<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:series="http://unfoldingneurons.com/"
		>
<channel>
	<title>Comments on: Haxx0red!</title>
	<atom:link href="http://literalbarrage.org/blog/archives/2007/10/02/haxx0red/feed/" rel="self" type="application/rss+xml" />
	<link>http://literalbarrage.org/blog/archives/2007/10/02/haxx0red/</link>
	<description>Faith, Family, Friends.</description>
	<lastBuildDate>Sat, 20 Feb 2010 23:39:22 -0400</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Doug</title>
		<link>http://literalbarrage.org/blog/archives/2007/10/02/haxx0red/comment-page-1/#comment-23182</link>
		<dc:creator>Doug</dc:creator>
		<pubDate>Fri, 02 May 2008 17:56:55 +0000</pubDate>
		<guid isPermaLink="false">http://literalbarrage.org/blog/archives/2007/10/02/haxx0red/#comment-23182</guid>
		<description>Feesh:
Blocking multiple logins is a bad idea, as some malefactor could well block you from your own blog simply by repeatedly attempting to log in as &quot;admin&quot;, thus denying you access.

coffee2code&#039;s &lt;a href=&quot;http://coffee2code.com/wp-plugins/last-logins/&quot; rel=&quot;nofollow&quot;&gt;Last Logins&lt;/a&gt; plugin may be something to look into, as it at least logs all attempted logins, thus giving you an idea as to whether someone is attempting to get in and react in time (by changing passwords, etc.).</description>
		<content:encoded><![CDATA[<p>Feesh:<br />
Blocking multiple logins is a bad idea, as some malefactor could well block you from your own blog simply by repeatedly attempting to log in as &#8220;admin&#8221;, thus denying you access.</p>
<p>coffee2code&#8217;s <a href="http://coffee2code.com/wp-plugins/last-logins/" rel="nofollow" class="extlink">Last Logins</a> plugin may be something to look into, as it at least logs all attempted logins, thus giving you an idea as to whether someone is attempting to get in and react in time (by changing passwords, etc.).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Feesh</title>
		<link>http://literalbarrage.org/blog/archives/2007/10/02/haxx0red/comment-page-1/#comment-23180</link>
		<dc:creator>Feesh</dc:creator>
		<pubDate>Fri, 02 May 2008 16:04:25 +0000</pubDate>
		<guid isPermaLink="false">http://literalbarrage.org/blog/archives/2007/10/02/haxx0red/#comment-23180</guid>
		<description>Do either of you happen to use a plugin to stop multiple login attempts?

If not, it could be that they brute forced your password.</description>
		<content:encoded><![CDATA[<p>Do either of you happen to use a plugin to stop multiple login attempts?</p>
<p>If not, it could be that they brute forced your password.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Doug</title>
		<link>http://literalbarrage.org/blog/archives/2007/10/02/haxx0red/comment-page-1/#comment-23176</link>
		<dc:creator>Doug</dc:creator>
		<pubDate>Thu, 01 May 2008 19:22:29 +0000</pubDate>
		<guid isPermaLink="false">http://literalbarrage.org/blog/archives/2007/10/02/haxx0red/#comment-23176</guid>
		<description>Dan:
What version of WP were you running previously?

I&#039;ve been operating under the assumption that the vector was WP&#039;s XML-RPC interface, as that&#039;s the only real point of entry for my setup (I also altered my admin password in an attempt to narrow down exploit holes).

It almost seemed as if the spammers in question got ahold of my login credentials somehow and used the Theme Editor to add the offending code.</description>
		<content:encoded><![CDATA[<p>Dan:<br />
What version of WP were you running previously?</p>
<p>I&#8217;ve been operating under the assumption that the vector was WP&#8217;s XML-RPC interface, as that&#8217;s the only real point of entry for my setup (I also altered my admin password in an attempt to narrow down exploit holes).</p>
<p>It almost seemed as if the spammers in question got ahold of my login credentials somehow and used the Theme Editor to add the offending code.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dan Cederholm</title>
		<link>http://literalbarrage.org/blog/archives/2007/10/02/haxx0red/comment-page-1/#comment-23175</link>
		<dc:creator>Dan Cederholm</dc:creator>
		<pubDate>Thu, 01 May 2008 19:12:12 +0000</pubDate>
		<guid isPermaLink="false">http://literalbarrage.org/blog/archives/2007/10/02/haxx0red/#comment-23175</guid>
		<description>I&#039;ve just discovered I&#039;ve been hit by the same exact problem on several of my domains.  I found one instance of the include-to-.txt and removed it.  But spam links are still showing up.  I&#039;ve grepp&#039;d my entire account for everything possible, and can&#039;t find the culprit.  Really really frustrating.  Would love to know if this is a WP issue, or just general hackery (I&#039;ve updated to WP2.5).</description>
		<content:encoded><![CDATA[<p>I&#8217;ve just discovered I&#8217;ve been hit by the same exact problem on several of my domains.  I found one instance of the include-to-.txt and removed it.  But spam links are still showing up.  I&#8217;ve grepp&#8217;d my entire account for everything possible, and can&#8217;t find the culprit.  Really really frustrating.  Would love to know if this is a WP issue, or just general hackery (I&#8217;ve updated to WP2.5).</p>
]]></content:encoded>
	</item>
</channel>
</rss>
