<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Websites Injected &#8211; Cool Little Tool</title>
	<atom:link href="http://cocaman.ch/wp/2008/01/websites-injected-cool-little-tool/feed/" rel="self" type="application/rss+xml" />
	<link>http://cocaman.ch/wp/2008/01/websites-injected-cool-little-tool/</link>
	<description>Geeky at the Lake of Zurich</description>
	<lastBuildDate>Sat, 31 Jul 2010 07:42:56 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: Michael D Price</title>
		<link>http://cocaman.ch/wp/2008/01/websites-injected-cool-little-tool/comment-page-1/#comment-146027</link>
		<dc:creator>Michael D Price</dc:creator>
		<pubDate>Wed, 12 Mar 2008 05:42:58 +0000</pubDate>
		<guid isPermaLink="false">http://cocaman.ch/wp/2008/01/websites-injected-cool-little-tool/#comment-146027</guid>
		<description>Yes,
I just encountered this myself.

I am an Internet Marketer, and I also do tech support for other Online marketers. This evening, as soon as I got online I received an IM from one of my marketing buddies. They were in a panic that many of their sites had been hacked.
So I decided to look into it for them and I also came across this script.

This script replaced the functions.php file in a wordpress theme file.

Im assuming someone cracked the password for this blog and added the code through the theme editor. Then by using the script, I assume, they modified many wpconfig files that were on this server.

This was a baby croc host gator web account, with about 20 or so blogs. It took me about 3 hours to get everything straightened out.

But In the end, I got my hourly wage, and ended up with a copy of this cool script :)

Michael D Price
http://theinsiderslist.com</description>
		<content:encoded><![CDATA[<p>Yes,<br />
I just encountered this myself.</p>
<p>I am an Internet Marketer, and I also do tech support for other Online marketers. This evening, as soon as I got online I received an IM from one of my marketing buddies. They were in a panic that many of their sites had been hacked.<br />
So I decided to look into it for them and I also came across this script.</p>
<p>This script replaced the functions.php file in a wordpress theme file.</p>
<p>Im assuming someone cracked the password for this blog and added the code through the theme editor. Then by using the script, I assume, they modified many wpconfig files that were on this server.</p>
<p>This was a baby croc host gator web account, with about 20 or so blogs. It took me about 3 hours to get everything straightened out.</p>
<p>But In the end, I got my hourly wage, and ended up with a copy of this cool script <img src='http://cocaman.ch/wp/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Michael D Price<br />
<a href="http://theinsiderslist.com" rel="nofollow">http://theinsiderslist.com</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: stefan2904</title>
		<link>http://cocaman.ch/wp/2008/01/websites-injected-cool-little-tool/comment-page-1/#comment-125286</link>
		<dc:creator>stefan2904</dc:creator>
		<pubDate>Thu, 17 Jan 2008 10:51:11 +0000</pubDate>
		<guid isPermaLink="false">http://cocaman.ch/wp/2008/01/websites-injected-cool-little-tool/#comment-125286</guid>
		<description>strange...</description>
		<content:encoded><![CDATA[<p>strange&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Web Cash</title>
		<link>http://cocaman.ch/wp/2008/01/websites-injected-cool-little-tool/comment-page-1/#comment-124528</link>
		<dc:creator>Web Cash</dc:creator>
		<pubDate>Sat, 12 Jan 2008 14:36:44 +0000</pubDate>
		<guid isPermaLink="false">http://cocaman.ch/wp/2008/01/websites-injected-cool-little-tool/#comment-124528</guid>
		<description>&lt;strong&gt;Protect Against Shell Script Hacks...&lt;/strong&gt;

While browsing through Technorati, I just stumbled on a post about a shell script attack.  It seems the poor chap got a shell script uploaded to his server, and the attacker used it to create a bunch of bogus files full of hyperlinks.
The original post...</description>
		<content:encoded><![CDATA[<p><strong>Protect Against Shell Script Hacks&#8230;</strong></p>
<p>While browsing through Technorati, I just stumbled on a post about a shell script attack.  It seems the poor chap got a shell script uploaded to his server, and the attacker used it to create a bunch of bogus files full of hyperlinks.<br />
The original post&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>
