<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for sean's place</title>
	<atom:link href="http://www.seanrees.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.seanrees.com</link>
	<description>Musings from a Software Development Geek.</description>
	<lastBuildDate>Tue, 08 Sep 2009 15:32:26 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Comment on Well, an update worth its salt by WordPress under gpc_10805 attack &#124; ShinePHP.com</title>
		<link>http://www.seanrees.com/2009/09/02/well-an-update-worth-its-salt/comment-page-1/#comment-11849</link>
		<dc:creator>WordPress under gpc_10805 attack &#124; ShinePHP.com</dc:creator>
		<pubDate>Tue, 08 Sep 2009 15:32:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.seanrees.com/?p=672#comment-11849</guid>
		<description>[...] http://www.seanrees.com/2009/09/02/well-an-update-worth-its-salt/ But pay attention that not only WordPress sites are attacked in this manner, look at the [...]</description>
		<content:encoded><![CDATA[<p>[...] <a href="http://www.seanrees.com/2009/09/02/well-an-update-worth-its-salt/" rel="nofollow">http://www.seanrees.com/2009/09/02/well-an-update-worth-its-salt/</a> But pay attention that not only WordPress sites are attacked in this manner, look at the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Well, an update worth its salt by vladimir</title>
		<link>http://www.seanrees.com/2009/09/02/well-an-update-worth-its-salt/comment-page-1/#comment-11848</link>
		<dc:creator>vladimir</dc:creator>
		<pubDate>Tue, 08 Sep 2009 01:02:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.seanrees.com/?p=672#comment-11848</guid>
		<description>I think it is not the WordPress vulnerability issue. Look at this thread
http://www.webdeveloper.com/forum/showthread.php?p=1032611
A lot of none-php clean HTML sites were infected with this gpc_() in the same manner. It is more probably that it uses compromised FTP passwords which stolen from your desktop by some virus which infected your computer.</description>
		<content:encoded><![CDATA[<p>I think it is not the WordPress vulnerability issue. Look at this thread<br />
<a href="http://www.webdeveloper.com/forum/showthread.php?p=1032611" rel="nofollow">http://www.webdeveloper.com/forum/showthread.php?p=1032611</a><br />
A lot of none-php clean HTML sites were infected with this gpc_() in the same manner. It is more probably that it uses compromised FTP passwords which stolen from your desktop by some virus which infected your computer.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Well, an update worth its salt by Tech Club &#124; Small Business Technology News and Innovations</title>
		<link>http://www.seanrees.com/2009/09/02/well-an-update-worth-its-salt/comment-page-1/#comment-11847</link>
		<dc:creator>Tech Club &#124; Small Business Technology News and Innovations</dc:creator>
		<pubDate>Sat, 05 Sep 2009 20:41:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.seanrees.com/?p=672#comment-11847</guid>
		<description>[...] related to the problem: http://www.journeyetc.com/2009/09/04/wordpress-permalink-rss-problems/ http://www.seanrees.com/2009/09/02/well-an-update-worth-its-salt/ http://wordpress.org/support/topic/297639/page/2 [...]</description>
		<content:encoded><![CDATA[<p>[...] related to the problem: <a href="http://www.journeyetc.com/2009/09/04/wordpress-permalink-rss-problems/" rel="nofollow">http://www.journeyetc.com/2009/09/04/wordpress-permalink-rss-problems/</a> <a href="http://www.seanrees.com/2009/09/02/well-an-update-worth-its-salt/" rel="nofollow">http://www.seanrees.com/2009/09/02/well-an-update-worth-its-salt/</a> <a href="http://wordpress.org/support/topic/297639/page/2" rel="nofollow">http://wordpress.org/support/topic/297639/page/2</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Well, an update worth its salt by Sean</title>
		<link>http://www.seanrees.com/2009/09/02/well-an-update-worth-its-salt/comment-page-1/#comment-11846</link>
		<dc:creator>Sean</dc:creator>
		<pubDate>Sat, 05 Sep 2009 19:47:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.seanrees.com/?p=672#comment-11846</guid>
		<description>It looks like there are more details (but not many more): http://mashable.com/2009/09/05/wordpress-attack/</description>
		<content:encoded><![CDATA[<p>It looks like there are more details (but not many more): <a href="http://mashable.com/2009/09/05/wordpress-attack/" rel="nofollow">http://mashable.com/2009/09/05/wordpress-attack/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Well, an update worth its salt by benanne</title>
		<link>http://www.seanrees.com/2009/09/02/well-an-update-worth-its-salt/comment-page-1/#comment-11845</link>
		<dc:creator>benanne</dc:creator>
		<pubDate>Fri, 04 Sep 2009 13:50:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.seanrees.com/?p=672#comment-11845</guid>
		<description>I was running v2.6.3, and the same thing happened to me. At least, the permalink setting was changed. I haven&#039;t found any injected code. To get rid of it, I fixed the permalink setting, but that turned out to be insufficient; closer inspection of my database revealed that there was somehow another user with administrator rights (I&#039;m supposed to be the only one), and his username was set to a bunch of Javascript. Upon discovering this, I manually removed all references to this user from the database (because he wouldn&#039;t show up in the WP admin pages) and upgraded to 2.8.4. I hope that does it, but I&#039;m not sure yet.

