<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: A hacker came by with c99madshell v. 2.0 madnet edition</title>
	<atom:link href="http://tutorialvine.com/a-hacker-came-by-with-c99madshell-v-20-madnet-edition.html/feed" rel="self" type="application/rss+xml" />
	<link>http://tutorialvine.com/a-hacker-came-by-with-c99madshell-v-20-madnet-edition.html</link>
	<description>Tutorials and Tips!</description>
	<lastBuildDate>Wed, 03 Jun 2009 00:39:50 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Denny</title>
		<link>http://tutorialvine.com/a-hacker-came-by-with-c99madshell-v-20-madnet-edition.html#comment-6129</link>
		<dc:creator>Denny</dc:creator>
		<pubDate>Mon, 17 Nov 2008 02:26:39 +0000</pubDate>
		<guid isPermaLink="false">http://tutorialvine.com/a-hacker-came-by-with-c99madshell-v-20-madnet-edition#comment-6129</guid>
		<description>I also found a gzipped version of C99madShell v. 2.0 madnet edition on one of my servers.  It appears the only purpose served was to drop tons of spam links in the footer of one of my Wordpress installations.  

Does anyone have any more information on this?  How to prevent it, repair it, log it, remove it... ???</description>
		<content:encoded><![CDATA[<p>I also found a gzipped version of C99madShell v. 2.0 madnet edition on one of my servers.  It appears the only purpose served was to drop tons of spam links in the footer of one of my Wordpress installations.  </p>
<p>Does anyone have any more information on this?  How to prevent it, repair it, log it, remove it&#8230; ???</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jd</title>
		<link>http://tutorialvine.com/a-hacker-came-by-with-c99madshell-v-20-madnet-edition.html#comment-6114</link>
		<dc:creator>jd</dc:creator>
		<pubDate>Sun, 19 Oct 2008 16:49:31 +0000</pubDate>
		<guid isPermaLink="false">http://tutorialvine.com/a-hacker-came-by-with-c99madshell-v-20-madnet-edition#comment-6114</guid>
		<description>I just found c99madshell on one of my sites on a shared server. In addition I found installed.php files a couple other domains on the same server. I&#039;ve removed the files but need to determine how this happened.

What else should I be looking for? Please help!</description>
		<content:encoded><![CDATA[<p>I just found c99madshell on one of my sites on a shared server. In addition I found installed.php files a couple other domains on the same server. I&#8217;ve removed the files but need to determine how this happened.</p>
<p>What else should I be looking for? Please help!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: admin</title>
		<link>http://tutorialvine.com/a-hacker-came-by-with-c99madshell-v-20-madnet-edition.html#comment-5523</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Thu, 06 Mar 2008 12:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://tutorialvine.com/a-hacker-came-by-with-c99madshell-v-20-madnet-edition#comment-5523</guid>
		<description>hi &quot;me too&quot; :-)

Thanks for the link, I am gonna try to decode the code and have a look.

I have no idea either how they got access to my host either, but I suspect a Wordpress problem that has not been fixed yet.</description>
		<content:encoded><![CDATA[<p>hi &#8220;me too&#8221; <img src='http://tutorialvine.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>Thanks for the link, I am gonna try to decode the code and have a look.</p>
<p>I have no thought either how they got access to my host either, but I suspect a Wordpress conundrum that has not been fixed yet.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: me too</title>
		<link>http://tutorialvine.com/a-hacker-came-by-with-c99madshell-v-20-madnet-edition.html#comment-5474</link>
		<dc:creator>me too</dc:creator>
		<pubDate>Wed, 27 Feb 2008 15:55:44 +0000</pubDate>
		<guid isPermaLink="false">http://tutorialvine.com/a-hacker-came-by-with-c99madshell-v-20-madnet-edition#comment-5474</guid>
		<description>I have. I found an index.php in a folder that didn&#039;t have one before. The contents were wrapped up like described at http://danilo.ariadoss.com/2006/01/04/decoding-eval-gzinflate-base64_decode/

After decoding it I found a reference to c99madshell inside and have found a couple references on the web to c99 shell. 

The person that put it there seemed to be after my Wordpress installation even though I can&#039;t say for sure yet how they got the shell on my host in the first place.</description>
		<content:encoded><![CDATA[<p>I have. I found an pointer.php in a folder that didn&#8217;t have one before. The contents were wrapped up like described at <a href="http://danilo.ariadoss.com/2006/01/04/decoding-eval-gzinflate-base64_decode/" rel="nofollow">http://danilo.ariadoss.com/2006/01/04/decoding-eval-gzinflate-base64_decode/</a></p>
<p>With decoding it I found a reference to c99madshell inside and have found a couple references on the web to c99 shell. </p>
<p>The person that place it here seemed to be with my Wordpress installation even though I can&#8217;t say for sure yet how they got the shell on my host in the first place.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
