<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: Upgrade and new theme</title>
	<atom:link href="http://www.lightbluetouchpaper.org/2007/10/27/upgrade-and-new-theme/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.lightbluetouchpaper.org/2007/10/27/upgrade-and-new-theme/</link>
	<description>Security Research, Computer Laboratory, University of Cambridge</description>
	<pubDate>Thu, 18 Mar 2010 10:34:30 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Thomas</title>
		<link>http://www.lightbluetouchpaper.org/2007/10/27/upgrade-and-new-theme/comment-page-1/#comment-27211</link>
		<dc:creator>Thomas</dc:creator>
		<pubDate>Mon, 26 Nov 2007 00:29:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2007/10/27/upgrade-and-new-theme/#comment-27211</guid>
		<description>@Steven

Can you tell me more about this second backdoor you mention? Just to be on the safe side, I want to double-double-check that he didn't leave anything that I did not discover (even though I'm pretty sure I'm covered - his /tmp backdoor did indeed fail to upload anything).</description>
		<content:encoded><![CDATA[<p>@Steven</p>
<p>Can you tell me more about this second backdoor you mention? Just to be on the safe side, I want to double-double-check that he didn&#8217;t leave anything that I did not discover (even though I&#8217;m pretty sure I&#8217;m covered - his /tmp backdoor did indeed fail to upload anything).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steven J. Murdoch</title>
		<link>http://www.lightbluetouchpaper.org/2007/10/27/upgrade-and-new-theme/comment-page-1/#comment-27205</link>
		<dc:creator>Steven J. Murdoch</dc:creator>
		<pubDate>Sun, 25 Nov 2007 01:14:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2007/10/27/upgrade-and-new-theme/#comment-27205</guid>
		<description>@Thomas

Very similar. The admin-ajax.php vulnerability was used, the backdoor was placed in /tmp, and then it was loaded as a plugin. The script looks identical too. 

However, where your attacker gave up, our one was more successful. He went on to upload a second backdoor, hidden amongst some other uploads, and then attempted to edit some of the Wordpress PHP files (but was prevented). 

After I removed the backdoors and changed the passwords, he still came back and tried to add links to some other compromised blogs which were hosting adverts for various pharmaceuticals. After a few days of unsuccessful attempts, he gave up.</description>
		<content:encoded><![CDATA[<p>@Thomas</p>
<p>Very similar. The admin-ajax.php vulnerability was used, the backdoor was placed in /tmp, and then it was loaded as a plugin. The script looks identical too. </p>
<p>However, where your attacker gave up, our one was more successful. He went on to upload a second backdoor, hidden amongst some other uploads, and then attempted to edit some of the Wordpress PHP files (but was prevented). </p>
<p>After I removed the backdoors and changed the passwords, he still came back and tried to add links to some other compromised blogs which were hosting adverts for various pharmaceuticals. After a few days of unsuccessful attempts, he gave up.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Thomas</title>
		<link>http://www.lightbluetouchpaper.org/2007/10/27/upgrade-and-new-theme/comment-page-1/#comment-27204</link>
		<dc:creator>Thomas</dc:creator>
		<pubDate>Sat, 24 Nov 2007 23:34:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2007/10/27/upgrade-and-new-theme/#comment-27204</guid>
		<description>Was it anything like this?
http://justaddwater.dk/2007/11/15/justaddwaterdk-hacked/</description>
		<content:encoded><![CDATA[<p>Was it anything like this?<br />
<a href="http://justaddwater.dk/2007/11/15/justaddwaterdk-hacked/" rel="nofollow">http://justaddwater.dk/2007/11/15/justaddwaterdk-hacked/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: paul</title>
		<link>http://www.lightbluetouchpaper.org/2007/10/27/upgrade-and-new-theme/comment-page-1/#comment-27201</link>
		<dc:creator>paul</dc:creator>
		<pubDate>Sat, 24 Nov 2007 02:24:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2007/10/27/upgrade-and-new-theme/#comment-27201</guid>
		<description>It looks like there is a patch undergoing testing that addresses this. It really does seem overdue.</description>
		<content:encoded><![CDATA[<p>It looks like there is a patch undergoing testing that addresses this. It really does seem overdue.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Clive Robinson</title>
		<link>http://www.lightbluetouchpaper.org/2007/10/27/upgrade-and-new-theme/comment-page-1/#comment-25481</link>
		<dc:creator>Clive Robinson</dc:creator>
		<pubDate>Mon, 05 Nov 2007 13:13:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2007/10/27/upgrade-and-new-theme/#comment-25481</guid>
		<description>@Steve,

