<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: How to Diagnose and Remove the WordPress Pharma Hack</title>
	<atom:link href="http://www.pearsonified.com/2010/04/wordpress-pharma-hack.php/feed" rel="self" type="application/rss+xml" />
	<link>http://www.pearsonified.com/2010/04/wordpress-pharma-hack.php</link>
	<description>Best Damn Blog on the Planet</description>
	<lastBuildDate>Thu, 09 Feb 2012 15:40:07 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Haneef Saleem</title>
		<link>http://www.pearsonified.com/2010/04/wordpress-pharma-hack.php#comment-185984</link>
		<dc:creator>Haneef Saleem</dc:creator>
		<pubDate>Mon, 16 Jan 2012 13:51:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.pearsonified.com/?p=742#comment-185984</guid>
		<description>Hello,
Thanks for the informative article about the 5 security tips to take in protecting a wordpress site.  Unfortunately, I did not discover this until after my site (macleem.com) was hacked.  Now if you try to visit any of the site&#039;s legitimate subdomains or even an invalid one it redirects you to a viagra or pharma site.  For example, a legitimate subfolder gets redirected to the viagra site...or if you try a similar folder that doesn&#039;t exist, it will take you to the same viagra site. 

At this point i am not convinced that the hack is integrated with Word Press, sine the word press blog does not sit on the root directory.  Any suggestions you could offer to resolve this issue?

Also, I did find random eval() codes outside of the wordpress folder.</description>
		<content:encoded><![CDATA[<p>Hello,<br />
Thanks for the informative article about the 5 security tips to take in protecting a wordpress site.  Unfortunately, I did not discover this until after my site (macleem.com) was hacked.  Now if you try to visit any of the site&#8217;s legitimate subdomains or even an invalid one it redirects you to a viagra or pharma site.  For example, a legitimate subfolder gets redirected to the viagra site&#8230;or if you try a similar folder that doesn&#8217;t exist, it will take you to the same viagra site. </p>
<p>At this point i am not convinced that the hack is integrated with Word Press, sine the word press blog does not sit on the root directory.  Any suggestions you could offer to resolve this issue?</p>
<p>Also, I did find random eval() codes outside of the wordpress folder.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike</title>
		<link>http://www.pearsonified.com/2010/04/wordpress-pharma-hack.php#comment-185684</link>
		<dc:creator>Mike</dc:creator>
		<pubDate>Wed, 21 Dec 2011 17:30:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.pearsonified.com/?p=742#comment-185684</guid>
		<description>Thanks for this awesome article.  I was hit with this and was able to find a file with the bit of base64 code in it and removed it but did not find anything in the wp_options table of the database looking like the possibilities you mention.

Any ideas?</description>
		<content:encoded><![CDATA[<p>Thanks for this awesome article.  I was hit with this and was able to find a file with the bit of base64 code in it and removed it but did not find anything in the wp_options table of the database looking like the possibilities you mention.</p>
<p>Any ideas?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eagle Locksmith</title>
		<link>http://www.pearsonified.com/2010/04/wordpress-pharma-hack.php#comment-185661</link>
		<dc:creator>Eagle Locksmith</dc:creator>
		<pubDate>Thu, 15 Dec 2011 17:55:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.pearsonified.com/?p=742#comment-185661</guid>
		<description>I haven&#039;t been hacked yet but heard about this. This is a good source to bookmark. Better safe than sorry. Thanks for posting this.</description>
		<content:encoded><![CDATA[<p>I haven&#8217;t been hacked yet but heard about this. This is a good source to bookmark. Better safe than sorry. Thanks for posting this.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stuart</title>
		<link>http://www.pearsonified.com/2010/04/wordpress-pharma-hack.php#comment-185638</link>
		<dc:creator>Stuart</dc:creator>
		<pubDate>Fri, 09 Dec 2011 19:32:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.pearsonified.com/?p=742#comment-185638</guid>
		<description>I had several blogs that were trashed by this malware last year and I am working on a clients site that has this problem. To prevent this malware hitting your site I downloaded  Wordpress File Monitor. It tells you when any of your files are modified. Just my two cents!</description>
		<content:encoded><![CDATA[<p>I had several blogs that were trashed by this malware last year and I am working on a clients site that has this problem. To prevent this malware hitting your site I downloaded  WordPress File Monitor. It tells you when any of your files are modified. Just my two cents!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Daniel</title>
		<link>http://www.pearsonified.com/2010/04/wordpress-pharma-hack.php#comment-185554</link>
		<dc:creator>Daniel</dc:creator>
		<pubDate>Thu, 17 Nov 2011 18:16:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.pearsonified.com/?p=742#comment-185554</guid>
		<description>Wasn&#039;t aware this was even possible</description>
		<content:encoded><![CDATA[<p>Wasn&#8217;t aware this was even possible</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Damian</title>
		<link>http://www.pearsonified.com/2010/04/wordpress-pharma-hack.php#comment-185491</link>
		<dc:creator>Damian</dc:creator>
		<pubDate>Mon, 07 Nov 2011 09:22:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.pearsonified.com/?p=742#comment-185491</guid>
		<description>Would just like to say thanks for this post, we looked in our akismet folder as suggested by you and guess what was in there :(

