<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:gml="http://www.opengis.net/gml"
	>
<channel>
	<title>Comments on: 10 Great Reasons NOT to use WordPress&#8230;</title>
	<atom:link href="http://raincityguide.com/2006/09/04/10-great-reasons-not-to-use-wordpress/feed/" rel="self" type="application/rss+xml" />
	<link>http://raincityguide.com/2006/09/04/10-great-reasons-not-to-use-wordpress/</link>
	<description>Seattle&#039;s Leading Resource for Real Estate Information</description>
	<lastBuildDate>Sun, 08 Nov 2009 01:47:42 -0800</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Joel Burslem</title>
		<link>http://raincityguide.com/2006/09/04/10-great-reasons-not-to-use-wordpress/#comment-16104</link>
		<dc:creator>Joel Burslem</dc:creator>
		<pubDate>Wed, 06 Sep 2006 04:32:13 +0000</pubDate>
		<guid isPermaLink="false">http://raincityguide.com/2006/09/04/10-great-reasons-not-to-use-wordpress/#comment-16104</guid>
		<description>Glad to see you&#039;re up and running again, guys.

This is a great lesson to anyone running WP - I&#039;m going to have to go through all my permissions and double check them.</description>
		<content:encoded><![CDATA[<p>Glad to see you&#8217;re up and running again, guys.</p>
<p>This is a great lesson to anyone running WP &#8211; I&#8217;m going to have to go through all my permissions and double check them.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: patrick</title>
		<link>http://raincityguide.com/2006/09/04/10-great-reasons-not-to-use-wordpress/#comment-15963</link>
		<dc:creator>patrick</dc:creator>
		<pubDate>Tue, 05 Sep 2006 17:48:51 +0000</pubDate>
		<guid isPermaLink="false">http://raincityguide.com/2006/09/04/10-great-reasons-not-to-use-wordpress/#comment-15963</guid>
		<description>Dustin,

Check for wget in your logs, for starters. Or a lot of stuff that looks like %0A , etc. Also you might consider turning off allow_furl_open in your php.ini (allowing a url to be included/opened like a file).</description>
		<content:encoded><![CDATA[<p>Dustin,</p>
<p>Check for wget in your logs, for starters. Or a lot of stuff that looks like %0A , etc. Also you might consider turning off allow_furl_open in your php.ini (allowing a url to be included/opened like a file).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Robbie</title>
		<link>http://raincityguide.com/2006/09/04/10-great-reasons-not-to-use-wordpress/#comment-15933</link>
		<dc:creator>Robbie</dc:creator>
		<pubDate>Tue, 05 Sep 2006 16:13:03 +0000</pubDate>
		<guid isPermaLink="false">http://raincityguide.com/2006/09/04/10-great-reasons-not-to-use-wordpress/#comment-15933</guid>
		<description>Wish I could be more helpful. On my planet, index.php is called default.aspx and .htaccess/chmod is replaced by cacls.exe and mad asp.net/ISAPI skills...</description>
		<content:encoded><![CDATA[<p>Wish I could be more helpful. On my planet, index.php is called default.aspx and .htaccess/chmod is replaced by cacls.exe and mad asp.net/ISAPI skills&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dustin</title>
		<link>http://raincityguide.com/2006/09/04/10-great-reasons-not-to-use-wordpress/#comment-15802</link>
		<dc:creator>Dustin</dc:creator>
		<pubDate>Tue, 05 Sep 2006 04:20:20 +0000</pubDate>
		<guid isPermaLink="false">http://raincityguide.com/2006/09/04/10-great-reasons-not-to-use-wordpress/#comment-15802</guid>
		<description>Patrick, 

I forgot what I ended up with, but I definitely didn&#039;t have any 777s.  I remember going through a few iterations to find the minimum that I had to leave open for individual files and still have the plugins work, so I did set things up so that the server could write stuff.   Hence, my guess that someone figured out a way to use one of the programs I had installed to trick the server into writing the junk. 

Based on the fact that almost no files were added/deleted to the server (that I can tell), it doesn&#039;t look like the hacker got around to doing very much damage.  
 
