<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Upgrade and new theme</title>
	<atom:link href="http://www.lightbluetouchpaper.org/2007/10/27/upgrade-and-new-theme/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.lightbluetouchpaper.org/2007/10/27/upgrade-and-new-theme/</link>
	<description>Security Research, Computer Laboratory, University of Cambridge</description>
	<lastBuildDate>Sat, 28 Jan 2012 18:43:15 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: autobuildit</title>
		<link>http://www.lightbluetouchpaper.org/2007/10/27/upgrade-and-new-theme/comment-page-1/#comment-141255</link>
		<dc:creator>autobuildit</dc:creator>
		<pubDate>Tue, 25 Oct 2011 20:56:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2007/10/27/upgrade-and-new-theme/#comment-141255</guid>
		<description>I not to mention my friends came taking note of the nice helpful hints located on your web site then all of a sudden came up with an awful feeling I never expressed respect to the web blog owner for those strategies. These men became as a consequence excited to read through all of them and already have definitely been taking pleasure in those things. Appreciation for really being indeed thoughtful and then for going for these kinds of perfect resources millions of individuals are really eager to discover. My very own sincere apologies for not expressing appreciation to  sooner.</description>
		<content:encoded><![CDATA[<p>I not to mention my friends came taking note of the nice helpful hints located on your web site then all of a sudden came up with an awful feeling I never expressed respect to the web blog owner for those strategies. These men became as a consequence excited to read through all of them and already have definitely been taking pleasure in those things. Appreciation for really being indeed thoughtful and then for going for these kinds of perfect resources millions of individuals are really eager to discover. My very own sincere apologies for not expressing appreciation to  sooner.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Thomas</title>
		<link>http://www.lightbluetouchpaper.org/2007/10/27/upgrade-and-new-theme/comment-page-1/#comment-27211</link>
		<dc:creator>Thomas</dc:creator>
		<pubDate>Mon, 26 Nov 2007 00:29:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2007/10/27/upgrade-and-new-theme/#comment-27211</guid>
		<description>@Steven

Can you tell me more about this second backdoor you mention? Just to be on the safe side, I want to double-double-check that he didn&#039;t leave anything that I did not discover (even though I&#039;m pretty sure I&#039;m covered - his /tmp backdoor did indeed fail to upload anything).</description>
		<content:encoded><![CDATA[<p>@Steven</p>
<p>Can you tell me more about this second backdoor you mention? Just to be on the safe side, I want to double-double-check that he didn&#8217;t leave anything that I did not discover (even though I&#8217;m pretty sure I&#8217;m covered &#8211; his /tmp backdoor did indeed fail to upload anything).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steven J. Murdoch</title>
		<link>http://www.lightbluetouchpaper.org/2007/10/27/upgrade-and-new-theme/comment-page-1/#comment-27205</link>
		<dc:creator>Steven J. Murdoch</dc:creator>
		<pubDate>Sun, 25 Nov 2007 01:14:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2007/10/27/upgrade-and-new-theme/#comment-27205</guid>
		<description>@Thomas

Very similar. The admin-ajax.php vulnerability was used, the backdoor was placed in /tmp, and then it was loaded as a plugin. The script looks identical too. 

However, where your attacker gave up, our one was more successful. He went on to upload a second backdoor, hidden amongst some other uploads, and then attempted to edit some of the Wordpress PHP files (but was prevented). 

After I removed the backdoors and changed the passwords, he still came back and tried to add links to some other compromised blogs which were hosting adverts for various pharmaceuticals. After a few days of unsuccessful attempts, he gave up.</description>
		<content:encoded><![CDATA[<p>@Thomas</p>
<p>Very similar. The admin-ajax.php vulnerability was used, the backdoor was placed in /tmp, and then it was loaded as a plugin. The script looks identical too. </p>
<p>However, where your attacker gave up, our one was more successful. He went on to upload a second backdoor, hidden amongst some other uploads, and then attempted to edit some of the Wordpress PHP files (but was prevented). </p>
<p>After I removed the backdoors and changed the passwords, he still came back and tried to add links to some other compromised blogs which were hosting adverts for various pharmaceuticals. After a few days of unsuccessful attempts, he gave up.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Thomas</title>
		<link>http://www.lightbluetouchpaper.org/2007/10/27/upgrade-and-new-theme/comment-page-1/#comment-27204</link>
		<dc:creator>Thomas</dc:creator>
		<pubDate>Sat, 24 Nov 2007 23:34:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2007/10/27/upgrade-and-new-theme/#comment-27204</guid>
		<description>Was it anything like this?
http://justaddwater.dk/2007/11/15/justaddwaterdk-hacked/</description>
		<content:encoded><![CDATA[<p>Was it anything like this?<br />
<a href="http://justaddwater.dk/2007/11/15/justaddwaterdk-hacked/" rel="nofollow">http://justaddwater.dk/2007/11/15/justaddwaterdk-hacked/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: paul</title>
		<link>http://www.lightbluetouchpaper.org/2007/10/27/upgrade-and-new-theme/comment-page-1/#comment-27201</link>
		<dc:creator>paul</dc:creator>
		<pubDate>Sat, 24 Nov 2007 02:24:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2007/10/27/upgrade-and-new-theme/#comment-27201</guid>
		<description>It looks like there is a patch undergoing testing that addresses this. It really does seem overdue.</description>
		<content:encoded><![CDATA[<p>It looks like there is a patch undergoing testing that addresses this. It really does seem overdue.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Clive Robinson</title>
		<link>http://www.lightbluetouchpaper.org/2007/10/27/upgrade-and-new-theme/comment-page-1/#comment-25481</link>
		<dc:creator>Clive Robinson</dc:creator>
		<pubDate>Mon, 05 Nov 2007 13:13:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2007/10/27/upgrade-and-new-theme/#comment-25481</guid>
		<description>@Steve,

