<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Web 2.0 Tutorials &#187; Asides</title>
	<atom:link href="http://tutorialvine.com/category/asides/feed" rel="self" type="application/rss+xml" />
	<link>http://tutorialvine.com</link>
	<description>From Webdesign to how to maximize your revenue streams.</description>
	<pubDate>Tue, 07 Oct 2008 10:38:34 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
	<language>en</language>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>A hacker came by with c99madshell v. 2.0 madnet edition</title>
		<link>http://tutorialvine.com/a-hacker-came-by-with-c99madshell-v-20-madnet-edition</link>
		<comments>http://tutorialvine.com/a-hacker-came-by-with-c99madshell-v-20-madnet-edition#comments</comments>
		<pubDate>Mon, 11 Feb 2008 19:09:43 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Asides]]></category>

		<category><![CDATA[blog updates]]></category>

		<category><![CDATA[wordpress]]></category>

		<category><![CDATA[advertise]]></category>

		<category><![CDATA[blog]]></category>

		<category><![CDATA[tutorial]]></category>

		<guid isPermaLink="false">http://tutorialvine.com/a-hacker-came-by-with-c99madshell-v-20-madnet-edition</guid>
		<description><![CDATA[*Update: Okay, I think I located the potential entry to the WP-Forum, which I have read having some security issues coming up lately. It has now been removed from this site. *¬†
Alright, not really what I wanted to happen on a Monday evening.
I came home, and just before I started to make dinner, I went [...]]]></description>
			<content:encoded><![CDATA[<p><em>*Update: Okay, I think I located the potential entry to the WP-Forum, which I have read having some security issues coming up lately. It has now been removed from this site. *¬†</em></p>
<p>Alright, not really what I wanted to happen on a Monday evening.</p>
<p>I came home, and just before I started to make dinner, I went to check my mail, in there was a mail from an advertiser that an ad was not showing, and naturally I went to the site to check.</p>
<p>Lo and behold, my site was hacked, and the hacker installed the c99madshell v. 2.0 on my domain.</p>
<p>Searching for information I found only vague information, and never really found out how the ‚Ç¨#&#8221;%&#8221;‚Ç¨# hacker came in.</p>
<p>I started by updating my <a href="http://tutorialvine.com/tag/wordpress" class="st_tag internal_tag" rel="tag nofollow" title="Posts tagged with wordpress">Wordpress</a> installation to the latest version, and then went hunting. I found the script in my themes folder, where it replaced one the .php files.</p>
<p>The only information I found that gave any clue to where to look was here: <a href="http://www.devside.net/blog/smf-exploit-like-phpbb-hack" target="_blank">http://www.devside.net/blog/smf-exploit-like-phpbb-hack </a></p>
<p>I included below screenshot, which is from the same <a href="http://tutorialvine.com/tag/blog" class="st_tag internal_tag" rel="tag nofollow" title="Posts tagged with blog">blog</a>-entry (credit where credit is due) since I focused on removing the hack instead of documenting it. I hope the owner does not take offence.</p>
<p><img src="http://tutorialvine.com/wp-content/uploads/c99sh_1_2.jpg" alt="c99sh_1_2.jpg" /></p>
<p>Removing it was fairly easy once I knew where to look, but I had to have a serious look around to see where it was hidden.</p>
<p>So, what did I learn from this? To backup, backup often, and to always update my <a href="http://tutorialvine.com/tag/wordpress" class="st_tag internal_tag" rel="tag nofollow" title="Posts tagged with wordpress">Wordpress</a> installations.</p>
<p>Have you had a visit?</p>
<div class="oio-postlinks"><b>&raquo; Post Purchase:</b>&nbsp;&nbsp;<a rel="nofollow" href="http://tutorialvine.com/wp-content/plugins/oiopub-direct/purchase.php?do=link&amp;p=110">Text Link</a></div>
<p>a</p>
<p><a href="http://tutorialvine.com/a-hacker-came-by-with-c99madshell-v-20-madnet-edition">A hacker came by with c99madshell v. 2.0 madnet edition</a></p>
]]></content:encoded>
			<wfw:commentRss>http://tutorialvine.com/a-hacker-came-by-with-c99madshell-v-20-madnet-edition/feed</wfw:commentRss>
		</item>
	</channel>
</rss>