BTW,  I tried looking through some access logs, but I didn&#039;t find anything interesting there... (not that I know exactly what I should be looking for... :) )</description>
		<content:encoded><![CDATA[<p>Patrick, </p>
<p>I forgot what I ended up with, but I definitely didn&#8217;t have any 777s.  I remember going through a few iterations to find the minimum that I had to leave open for individual files and still have the plugins work, so I did set things up so that the server could write stuff.   Hence, my guess that someone figured out a way to use one of the programs I had installed to trick the server into writing the junk. </p>
<p>Based on the fact that almost no files were added/deleted to the server (that I can tell), it doesn&#8217;t look like the hacker got around to doing very much damage.  </p>
<p>BTW,  I tried looking through some access logs, but I didn&#8217;t find anything interesting there&#8230; (not that I know exactly what I should be looking for&#8230; <img src='http://raincityguide.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  )</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: patrick</title>
		<link>http://raincityguide.com/2006/09/04/10-great-reasons-not-to-use-wordpress/#comment-15746</link>
		<dc:creator>patrick</dc:creator>
		<pubDate>Mon, 04 Sep 2006 22:37:07 +0000</pubDate>
		<guid isPermaLink="false">http://raincityguide.com/2006/09/04/10-great-reasons-not-to-use-wordpress/#comment-15746</guid>
		<description>How are you doing &quot;..require that the web admin set folder settings so that the plugin can “write” to the server..&quot; this? If you have chmoded to 777, then anything can be written there by anyone. 

Did you search your server logs? Not just access_log, but error_log (these are for Apache), but your system&#039;s kernel log (/var/log/messages), et al? These will provide clues as to what files were scanned and exploited.</description>
		<content:encoded><![CDATA[<p>How are you doing &#8220;..require that the web admin set folder settings so that the plugin can “write” to the server..&#8221; this? If you have chmoded to 777, then anything can be written there by anyone. </p>
<p>Did you search your server logs? Not just access_log, but error_log (these are for Apache), but your system&#8217;s kernel log (/var/log/messages), et al? These will provide clues as to what files were scanned and exploited.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ARDELL</title>
		<link>http://raincityguide.com/2006/09/04/10-great-reasons-not-to-use-wordpress/#comment-15703</link>
		<dc:creator>ARDELL</dc:creator>
		<pubDate>Mon, 04 Sep 2006 18:14:06 +0000</pubDate>
		<guid isPermaLink="false">http://raincityguide.com/2006/09/04/10-great-reasons-not-to-use-wordpress/#comment-15703</guid>
		<description>I changed my password, for what it&#039;s worth.  I suggest everyone do the same.</description>
		<content:encoded><![CDATA[<p>I changed my password, for what it&#8217;s worth.  I suggest everyone do the same.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dustin</title>
		<link>http://raincityguide.com/2006/09/04/10-great-reasons-not-to-use-wordpress/#comment-15695</link>
		<dc:creator>Dustin</dc:creator>
		<pubDate>Mon, 04 Sep 2006 17:29:55 +0000</pubDate>
		<guid isPermaLink="false">http://raincityguide.com/2006/09/04/10-great-reasons-not-to-use-wordpress/#comment-15695</guid>
		<description>No,  I don&#039;t think they erased anything... My first step was to over-write the index.php file, but that did nothing.  They were clearly messing with something on a deeper level and my guess goes back to the .htaccess file, which I think (but I really don&#039;t know) would cause the behavior you described.   I&#039;ve noticed that the .htaccess file has a ton of power. And seeing as how this file allows the the server to write the &quot;human readable URLs&quot; on the fly, I&#039;m pretty sure it could be configured to do the redirection that was going on.  If anyone thinks I&#039;m full of it and spreading bad information, please feel free to step in!  :)</description>
		<content:encoded><![CDATA[<p>No,  I don&#8217;t think they erased anything&#8230; My first step was to over-write the index.php file, but that did nothing.  They were clearly messing with something on a deeper level and my guess goes back to the .htaccess file, which I think (but I really don&#8217;t know) would cause the behavior you described.   I&#8217;ve noticed that the .htaccess file has a ton of power. And seeing as how this file allows the the server to write the &#8220;human readable URLs&#8221; on the fly, I&#8217;m pretty sure it could be configured to do the redirection that was going on.  If anyone thinks I&#8217;m full of it and spreading bad information, please feel free to step in!  <img src='http://raincityguide.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Greg Swann</title>
		<link>http://raincityguide.com/2006/09/04/10-great-reasons-not-to-use-wordpress/#comment-15691</link>
		<dc:creator>Greg Swann</dc:creator>
		<pubDate>Mon, 04 Sep 2006 17:22:07 +0000</pubDate>
		<guid isPermaLink="false">http://raincityguide.com/2006/09/04/10-great-reasons-not-to-use-wordpress/#comment-15691</guid>
		<description>From appearances (I didn&#039;t test exhaustively), it seemed that everything at the root level for the domain had been erased and you (or they) had set the default 404 behavior to index.php. Is that correct?</description>
		<content:encoded><![CDATA[<p>From appearances (I didn&#8217;t test exhaustively), it seemed that everything at the root level for the domain had been erased and you (or they) had set the default 404 behavior to index.php. Is that correct?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dustin</title>
		<link>http://raincityguide.com/2006/09/04/10-great-reasons-not-to-use-wordpress/#comment-15685</link>
		<dc:creator>Dustin</dc:creator>
		<pubDate>Mon, 04 Sep 2006 17:02:02 +0000</pubDate>
		<guid isPermaLink="false">http://raincityguide.com/2006/09/04/10-great-reasons-not-to-use-wordpress/#comment-15685</guid>
		<description>All, 