this saved us a lot of time and this is our thanks for this great post</description>
		<content:encoded><![CDATA[<p>Would just like to say thanks for this post, we looked in our akismet folder as suggested by you and guess what was in there :(</p>
<p>this saved us a lot of time and this is our thanks for this great post</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bob Dickinson</title>
		<link>http://www.pearsonified.com/2010/04/wordpress-pharma-hack.php#comment-185399</link>
		<dc:creator>Bob Dickinson</dc:creator>
		<pubDate>Thu, 20 Oct 2011 18:52:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.pearsonified.com/?p=742#comment-185399</guid>
		<description>Does this impact my indexing and SEO? I didn&#039;t find any files in the public html but still having problems</description>
		<content:encoded><![CDATA[<p>Does this impact my indexing and SEO? I didn&#8217;t find any files in the public html but still having problems</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bob</title>
		<link>http://www.pearsonified.com/2010/04/wordpress-pharma-hack.php#comment-185348</link>
		<dc:creator>Bob</dc:creator>
		<pubDate>Wed, 12 Oct 2011 09:57:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.pearsonified.com/?p=742#comment-185348</guid>
		<description>Another place to check is in your index.php file in the root of your wordpress install.

I found the following there
[code]
include(&quot;js/wp-admin.php&quot;);
[/code]

js/wp-admin.php was a script that ran
[code]
header(&quot;Location: http://www.example-site.com/lorazepam.html?aid=vleup&quot;); 
[/code]

Scum...</description>
		<content:encoded><![CDATA[<p>Another place to check is in your index.php file in the root of your wordpress install.</p>
<p>I found the following there<br />
[code]<br />
include("js/wp-admin.php");<br />
[/code]</p>
<p>js/wp-admin.php was a script that ran<br />
[code]<br />
header("Location: <a href="http://www.example-site.com/lorazepam.html?aid=vleup" rel="nofollow">http://www.example-site.com/lorazepam.html?aid=vleup</a>");<br />
[/code]</p>
<p>Scum&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: eric</title>
		<link>http://www.pearsonified.com/2010/04/wordpress-pharma-hack.php#comment-185319</link>
		<dc:creator>eric</dc:creator>
		<pubDate>Fri, 07 Oct 2011 17:47:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.pearsonified.com/?p=742#comment-185319</guid>
		<description>To pick a nit: If you don&#039;t know how the exploit worked, you don&#039;t know that people can prevent it in the future using the methods outlined in the linked post. Mind, they all seem like reasonable things to do, but from what I&#039;m seeing so far it sounds to me like the most likely problem is a combination of inadequate directory permissions and some code-cleaning weakness in Wordpress.</description>
		<content:encoded><![CDATA[<p>To pick a nit: If you don&#8217;t know how the exploit worked, you don&#8217;t know that people can prevent it in the future using the methods outlined in the linked post. Mind, they all seem like reasonable things to do, but from what I&#8217;m seeing so far it sounds to me like the most likely problem is a combination of inadequate directory permissions and some code-cleaning weakness in WordPress.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tom altman</title>
		<link>http://www.pearsonified.com/2010/04/wordpress-pharma-hack.php#comment-185174</link>
		<dc:creator>tom altman</dc:creator>
		<pubDate>Thu, 22 Sep 2011 10:40:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.pearsonified.com/?p=742#comment-185174</guid>
		<description>It appears they may have upgraded this hack.  I&#039;ve been affected and I&#039;m pretty sure they did access the database at all.

Anyone notice any other variants?</description>
		<content:encoded><![CDATA[<p>It appears they may have upgraded this hack.  I&#8217;ve been affected and I&#8217;m pretty sure they did access the database at all.</p>
<p>Anyone notice any other variants?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using apc (Feed is rejected)
Page Caching using apc (User agent is rejected)
Database Caching 1/4 queries in 0.004 seconds using apc
Object Caching 266/270 objects using disk: basic
Content Delivery Network via cdn.pearsonified.com

Served from: www.pearsonified.com @ 2012-02-09 13:26:59 -->
