<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Neat!  I was hacked.</title>
	<atom:link href="http://wqoq.com/2007/05/16/neat-i-was-hacked/feed/" rel="self" type="application/rss+xml" />
	<link>http://wqoq.com/2007/05/16/neat-i-was-hacked/</link>
	<description>Clever... not good, but clever.</description>
	<lastBuildDate>Sun, 29 Apr 2012 20:30:10 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3-beta1-18972</generator>
	<item>
		<title>By: Bob Maguire</title>
		<link>http://wqoq.com/2007/05/16/neat-i-was-hacked/comment-page-1/#comment-4493</link>
		<dc:creator>Bob Maguire</dc:creator>
		<pubDate>Sat, 15 Sep 2007 19:55:55 +0000</pubDate>
		<guid isPermaLink="false">http://wqoq.com/2007/05/16/neat-i-was-hacked/#comment-4493</guid>
		<description>Sure.  No problem.  There&#039;s been a considerable passage of time since then anyway.</description>
		<content:encoded><![CDATA[<p>Sure.  No problem.  There&#8217;s been a considerable passage of time since then anyway.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GateZone</title>
		<link>http://wqoq.com/2007/05/16/neat-i-was-hacked/comment-page-1/#comment-4492</link>
		<dc:creator>GateZone</dc:creator>
		<pubDate>Sat, 15 Sep 2007 19:50:01 +0000</pubDate>
		<guid isPermaLink="false">http://wqoq.com/2007/05/16/neat-i-was-hacked/#comment-4492</guid>
		<description>FYI - there are sites and ip&#039;s included in your mega list that were hacked also and then used unknowingly for brief periods until the owners/administrators were able to shut down the exploits in the same or similar ways that you were able to do. Only now when those domains are searched they get your blog that associates them with hacking exploits... not great.  In other words someone else could have done a similar list with your domain on it because of the hack on your site.  My point is that publishing these lists without fully understanding what you are publishing (pardon me if you do) results in potential damage to others who suffered the exact same assault that you did.  I would like you to consider removing the list as I&#039;m sure I am not the only one.  Thanks.  GZ</description>
		<content:encoded><![CDATA[<p>FYI &#8211; there are sites and ip&#8217;s included in your mega list that were hacked also and then used unknowingly for brief periods until the owners/administrators were able to shut down the exploits in the same or similar ways that you were able to do. Only now when those domains are searched they get your blog that associates them with hacking exploits&#8230; not great.  In other words someone else could have done a similar list with your domain on it because of the hack on your site.  My point is that publishing these lists without fully understanding what you are publishing (pardon me if you do) results in potential damage to others who suffered the exact same assault that you did.  I would like you to consider removing the list as I&#8217;m sure I am not the only one.  Thanks.  GZ</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bob Maguire</title>
		<link>http://wqoq.com/2007/05/16/neat-i-was-hacked/comment-page-1/#comment-4479</link>
		<dc:creator>Bob Maguire</dc:creator>
		<pubDate>Tue, 14 Aug 2007 04:16:43 +0000</pubDate>
		<guid isPermaLink="false">http://wqoq.com/2007/05/16/neat-i-was-hacked/#comment-4479</guid>
		<description>What a coincidence.  I have visited yours 0 times.</description>
		<content:encoded><![CDATA[<p>What a coincidence.  I have visited yours 0 times.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Visitor082</title>
		<link>http://wqoq.com/2007/05/16/neat-i-was-hacked/comment-page-1/#comment-4475</link>
		<dc:creator>Visitor082</dc:creator>
		<pubDate>Tue, 14 Aug 2007 03:08:52 +0000</pubDate>
		<guid isPermaLink="false">http://wqoq.com/2007/05/16/neat-i-was-hacked/#comment-4475</guid>
		<description>I have visited your site 368-times</description>
		<content:encoded><![CDATA[<p>I have visited your site 368-times</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hack attack in progress &#124; YugaTech &#124; Philippine Technology News &#38; Reviews</title>
		<link>http://wqoq.com/2007/05/16/neat-i-was-hacked/comment-page-1/#comment-4464</link>
		<dc:creator>Hack attack in progress &#124; YugaTech &#124; Philippine Technology News &#38; Reviews</dc:creator>
		<pubDate>Mon, 30 Jul 2007 00:59:48 +0000</pubDate>
		<guid isPermaLink="false">http://wqoq.com/2007/05/16/neat-i-was-hacked/#comment-4464</guid>
		<description>[...] Several people have encountered the same and have been successfully hacked. The script is uploaded somewhere else and being pulled up from the target site. Your error logs might display this as such: [...]</description>
		<content:encoded><![CDATA[<p>[...] Several people have encountered the same and have been successfully hacked. The script is uploaded somewhere else and being pulled up from the target site. Your error logs might display this as such: [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael</title>
		<link>http://wqoq.com/2007/05/16/neat-i-was-hacked/comment-page-1/#comment-4450</link>
		<dc:creator>Michael</dc:creator>
		<pubDate>Wed, 11 Jul 2007 11:52:41 +0000</pubDate>
		<guid isPermaLink="false">http://wqoq.com/2007/05/16/neat-i-was-hacked/#comment-4450</guid>
		<description>I saw attempts for this as well and decided to comb my logs for more occurences. I hacked out this ugly multi-part awk monstrosity to dump the results from the various logs to a file:

cat /var/log/default.access.log &#124; awk &#039;{print $1,&quot; - &quot;,$4,&quot; - &quot;,$12,&quot; - &quot;,$7}&#039; &#124; awk &#039;/.*\?$/&#039; &gt; attackers-wiki.txt

I&#039;m sure someone with greater awk skillz can make it nicer...

One interesting thing I noticed was that one of the files they try to run attempts to disable the safe-mode option in PHP.</description>
		<content:encoded><![CDATA[<p>I saw attempts for this as well and decided to comb my logs for more occurences. I hacked out this ugly multi-part awk monstrosity to dump the results from the various logs to a file:</p>
<p>cat /var/log/default.access.log | awk &#8216;{print $1,&#8221; &#8211; &#8220;,$4,&#8221; &#8211; &#8220;,$12,&#8221; &#8211; &#8220;,$7}&#8217; | awk &#8216;/.*\?$/&#8217; &gt; attackers-wiki.txt</p>
<p>I&#8217;m sure someone with greater awk skillz can make it nicer&#8230;</p>
<p>One interesting thing I noticed was that one of the files they try to run attempts to disable the safe-mode option in PHP.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bob Maguire</title>
		<link>http://wqoq.com/2007/05/16/neat-i-was-hacked/comment-page-1/#comment-4402</link>
		<dc:creator>Bob Maguire</dc:creator>
		<pubDate>Thu, 17 May 2007 05:24:42 +0000</pubDate>
		<guid isPermaLink="false">http://wqoq.com/2007/05/16/neat-i-was-hacked/#comment-4402</guid>
		<description>Someone clicked on the link and visited my site to see the evidence, so it ended up in my logs as a referer link.</description>
		<content:encoded><![CDATA[<p>Someone clicked on the link and visited my site to see the evidence, so it ended up in my logs as a referer link.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Francois</title>
		<link>http://wqoq.com/2007/05/16/neat-i-was-hacked/comment-page-1/#comment-4401</link>
		<dc:creator>Francois</dc:creator>
		<pubDate>Thu, 17 May 2007 04:04:11 +0000</pubDate>
		<guid isPermaLink="false">http://wqoq.com/2007/05/16/neat-i-was-hacked/#comment-4401</guid>
		<description>Bob, sorry to hear about the hack.  How exactly did you notice that site was posted in a Spanish-language forum?  Do you Google your site on a regular basis?</description>
		<content:encoded><![CDATA[<p>Bob, sorry to hear about the hack.  How exactly did you notice that site was posted in a Spanish-language forum?  Do you Google your site on a regular basis?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

