<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Kevin Godby &#187; hacked</title>
	<atom:link href="http://kevin.godby.org/tag/hacked/feed/" rel="self" type="application/rss+xml" />
	<link>http://kevin.godby.org</link>
	<description>My Weblog</description>
	<lastBuildDate>Mon, 17 May 2010 17:40:42 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>I feel so exploited!</title>
		<link>http://kevin.godby.org/2008/11/03/i-feel-so-exploited/</link>
		<comments>http://kevin.godby.org/2008/11/03/i-feel-so-exploited/#comments</comments>
		<pubDate>Mon, 03 Nov 2008 07:10:28 +0000</pubDate>
		<dc:creator>Kevin Godby</dc:creator>
				<category><![CDATA[general]]></category>
		<category><![CDATA[hacked]]></category>

		<guid isPermaLink="false">http://kevin.godby.org/?p=197</guid>
		<description><![CDATA[My website was compromised Saturday night and spent the better part of a day participating in some sort of link farm. I&#8217;ve removed the offending files and am still auditing my site looking for more. I&#8217;ve also upgraded much of the software on the site in case the script kiddies weaseled their way in through [...]]]></description>
			<content:encoded><![CDATA[<p>My website was compromised Saturday night and spent the better part of a day participating in some sort of link farm.</p>
<p>I&#8217;ve removed the offending files and am still auditing my site looking for more. I&#8217;ve also upgraded much of the software on the site in case the script kiddies weaseled their way in through some outdated <acronym title="Hypertext Preprocessor">PHP</acronym> script.</p>
<p>In one day, my site has had more hits than it normally gets in a full month. If you found my site by clicking on a link that looked like <tt style="font-size: 10pt;">http://kevin.godby.org/page.php?id=...</tt> then I apologize.  The link you clicked on would have taken you to a site with a few hundred keywords, but no useful information.  And to top it off, the site tries to install malware on your computer.  </p>
<p>Some details on the exploit: The Russian and Ukrainian hackers uploaded the <tt style="font-size: 10pt;">page.php</tt> file at 14:36:27 PST on November 1, 2008. The <tt style="font-size: 10pt;">page.php</tt> file looks at the ID number at the end of the address and downloads a web page from a server in Germany. Once downloaded, the page is streamed to your browser (so it looks like I&#8217;m hosting the page). The page contains a litany of spammy keywords and a list of links pointing back to the <tt style="font-size: 10pt;">page.php</tt> file on my site (with different ID values). </p>
<p>I&#8217;ve already emailed the technical contact for the block of Internet addresses used to host the spam and malware pages. I&#8217;m not sure if their server was also hacked or if they&#8217;re willingly hosting the link farm.</p>
<p>I&#8217;ve also contacted <a href="http://www.dreamhost.com/" title="Dreamhost">Dreamhost</a>, my hosting provider, and provided them with details of the exploit.  Unfortunately, my site was not the only one to fall victim.  I wrote a small program to download pages with other ID numbers from the server in Germany, and they have links to other Dreamhost servers.  Hopefully, Dreamhost can help everyone clean up their sites or shut down traffic to the server in Germany.</p>
]]></content:encoded>
			<wfw:commentRss>http://kevin.godby.org/2008/11/03/i-feel-so-exploited/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.220 seconds -->

