<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
><channel><title>Pankaj Pandey &#187; networkads.net</title> <atom:link href="http://www.pankajpandey.com/tag/networkads-net/feed/" rel="self" type="application/rss+xml" /><link>http://www.pankajpandey.com</link> <description>Web design &#38; Internet Marketing Consultant</description> <lastBuildDate>Thu, 19 Jan 2012 07:54:30 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <item><title>Network Solutions hosting issue or WordPress Security Flaw</title><link>http://www.pankajpandey.com/2010/04/network-solutions-hosting-issue-or-wordpress-security-flaw/</link> <comments>http://www.pankajpandey.com/2010/04/network-solutions-hosting-issue-or-wordpress-security-flaw/#comments</comments> <pubDate>Wed, 14 Apr 2010 16:24:21 +0000</pubDate> <dc:creator>Pankaj</dc:creator> <category><![CDATA[Blog Development]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[Web development]]></category> <category><![CDATA[binglbalts.com]]></category> <category><![CDATA[blog]]></category> <category><![CDATA[hack]]></category> <category><![CDATA[mainnetsoll.com]]></category> <category><![CDATA[Malware]]></category> <category><![CDATA[networkads.net]]></category> <category><![CDATA[WordPress]]></category><guid
isPermaLink="false">http://www.pankajpandey.com/?p=260</guid> <description><![CDATA[My one of client is victim of this mass hack on network solution hosted blog. I am going to share some interesting fact about this vulnerability story. when our client contacted to Network Solution support tell them to buy SSL as your site is not secure.  (6 April) I fixed theme files which is altered [...]]]></description> <content:encoded><![CDATA[<h3>My one of client is victim of this mass hack on network solution hosted blog. I am going to share some interesting fact about this vulnerability story.</h3><ol><li>when our client contacted to Network Solution support tell them to buy SSL as your site is not secure.  (6 April)</li><li>I fixed theme files which is altered by this hack and checked my database for any possible code. found a funx.php on theme file and called in footer.php. site seems to fix that time for me. I used to clear my cookies to check at every refresh. my avast home antivirus and chrome browser help me to do that. Suddenly my blog database connection gone due to network solution effort i think. I changed all username and password for ftp, database, wp-admin users (8 April)</li><li>When i wake up at 9 April found hacked blog again this time this this is another issue. Theme footer have reference to a function and 1 file included that is created on server. not able to remember the name 2 random file without any extension. I am not sure how someone put file on my server. I fixed the site again and and checked multiple time with clearing the cookies.  Seems fixed. I am very curious to know how this thing is happing to the site. anyone placing file on my server. (9-April).</li><li>Seems everything is fixed i start working on to make site secure with ssl. fed up with redirect error and i finaly make that working. (10 April)</li><li>Url is now http<strong>s</strong>.  i loosed my page rank and all back link on new site. (10 April)</li><li>Site is infected again. this time a plugins JavaScript file is infected. fixed again. (12 April).</li><li>Till now not noticed any infection issue (14 April)</li></ol><p>Now i am getting strange errors on site not sure this is infection or ?????</p><div
class="codecolorer-container html4strict mac-classic" style="overflow:auto;white-space:nowrap;border:1px solid #9F9F9F;width:435px;"><table
cellspacing="0" cellpadding="0"><tbody><tr><td
style="padding:5px;text-align:center;color:#888888;background-color:#EEEEEE;border-right: 1px solid #9F9F9F;font: normal 12px/1.4em Monaco, Lucida Console, monospace;"><div>1<br
/>2<br
/>3<br
/></div></td><td><div
class="html4strict codecolorer" style="padding:5px;font:normal 12px/1.4em Monaco, Lucida Console, monospace;white-space:nowrap">Error in ISAPI_Rewrite helper ISAPI extension.<br
/> 12030 - The connection with the server was terminated abnormally<br
/> File: .\rwhelper.cpp, Line: 1290.</div></td></tr></tbody></table></div><p>More update coming . Feel free to comment. Thanks</p><h3><span
style="color: #ff6600;">Update 18 April</span></h3><p>Site is again showing virus warning. I did all step to resolve nothing works. then i rename .htaccess upload a 1.php on root with  following code</p><div
class="codecolorer-container php mac-classic" style="overflow:auto;white-space:nowrap;border:1px solid #9F9F9F;width:435px;"><table
cellspacing="0" cellpadding="0"><tbody><tr><td
style="padding:5px;text-align:center;color:#888888;background-color:#EEEEEE;border-right: 1px solid #9F9F9F;font: normal 12px/1.4em Monaco, Lucida Console, monospace;"><div>1<br
/></div></td><td><div
class="php codecolorer" style="padding:5px;font:normal 12px/1.4em Monaco, Lucida Console, monospace;white-space:nowrap"><span
style="color: #339933;">&amp;</span>lt<span
style="color: #339933;">;</span> ?php <a
href="http://www.php.net/phpinfo"><span
style="color: #990000;">phpinfo</span></a><span
style="color: #009900;">&#40;</span><span
style="color: #009900;">&#41;</span><span
style="color: #339933;">;</span> ?<span
style="color: #339933;">&amp;</span>gt<span
style="color: #339933;">;</span></div></td></tr></tbody></table></div><p><a
href="http://www.pankajpandey.com/wp-content/uploads/2010/04/alert.png"><img
class="size-medium wp-image-295 alignnone" title="alert" src="http://www.pankajpandey.com/wp-content/uploads/2010/04/alert-250x111.png" alt="" width="250" height="111" /></a><a
href="http://www.pankajpandey.com/wp-content/uploads/2010/04/error.png"><img
class="size-medium wp-image-294 alignnone" title="error" src="http://www.pankajpandey.com/wp-content/uploads/2010/04/error-250x189.png" alt="" width="250" height="189" /></a></p><p>According to my knowledge this is server issue. This is no more any WordPress Issues. May be this problem is solved by Network solution before people notiiced that.</p><h3>Update 21 April</h3><p>I gave up my effort with Network Solution and i shifted to another Host.</p><h3>Best response on this issue</h3><blockquote><p>Summary: A web host had a crappy server configuration that allowed people on the same box to read each others’ configuration files, and some members of the “security” press have tried to turn this into a “WordPress vulnerability” story.</p><p>WordPress, like all other web applications, must store database connection info in clear text. Encrypting credentials doesn’t matter because the keys have to be stored where the web server can read them in order to decrypt the data. If a malicious user has access to the file system — like they appeared to have in this case — it is trivial to obtain the keys and decrypt the information. When you leave the keys to the door in the lock, does it help to lock the door?</p><p>A properly configured web server will not allow users to access the files of another user, regardless of file permissions. The web server is the responsibility of the hosting provider. The methods for doing this (suexec, et al) have been around for 5+ years.</p><p>I’m not even going to link any of the articles because they have so many inaccuracies you become stupider by reading them.</p><p>If you’re a web host and you turn a bad file permissions story into a WordPress story, you’re doing something wrong.</p><p>P.S. Network Solutions, it’s “WordPress” not “Word Press.”</p><p>&#8211;Matt</p></blockquote> ]]></content:encoded> <wfw:commentRss>http://www.pankajpandey.com/2010/04/network-solutions-hosting-issue-or-wordpress-security-flaw/feed/</wfw:commentRss> <slash:comments>1</slash:comments> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: basic
Database Caching 7/32 queries in 0.334 seconds using disk: basic
Object Caching 878/935 objects using disk: basic

Served from: www.pankajpandey.com @ 2012-02-08 01:00:56 -->