I just thought I&#039;d mention it here, because you don&#039;t say anything about suspicious administrator users, so it&#039;s possible that that&#039;s something you have overlooked. Also, there seems to have been an outbreak of this lately, wordpress.org&#039;s support forums are swarming with people reporting the same symptoms.</description>
		<content:encoded><![CDATA[<p>I was running v2.6.3, and the same thing happened to me. At least, the permalink setting was changed. I haven&#8217;t found any injected code. To get rid of it, I fixed the permalink setting, but that turned out to be insufficient; closer inspection of my database revealed that there was somehow another user with administrator rights (I&#8217;m supposed to be the only one), and his username was set to a bunch of Javascript. Upon discovering this, I manually removed all references to this user from the database (because he wouldn&#8217;t show up in the WP admin pages) and upgraded to 2.8.4. I hope that does it, but I&#8217;m not sure yet.</p>
<p>I just thought I&#8217;d mention it here, because you don&#8217;t say anything about suspicious administrator users, so it&#8217;s possible that that&#8217;s something you have overlooked. Also, there seems to have been an outbreak of this lately, wordpress.org&#8217;s support forums are swarming with people reporting the same symptoms.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Well, an update worth its salt by passer-by</title>
		<link>http://www.seanrees.com/2009/09/02/well-an-update-worth-its-salt/comment-page-1/#comment-11844</link>
		<dc:creator>passer-by</dc:creator>
		<pubDate>Fri, 04 Sep 2009 08:59:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.seanrees.com/?p=672#comment-11844</guid>
		<description>Hi Sean,

I too have been hit by this, on the 2nd Sept 2009.
I&#039;m a bit stunned as like yourself I have no idea how this person has done it.  Kudos to the little punk.  

I am beginning to think its a WP exploit.  I have a part of my website served up from a private area, none of the files there were effected.  Everything effected has been in the root wordpress directory.  I am using WP 2.6.  Maybe time to upgrade.</description>
		<content:encoded><![CDATA[<p>Hi Sean,</p>
<p>I too have been hit by this, on the 2nd Sept 2009.<br />
I&#8217;m a bit stunned as like yourself I have no idea how this person has done it.  Kudos to the little punk.  </p>
<p>I am beginning to think its a WP exploit.  I have a part of my website served up from a private area, none of the files there were effected.  Everything effected has been in the root wordpress directory.  I am using WP 2.6.  Maybe time to upgrade.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Thoughts on IPv6 by sjmitchell</title>
		<link>http://www.seanrees.com/2009/06/20/thoughts-on-ipv6/comment-page-1/#comment-11842</link>
		<dc:creator>sjmitchell</dc:creator>
		<pubDate>Mon, 22 Jun 2009 15:25:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.seanrees.com/?p=629#comment-11842</guid>
		<description>Fact is, hiding behind NAT and the implicit firewall provides some much needed security to today&#039;s average home owner.  Imagine if my TiVo was publicly addressable..  What obscure vulnerabilities exist that today can go unnoticed to me and to TiVo?