I'll give it a try you knever know they might listen...</description>
		<content:encoded><![CDATA[<p>@Steve,</p>
<p>I&#8217;ll give it a try you knever know they might listen&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steven J. Murdoch</title>
		<link>http://www.lightbluetouchpaper.org/2007/10/27/upgrade-and-new-theme/comment-page-1/#comment-25300</link>
		<dc:creator>Steven J. Murdoch</dc:creator>
		<pubDate>Sat, 03 Nov 2007 22:20:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2007/10/27/upgrade-and-new-theme/#comment-25300</guid>
		<description>@Clive

I'm trying, as much as possible, to track the mainline Wordpress distribution. Otherwise each time I upgrade to fix the frequent security problems, my patches break. There is, however, a facility to browse authors posts, for example my posts are at: http://www.lightbluetouchpaper.org/author/sjmurdoch/

You could also try submitting a &lt;a href="http://trac.wordpress.org/" rel="nofollow"&gt;feature request&lt;/a&gt; at Wordpress. Hopefully you'll have more luck that me with my 2 year old &lt;a href="http://trac.wordpress.org/ticket/2394" rel="nofollow"&gt;security vulnerability&lt;/a&gt; :-)</description>
		<content:encoded><![CDATA[<p>@Clive</p>
<p>I&#8217;m trying, as much as possible, to track the mainline Wordpress distribution. Otherwise each time I upgrade to fix the frequent security problems, my patches break. There is, however, a facility to browse authors posts, for example my posts are at: <a href="http://www.lightbluetouchpaper.org/author/sjmurdoch/" rel="nofollow">http://www.lightbluetouchpaper.org/author/sjmurdoch/</a></p>
<p>You could also try submitting a <a href="http://trac.wordpress.org/" rel="nofollow">feature request</a> at Wordpress. Hopefully you&#8217;ll have more luck that me with my 2 year old <a href="http://trac.wordpress.org/ticket/2394" rel="nofollow">security vulnerability</a> <img src='http://www.lightbluetouchpaper.org/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Clive Robinson</title>
		<link>http://www.lightbluetouchpaper.org/2007/10/27/upgrade-and-new-theme/comment-page-1/#comment-25240</link>
		<dc:creator>Clive Robinson</dc:creator>
		<pubDate>Sat, 03 Nov 2007 10:10:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2007/10/27/upgrade-and-new-theme/#comment-25240</guid>
		<description>@Steven,

One sugestion for a possible "enhancement".

Currently it would appear that your search function does not include the posters name. Often this is handy when trying to find related information.

RGR</description>
		<content:encoded><![CDATA[<p>@Steven,</p>
<p>One sugestion for a possible &#8220;enhancement&#8221;.</p>
<p>Currently it would appear that your search function does not include the posters name. Often this is handy when trying to find related information.</p>
<p>RGR</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Clive Robinson</title>
		<link>http://www.lightbluetouchpaper.org/2007/10/27/upgrade-and-new-theme/comment-page-1/#comment-24760</link>
		<dc:creator>Clive Robinson</dc:creator>
		<pubDate>Sun, 28 Oct 2007 16:07:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2007/10/27/upgrade-and-new-theme/#comment-24760</guid>
		<description>Good luck, and I hope things go smothly.</description>
		<content:encoded><![CDATA[<p>Good luck, and I hope things go smothly.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