I&#039;ll give it a try you knever know they might listen...</description>
		<content:encoded><![CDATA[<p>@Steve,</p>
<p>I&#8217;ll give it a try you knever know they might listen&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steven J. Murdoch</title>
		<link>http://www.lightbluetouchpaper.org/2007/10/27/upgrade-and-new-theme/comment-page-1/#comment-25300</link>
		<dc:creator>Steven J. Murdoch</dc:creator>
		<pubDate>Sat, 03 Nov 2007 22:20:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2007/10/27/upgrade-and-new-theme/#comment-25300</guid>
		<description>@Clive

I&#039;m trying, as much as possible, to track the mainline Wordpress distribution. Otherwise each time I upgrade to fix the frequent security problems, my patches break. There is, however, a facility to browse authors posts, for example my posts are at: http://www.lightbluetouchpaper.org/author/sjmurdoch/

You could also try submitting a &lt;a href=&quot;http://trac.wordpress.org/&quot; rel=&quot;nofollow&quot;&gt;feature request&lt;/a&gt; at Wordpress. Hopefully you&#039;ll have more luck that me with my 2 year old &lt;a href=&quot;http://trac.wordpress.org/ticket/2394&quot; rel=&quot;nofollow&quot;&gt;security vulnerability&lt;/a&gt; :-)</description>
		<content:encoded><![CDATA[<p>@Clive</p>
<p>I&#8217;m trying, as much as possible, to track the mainline Wordpress distribution. Otherwise each time I upgrade to fix the frequent security problems, my patches break. There is, however, a facility to browse authors posts, for example my posts are at: <a href="http://www.lightbluetouchpaper.org/author/sjmurdoch/" rel="nofollow">http://www.lightbluetouchpaper.org/author/sjmurdoch/</a></p>
<p>You could also try submitting a <a href="http://trac.wordpress.org/" rel="nofollow">feature request</a> at Wordpress. Hopefully you&#8217;ll have more luck that me with my 2 year old <a href="http://trac.wordpress.org/ticket/2394" rel="nofollow">security vulnerability</a> <img src='http://www.lightbluetouchpaper.org/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Clive Robinson</title>
		<link>http://www.lightbluetouchpaper.org/2007/10/27/upgrade-and-new-theme/comment-page-1/#comment-25240</link>
		<dc:creator>Clive Robinson</dc:creator>
		<pubDate>Sat, 03 Nov 2007 10:10:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2007/10/27/upgrade-and-new-theme/#comment-25240</guid>
		<description>@Steven,

One sugestion for a possible &quot;enhancement&quot;.

Currently it would appear that your search function does not include the posters name. Often this is handy when trying to find related information.

RGR</description>
		<content:encoded><![CDATA[<p>@Steven,</p>
<p>One sugestion for a possible &#8220;enhancement&#8221;.</p>
<p>Currently it would appear that your search function does not include the posters name. Often this is handy when trying to find related information.</p>
<p>RGR</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Clive Robinson</title>
		<link>http://www.lightbluetouchpaper.org/2007/10/27/upgrade-and-new-theme/comment-page-1/#comment-24760</link>
		<dc:creator>Clive Robinson</dc:creator>
		<pubDate>Sun, 28 Oct 2007 16:07:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2007/10/27/upgrade-and-new-theme/#comment-24760</guid>
		<description>Good luck, and I hope things go smothly.</description>
		<content:encoded><![CDATA[<p>Good luck, and I hope things go smothly.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

