chris


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Keith W.  
View profile  
 More options Jul 6, 11:28 pm
From: Keith W.
Date: Mon, 6 Jul 2009 20:28:15 -0700 (PDT)
Local: Mon, Jul 6 2009 11:28 pm
Subject: Re: Spam Feed: Culprit/How to Remove
Thanks, I think this fixed it with the rss_f541b3abd05e entry in the
database and some offending code that did not look right.> I hope this
helps.

    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Messages 1 - 25 of 33   Newer >
« Back to Discussions « Newer topic     Older topic »

Create a group - Google Groups - Google Home - Terms of Service - Privacy Policy
©2009 Google