I&#039;m not saying it&#039;s a bad thing--but it&#039;s a different thing that will require a new level of device hardening than we need today.  NAT and the home firewall provide a crutch that is going to go away once IPv6 becomes the norm.</description>
		<content:encoded><![CDATA[<p>Fact is, hiding behind NAT and the implicit firewall provides some much needed security to today&#8217;s average home owner.  Imagine if my TiVo was publicly addressable..  What obscure vulnerabilities exist that today can go unnoticed to me and to TiVo?</p>
<p>I&#8217;m not saying it&#8217;s a bad thing&#8211;but it&#8217;s a different thing that will require a new level of device hardening than we need today.  NAT and the home firewall provide a crutch that is going to go away once IPv6 becomes the norm.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Thoughts on IPv6 by Thoughts on IPv6 &#124; BigB</title>
		<link>http://www.seanrees.com/2009/06/20/thoughts-on-ipv6/comment-page-1/#comment-11841</link>
		<dc:creator>Thoughts on IPv6 &#124; BigB</dc:creator>
		<pubDate>Sat, 20 Jun 2009 23:31:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.seanrees.com/?p=629#comment-11841</guid>
		<description>[...] more here:  Thoughts on IPv6   Share and [...]</description>
		<content:encoded><![CDATA[<p>[...] more here:  Thoughts on IPv6   Share and [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Boldly Going by smurf</title>
		<link>http://www.seanrees.com/2009/05/08/boldly-going/comment-page-1/#comment-11840</link>
		<dc:creator>smurf</dc:creator>
		<pubDate>Fri, 29 May 2009 16:35:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.seanrees.com/?p=625#comment-11840</guid>
		<description>John Scalzi&#039;s &lt;a href=&quot;http://whatever.scalzi.com/2009/05/11/quick-review-star-trek/&quot; rel=&quot;nofollow&quot;&gt;review&lt;/a&gt; pretty much sums up my feelings about the movie. And I think if anything deserves to be renamed Star Trek: The Comedy, it should be Star Trek IV: The Voyage Home.

Crew goes back in time
For songs of the humpback whale
Or else Earth goes boom

(also from &lt;a href=&quot;http://blogs.amctv.com/scifi-scanner/2009/05/star-trek-movie-plots.php&quot; rel=&quot;nofollow&quot;&gt; Scalzi)

I hope you&#039;re having fun in Ireland (it certainly sounds like it from your Twitter stream).</description>
		<content:encoded><![CDATA[<p>John Scalzi&#8217;s <a href="http://whatever.scalzi.com/2009/05/11/quick-review-star-trek/" rel="nofollow">review</a> pretty much sums up my feelings about the movie. And I think if anything deserves to be renamed Star Trek: The Comedy, it should be Star Trek IV: The Voyage Home.</p>
<p>Crew goes back in time<br />
For songs of the humpback whale<br />
Or else Earth goes boom</p>
<p>(also from <a href="http://blogs.amctv.com/scifi-scanner/2009/05/star-trek-movie-plots.php" rel="nofollow"> Scalzi)</p>
<p>I hope you&#8217;re having fun in Ireland (it certainly sounds like it from your Twitter stream).</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Boldly Going by ECH</title>
		<link>http://www.seanrees.com/2009/05/08/boldly-going/comment-page-1/#comment-11839</link>
		<dc:creator>ECH</dc:creator>
		<pubDate>Fri, 15 May 2009 03:21:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.seanrees.com/?p=625#comment-11839</guid>
		<description>If you read my movie review of Star Trek you should have read the &lt;a href=&quot;http://www.amazon.com/Star-Trek-Countdown-J-Abrams/dp/1600104207/ref=sr_1_1?ie=UTF8&amp;s=books&amp;qid=1241765504&amp;sr=8-1&quot; rel=&quot;nofollow&quot;&gt;Star Trek:Countdown&lt;/a&gt; before seeing the movie or you would think that it would suck.</description>
		<content:encoded><![CDATA[<p>If you read my movie review of Star Trek you should have read the <a href="http://www.amazon.com/Star-Trek-Countdown-J-Abrams/dp/1600104207/ref=sr_1_1?ie=UTF8&amp;s=books&amp;qid=1241765504&amp;sr=8-1" rel="nofollow">Star Trek:Countdown</a> before seeing the movie or you would think that it would suck.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