I&#039;d love to tell you how they got in and exploited my site, but I simply don&#039;t know.   My guess is either
1) They found a weak password as Robbie suggest or 
2) I mis-configured the permissions on my server. 

I suspect the second issue because a number of WP plugins require that the web admin set folder settings so that the plugin can &quot;write&quot; to the server.  I&#039;ve tried to be as conservative as possible when changing these settings because I&#039;ve always thought that it was a bad practice for me to allow my server to write over files when I&#039;m not sure what is &quot;safe&quot; and what is &quot;dumb&quot;.  Anyway, at this point, I&#039;ve changed all the permissions so that the server cannot write (overwrite!) files, but that means that I don&#039;t have easy plugins for things like backing up the database and updating the .htaccess file.  Such is life until I start feeling adventurous again.</description>
		<content:encoded><![CDATA[<p>All, </p>
<p>I&#8217;d love to tell you how they got in and exploited my site, but I simply don&#8217;t know.   My guess is either<br />
1) They found a weak password as Robbie suggest or<br />
2) I mis-configured the permissions on my server. </p>
<p>I suspect the second issue because a number of WP plugins require that the web admin set folder settings so that the plugin can &#8220;write&#8221; to the server.  I&#8217;ve tried to be as conservative as possible when changing these settings because I&#8217;ve always thought that it was a bad practice for me to allow my server to write over files when I&#8217;m not sure what is &#8220;safe&#8221; and what is &#8220;dumb&#8221;.  Anyway, at this point, I&#8217;ve changed all the permissions so that the server cannot write (overwrite!) files, but that means that I don&#8217;t have easy plugins for things like backing up the database and updating the .htaccess file.  Such is life until I start feeling adventurous again.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Josh</title>
		<link>http://raincityguide.com/2006/09/04/10-great-reasons-not-to-use-wordpress/#comment-15678</link>
		<dc:creator>Josh</dc:creator>
		<pubDate>Mon, 04 Sep 2006 16:28:57 +0000</pubDate>
		<guid isPermaLink="false">http://raincityguide.com/2006/09/04/10-great-reasons-not-to-use-wordpress/#comment-15678</guid>
		<description>Welcome back. Sorry that you had to deal with those hackers.

I&#039;d also like to know exactly what happened, in an effort to protect myself and others.  Please feel free to email me or post it here!  Thanks.</description>
		<content:encoded><![CDATA[<p>Welcome back. Sorry that you had to deal with those hackers.</p>
<p>I&#8217;d also like to know exactly what happened, in an effort to protect myself and others.  Please feel free to email me or post it here!  Thanks.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
